Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
main.exe

Overview

General Information

Sample name:main.exe
Analysis ID:1547827
MD5:91d6288da150030f5bb3520d313b4c3b
SHA1:cddd9dd6abaed79d89c7acd0c679db7173d55a9f
SHA256:a661cd857dc41135f7f2f95bc7cc257d020ebbe44b80e9c8d1c9436ccc322c6c
Tags:exeParaniCheckeruser-Fact_Finder03
Infos:

Detection

Score:48
Range:0 - 100
Whitelisted:false
Confidence:100%

Signatures

Multi AV Scanner detection for submitted file
Binary contains a suspicious time stamp
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to query CPU information (cpuid)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Creates a process in suspended mode (likely to inject code)
Detected potential crypto function
Drops PE files
Extensive use of GetProcAddress (often used to hide API calls)
Found dropped PE file which has not been started or loaded
Found evasive API chain checking for process token information
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
IP address seen in connection with other malware
PE file contains executable resources (Code or Archives)
PE file contains more sections than normal
PE file contains sections with non-standard names
PE file does not import any functions
Queries sensitive processor information (via WMI, Win32_Processor, often done to detect virtual machines)
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Suricata IDS alerts with low severity for network traffic

Classification

  • System is w10x64
  • main.exe (PID: 7584 cmdline: "C:\Users\user\Desktop\main.exe" MD5: 91D6288DA150030F5BB3520D313B4C3B)
    • conhost.exe (PID: 7592 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
    • main.exe (PID: 7696 cmdline: "C:\Users\user\Desktop\main.exe" MD5: 91D6288DA150030F5BB3520D313B4C3B)
  • cleanup
No configs have been found
No yara matches
No Sigma rule has matched
TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
2024-11-03T06:52:20.012210+010020229301A Network Trojan was detected20.109.210.53443192.168.2.449735TCP
2024-11-03T06:52:58.885422+010020229301A Network Trojan was detected20.109.210.53443192.168.2.449739TCP

Click to jump to signature section

Show All Signature Results

AV Detection

barindex
Source: main.exeVirustotal: Detection: 11%Perma Link
Source: main.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: Binary string: D:\a\1\b\bin\amd64\python312.pdb source: main.exe, 00000002.00000002.1829460779.00007FFDFB810000.00000002.00000001.01000000.00000004.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\unicodedata.pdb source: main.exe, 00000002.00000002.1826417962.00007FFDFA89F000.00000002.00000001.01000000.0000001D.sdmp
Source: Binary string: D:\a\1\b\libcrypto-3.pdb| source: main.exe, 00000002.00000002.1828585678.00007FFDFB35A000.00000002.00000001.01000000.00000012.sdmp
Source: Binary string: D:\a\1\b\libssl-3.pdbDD source: main.exe, 00000002.00000002.1827879391.00007FFDFAEC5000.00000002.00000001.01000000.00000014.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_wmi.pdb(('GCTL source: main.exe, 00000002.00000002.1834391227.00007FFE130C4000.00000002.00000001.01000000.0000000D.sdmp, _wmi.pyd.0.dr
Source: Binary string: @ compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG"OpenSSL 3.0.15 3 Sep 20243.0.15built on: Wed Sep 4 15:52:04 2024 UTCplatform: VC-WIN64A-masmOPENSSLDIR: "C:\Program Files\Common Files\SSL"ENGINESDIR: "C:\Program Files\OpenSSL\lib\engines-3"MODULESDIR: "C:\Program Files\OpenSSL\lib\ossl-modules"CPUINFO: N/Anot availableget_and_lock..\s\crypto\ex_data.cossl_crypto_get_ex_new_index_exossl_crypto_new_ex_data_exCRYPTO_dup_ex_dataCRYPTO_set_ex_dataOPENSSL_WIN32_UTF8..\s\crypto\getenv.ccompiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG";CPUINFO: OPENSSL_ia32cap=0x%llx:0x%llxOPENSSL_ia32cap env:%sos-specificC:\Program Files\Common Files\SSLC:\Program Files\OpenSSL\lib\ossl-modules.dllCPUINFO: ..\s\crypto\init.cOPENSSL_init_cryptoOPENSSL_atexit..\s\crypto\initthread.c..\s\crypto\mem_sec.cassertion failed: (bit & 1) == 0assertion failed: list >= 0 && list < sh.freelist_sizeassertion failed: ((ptr - sh.arena) & ((sh.arena_size >> list) - 1)) == 0assertion failed: bit > 0 && bit < sh.bittable_sizeassertion failed: TESTBIT(table, bit)assertion failed: !TESTBIT(table, bit)assertion failed: WITHIN_FREELIST(list)assertion failed: WITHIN_ARENA(ptr)assertion failed: temp->next == NULL || WITHIN_ARENA(temp->next)assertion failed: (char **)temp->next->p_next == listassertion failed: WITHIN_FREELIST(temp2->p_next) || WITHIN_ARENA(temp2->p_next)assertion failed: size > 0assertion failed: (size & (size - 1)) == 0assertion failed: (minsize & (minsize - 1)) == 0assertion failed: sh.freelist != NULLassertion failed: sh.bittable != NULLassertion failed: sh.bitmalloc != NULLassertion failed: !sh_testbit(temp, slist, sh.bitmalloc)assertion failed: temp != sh.freelist[slist]assertion failed: sh.freelist[slist] == tempassertion failed: temp-(sh.arena_size >> slist) == sh_find_my_buddy(temp, slist)assertion failed: sh_testbit(chunk, list, sh.bittable)assertion failed: WITHIN_ARENA(chunk)assertion failed: sh_testbit(ptr, list, sh.bittable)assertion failed: ptr == sh_find_my_buddy(buddy, list)assertion failed: ptr != NULLassertion failed: !sh_testbit(ptr, list, sh.bitmalloc)assertion failed: sh.freelist[list] == ptr/*0123456789ABCDEFCRYPTO_memdup..\s\crypto\o_str.chexstr2buf_sepossl_hexstr2buf_sepbuf2hexstr_sepossl_buf2hexstr_sep..\s\crypto\packet.cwpacket_intern_init_lenWPACKET_start_sub_packet_len__..\s\crypto\param_build.cparam_pushparam_push_numOSSL_PARAM_BLD_push_BN_padNegative big numbers are unsupported for OSSL_PARAMOSSL_PARAM_BLD_push_utf8_stringOSSL_PARAM_BLD_push_utf8_ptrOSSL_PARAM_BLD_push_octet_stringOSSL_PARAM_BLD_p
Source: Binary string: D:\a\1\b\bin\amd64\_overlapped.pdb source: main.exe, 00000000.00000003.1667991159.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: main.exe, 00000000.00000003.1665998538.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1834001257.00007FFE126F4000.00000002.00000001.01000000.00000005.sdmp
Source: Binary string: compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG" source: main.exe, 00000002.00000002.1828585678.00007FFDFB2C2000.00000002.00000001.01000000.00000012.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdbGCTL source: main.exe, 00000000.00000003.1665998538.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1834001257.00007FFE126F4000.00000002.00000001.01000000.00000005.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_tkinter.pdb source: main.exe, 00000002.00000002.1831127830.00007FFE101D8000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: D:\a\1\b\libcrypto-3.pdb source: main.exe, 00000002.00000002.1828585678.00007FFDFB35A000.00000002.00000001.01000000.00000012.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_multiprocessing.pdb source: main.exe, 00000000.00000003.1667910143.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdb source: main.exe, 00000000.00000003.1666138884.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1834183539.00007FFE12E15000.00000002.00000001.01000000.0000000E.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\select.pdb source: main.exe, 00000002.00000002.1834528698.00007FFE13303000.00000002.00000001.01000000.0000000C.sdmp, select.pyd.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_ctypes.pdb source: main.exe, 00000002.00000002.1833649384.00007FFE126D1000.00000002.00000001.01000000.00000007.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_hashlib.pdb source: main.exe, 00000000.00000003.1666974627.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1831572786.00007FFE10307000.00000002.00000001.01000000.00000011.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_lzma.pdbNN source: main.exe, 00000000.00000003.1667117359.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1832908322.00007FFE11EBB000.00000002.00000001.01000000.0000000A.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_asyncio.pdb source: main.exe, 00000000.00000003.1666228969.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\pyexpat.pdb source: main.exe, 00000002.00000002.1831275137.00007FFE10252000.00000002.00000001.01000000.0000000F.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_queue.pdb source: main.exe, 00000000.00000003.1668083850.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1833462927.00007FFE120C3000.00000002.00000001.01000000.00000010.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_lzma.pdb source: main.exe, 00000000.00000003.1667117359.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1832908322.00007FFE11EBB000.00000002.00000001.01000000.0000000A.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_bz2.pdb source: main.exe, 00000000.00000003.1666360098.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1833278196.00007FFE11EDD000.00000002.00000001.01000000.00000009.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_wmi.pdb source: main.exe, 00000002.00000002.1834391227.00007FFE130C4000.00000002.00000001.01000000.0000000D.sdmp, _wmi.pyd.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_socket.pdb source: main.exe, 00000000.00000003.1668165313.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1832117869.00007FFE11519000.00000002.00000001.01000000.0000000B.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\python3.pdb source: main.exe, 00000002.00000002.1814403344.000001D697450000.00000002.00000001.01000000.00000006.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdbGCTL source: main.exe, 00000000.00000003.1666138884.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1834183539.00007FFE12E15000.00000002.00000001.01000000.0000000E.sdmp
Source: Binary string: D:\a\1\b\libssl-3.pdb source: main.exe, 00000002.00000002.1827879391.00007FFDFAEC5000.00000002.00000001.01000000.00000014.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_ssl.pdb source: main.exe, 00000002.00000002.1830886823.00007FFE0EB4D000.00000002.00000001.01000000.00000013.sdmp
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35C7810 FindFirstFileW,RemoveDirectoryW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,0_2_00007FF7B35C7810
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35C87E0 FindFirstFileExW,FindClose,0_2_00007FF7B35C87E0
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35E2A84 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,0_2_00007FF7B35E2A84
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35C87E0 FindFirstFileExW,FindClose,2_2_00007FF7B35C87E0
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35E2A84 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,2_2_00007FF7B35E2A84
Source: C:\Users\user\Desktop\main.exeFile opened: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\Jump to behavior
Source: C:\Users\user\Desktop\main.exeFile opened: C:\Users\user\AppData\Local\Temp\_MEI75842\Jump to behavior
Source: C:\Users\user\Desktop\main.exeFile opened: C:\Users\user\AppData\Local\Temp\Jump to behavior
Source: C:\Users\user\Desktop\main.exeFile opened: C:\Users\user\AppData\Local\Jump to behavior
Source: C:\Users\user\Desktop\main.exeFile opened: C:\Users\user\AppData\Jump to behavior
Source: C:\Users\user\Desktop\main.exeFile opened: C:\Users\user\Jump to behavior
Source: Joe Sandbox ViewIP Address: 169.197.85.95 169.197.85.95
Source: Network trafficSuricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 20.109.210.53:443 -> 192.168.2.4:49735
Source: Network trafficSuricata IDS: 2022930 - Severity 1 - ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow : 20.109.210.53:443 -> 192.168.2.4:49739
Source: unknownUDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global trafficDNS traffic detected: DNS query: i.ibb.co
Source: main.exe, 00000002.00000002.1825037011.000001D699488000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://.../back.jpeg
Source: main.exe, 00000002.00000002.1824950126.000001D6992D0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://bugs.python.org/issue23606)
Source: main.exe, 00000000.00000003.1838975876.000001BD26EC3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.co
Source: main.exe, 00000000.00000003.1838975876.000001BD26EC3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.co$
Source: main.exe, 00000000.00000003.1666802997.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiC
Source: main.exe, 00000000.00000003.1838975876.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://cacerts.digicert.com/DigiCe
Source: main.exe, 00000000.00000003.1668272048.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666635056.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666228969.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666802997.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667117359.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668165313.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667910143.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1839371494.000001BD26ED6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668083850.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666974627.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667991159.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666360098.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _wmi.pyd.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertAssuredIDRootCA.crt0E
Source: main.exe, 00000000.00000003.1668272048.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666635056.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666228969.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666802997.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667117359.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668165313.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667910143.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668083850.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666974627.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667991159.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666360098.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _wmi.pyd.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crt0
Source: main.exe, 00000000.00000003.1668272048.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666635056.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666228969.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666802997.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667117359.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668165313.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667910143.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668083850.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666974627.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667991159.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666360098.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _wmi.pyd.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crt0
Source: main.exe, 00000000.00000003.1668272048.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666635056.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666228969.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666802997.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667117359.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668165313.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667910143.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1839371494.000001BD26ED6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668083850.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666974627.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667991159.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666360098.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _wmi.pyd.0.drString found in binary or memory: http://cacerts.digicert.com/DigiCertTrustedRootG4.crt0C
Source: main.exe, 00000002.00000003.1805162336.000001D697661000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795183177.000001D697639000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1808806949.000001D697664000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1796277650.000001D697701000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804699405.000001D697722000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1759485920.000001D697716000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1754382093.000001D697716000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1758085717.000001D697716000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1756090650.000001D697716000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802657209.000001D697702000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794517273.000001D6975E2000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795398300.000001D697660000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://code.activestate.com/recipes/577452-a-memoize-decorator-for-instance-methods/
Source: main.exe, 00000002.00000003.1758592599.000001D697AF7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1755658499.000001D697B57000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1809087144.000001D697AF6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1801115049.000001D697ACC000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1799844785.000001D697ACC000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797937359.000001D697ACC000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1761451233.000001D697AF7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1820455951.000001D697AF7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1754290348.000001D697B57000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1754290348.000001D697B18000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://code.activestate.com/recipes/577916/
Source: main.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797726747.000001D6976CB000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807277668.000001D6987A6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795183177.000001D697639000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797431650.000001D6976A6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1809201841.000001D6976DF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1818154964.000001D6976DF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797908449.000001D6976DB000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806885649.000001D698797000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804605192.000001D698794000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794517273.000001D6975E2000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795398300.000001D697660000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806707953.000001D6976DE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.certigna.fr/certignarootca.crl01
Source: main.exe, 00000002.00000003.1803717202.000001D698622000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1808338368.000001D69716C000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795074686.000001D69860D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1796756782.000001D69716C000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805683337.000001D69716C000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1813207828.000001D69716C000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/AAACertificateServices.crl06
Source: main.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl
Source: main.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl-
Source: main.exe, 00000002.00000003.1807433053.000001D697A76000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1820164882.000001D697A79000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797937359.000001D697A75000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.comodoca.com/COMODOCertificationAuthority.crl6e
Source: main.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807277668.000001D6987A6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806885649.000001D698797000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804605192.000001D698794000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.dhimyotis.com/certignarootca.crl
Source: main.exe, 00000002.00000003.1797726747.000001D6976CB000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795183177.000001D697639000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797431650.000001D6976A6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1809201841.000001D6976DF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1818154964.000001D6976DF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797908449.000001D6976DB000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794517273.000001D6975E2000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795398300.000001D697660000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806707953.000001D6976DE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.dhimyotis.com/certignarootca.crl0
Source: main.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.dhimyotis.com/certignarootca.crlw
Source: main.exe, 00000002.00000002.1823433559.000001D698768000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806118626.000001D69875B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806834143.000001D69875C000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/SGCA.crl
Source: main.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/SGCA.crl0
Source: main.exe, 00000002.00000002.1823433559.000001D698768000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806118626.000001D69875B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806834143.000001D69875C000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/STCA.crl
Source: main.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/STCA.crl0
Source: main.exe, 00000002.00000002.1823433559.000001D698768000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806118626.000001D69875B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806834143.000001D69875C000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.securetrust.com/STCA.crlr
Source: main.exe, 00000002.00000003.1793534097.000001D6986AF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1808021528.000001D6986AF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805455063.000001D6986AF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1823250819.000001D6986AF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl
Source: main.exe, 00000002.00000003.1803717202.000001D698622000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795074686.000001D69860D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl.xrampsecurity.com/XGCA.crl0
Source: main.exe, 00000000.00000003.1668272048.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666635056.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666228969.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666802997.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667117359.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668165313.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667910143.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1839371494.000001BD26ED6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668083850.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666974627.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667991159.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666360098.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _wmi.pyd.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertAssuredIDRootCA.crl0
Source: main.exe, 00000000.00000003.1668272048.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666635056.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666228969.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666802997.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667117359.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668165313.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667910143.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668083850.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26EC3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666974627.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667991159.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666360098.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _wmi.pyd.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0S
Source: main.exe, 00000000.00000003.1668272048.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666635056.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666228969.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666802997.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667117359.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668165313.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667910143.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668083850.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666974627.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667991159.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666360098.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _wmi.pyd.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedG4RSA4096SHA256TimeStampingCA.crl0
Source: _wmi.pyd.0.drString found in binary or memory: http://crl3.digicert.com/DigiCertTrustedRootG4.crl0
Source: main.exe, 00000000.00000003.1668083850.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA384
Source: main.exe, 00000000.00000003.1668272048.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666635056.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666228969.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666802997.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667117359.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668165313.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667910143.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668083850.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26EC3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666974627.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667991159.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666360098.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _wmi.pyd.0.drString found in binary or memory: http://crl4.digicert.com/DigiCertTrustedG4CodeSigningRSA4096SHA3842021CA1.crl0
Source: main.exe, 00000002.00000003.1794709862.000001D69862B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1825170214.000001D699510000.00000004.00001000.00020000.00000000.sdmp, main.exe, 00000002.00000002.1823114770.000001D69862D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806994937.000001D69862D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://curl.haxx.se/rfc/cookie_spec.html
Source: main.exe, 00000002.00000002.1822012845.000001D697ED0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://docs.python.org/library/itertools.html#recipes
Source: main.exe, 00000002.00000003.1759247461.000001D697B0F000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1758592599.000001D697B07000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1822012845.000001D697ED0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://foo/bar.tar.gz
Source: main.exe, 00000002.00000003.1759247461.000001D697B0F000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1758592599.000001D697B07000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1822012845.000001D697ED0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://foo/bar.tgz
Source: main.exe, 00000002.00000003.1809719132.000001D6985E2000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795183177.000001D697639000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795074686.000001D6985D7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1817449152.000001D6976AD000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797431650.000001D6976A6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1803839819.000001D6985D9000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794517273.000001D6975E2000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795398300.000001D697660000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://google.com/
Source: main.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://google.com/mail/
Source: main.exe, 00000002.00000003.1796601019.000001D697D67000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794304823.000001D697D63000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804820833.000001D697D68000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://hg.python.org/cpython/file/603b4d593758/Lib/socket.py#l535
Source: main.exe, 00000002.00000003.1808891761.000001D69877B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1823511945.000001D69877C000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806163545.000001D69877A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.accv.es
Source: main.exe, 00000002.00000003.1808891761.000001D69877B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1823511945.000001D69877C000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806163545.000001D69877A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.accv.es%
Source: main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807129538.000001D69877D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806163545.000001D69877A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://ocsp.accv.es0
Source: main.exe, 00000000.00000003.1668272048.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666635056.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666228969.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666802997.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667117359.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668165313.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667910143.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668083850.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26EC3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666974627.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667991159.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666360098.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _wmi.pyd.0.drString found in binary or memory: http://ocsp.digicert.com0
Source: main.exe, 00000000.00000003.1668272048.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666635056.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666228969.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666802997.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667117359.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668165313.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667910143.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1839371494.000001BD26ED6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668083850.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666974627.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667991159.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666360098.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _wmi.pyd.0.drString found in binary or memory: http://ocsp.digicert.com0A
Source: main.exe, 00000000.00000003.1668272048.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666635056.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666228969.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666802997.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667117359.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668165313.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667910143.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1839371494.000001BD26ED6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668083850.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666974627.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667991159.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666360098.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _wmi.pyd.0.drString found in binary or memory: http://ocsp.digicert.com0C
Source: main.exe, 00000000.00000003.1668272048.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666635056.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666228969.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666802997.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667117359.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668165313.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667910143.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668083850.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666974627.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667991159.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666360098.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _wmi.pyd.0.drString found in binary or memory: http://ocsp.digicert.com0X
Source: main.exe, 00000002.00000002.1821925873.000001D697DC0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://opensource.apple.com/source/CF/CF-744.18/CFBinaryPList.c
Source: main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1809296187.000001D697C1A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://repository.swisssign.com/
Source: main.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://repository.swisssign.com/f
Source: main.exe, 00000002.00000003.1809875226.000001D697B2D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805948789.000001D697B17000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1820684603.000001D697B3C000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797937359.000001D697ACC000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1799559383.000001D697B01000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1801115049.000001D697B02000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://tip.tcl.tk/48)
Source: main.exe, 00000002.00000002.1825170214.000001D6994D0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://tools.ietf.org/html/rfc6125#section-6.4.3
Source: main.exe, 00000002.00000003.1808891761.000001D69877B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807129538.000001D69877D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1823511945.000001D69877C000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806163545.000001D69877A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1.crt0
Source: main.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl
Source: main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807129538.000001D69877D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806163545.000001D69877A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1_der.crl0
Source: main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806163545.000001D69877A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/legislacion_c.htm
Source: main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807129538.000001D69877D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806163545.000001D69877A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/legislacion_c.htm0U
Source: main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806163545.000001D69877A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es/legislacion_c.htm?
Source: main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807129538.000001D69877D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806163545.000001D69877A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.accv.es00
Source: main.exe, 00000000.00000003.1739472711.000001BD26EAE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.apache.org/licenses/LICENSE-2.0
Source: main.exe, 00000002.00000002.1821925873.000001D697DC0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: http://www.apple.com/DTDs/PropertyList-1.0.dtd
Source: main.exe, 00000002.00000002.1821760220.000001D697D53000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1808256570.000001D697D51000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1823562297.000001D6987A1000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802945421.000001D697D42000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806757691.000001D697D44000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806885649.000001D698797000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804605192.000001D698794000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1796152323.000001D697D41000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.cert.fnmt.es/dpcs/
Source: main.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.cert.fnmt.es/dpcs/0
Source: main.exe, 00000000.00000003.1668272048.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666635056.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666228969.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666802997.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667117359.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668165313.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667910143.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1668083850.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1838975876.000001BD26EC3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666974627.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1667991159.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000003.1666360098.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, select.pyd.0.dr, _wmi.pyd.0.drString found in binary or memory: http://www.digicert.com/CPS0
Source: main.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1809875226.000001D697B2D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805948789.000001D697B17000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1820684603.000001D697B3C000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797937359.000001D697ACC000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1799559383.000001D697B01000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1801115049.000001D697B02000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.firmaprofesional.com/cps0
Source: main.exe, 00000002.00000003.1795183177.000001D697639000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804464846.000001D69763B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806485762.000001D697642000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794517273.000001D6975E2000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.iana.org/assignments/tls-parameters/tls-parameters.xml#tls-parameters-6
Source: main.exe, 00000002.00000003.1793534097.000001D6986AF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1808021528.000001D6986AF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805455063.000001D6986AF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1823250819.000001D6986AF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.quovadisglobal.com/cps
Source: main.exe, 00000002.00000003.1810059205.000001D697C1E000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1796910286.000001D697C1A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1809296187.000001D697C1A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.quovadisglobal.com/cps0
Source: main.exe, 00000002.00000003.1793534097.000001D6986AF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1808021528.000001D6986AF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805455063.000001D6986AF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1823250819.000001D6986AF000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://www.quovadisglobal.com/cpst
Source: main.exe, 00000000.00000003.1838975876.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1830762935.00007FFE0E188000.00000008.00000001.01000000.00000018.sdmpString found in binary or memory: http://www.zlib.net/D
Source: main.exe, 00000002.00000003.1794709862.000001D69862B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1822881062.000001D698582000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1823114770.000001D69862D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806994937.000001D69862D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: http://wwwsearch.sf.net/):
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://PROJECT_RTD.readthedocs.io/en/latest/?badge=latest
Source: main.exe, 00000002.00000003.1793703061.000001D697C62000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1764334948.000001D697CCE000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821509080.000001D697C79000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821657183.000001D697CB9000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804206735.000001D697C76000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1764794908.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1764334948.000001D697C6A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804979469.000001D697CB7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1803101027.000001D697C6B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://anzeljg.github.io/rin2/book2/2405/docs/tkinter/fonts.html
Source: main.exe, 00000002.00000003.1796601019.000001D697D67000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1793703061.000001D697C62000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821509080.000001D697C79000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794304823.000001D697D63000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804206735.000001D697C76000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D72000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D6B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1803101027.000001D697C6B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://anzeljg.github.io/rin2/book2/2405/docs/tkinter/text.html
Source: main.exe, 00000002.00000002.1822586111.000001D698310000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot
Source: METADATA14.0.drString found in binary or memory: https://backportstarfile.readthedocs.io/en/latest/?badge=latest
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmp, METADATA14.0.dr, METADATA0.0.dr, METADATA15.0.dr, METADATA.0.drString found in binary or memory: https://blog.jaraco.com/skeleton
Source: main.exe, 00000002.00000002.1822195414.000001D698100000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://bugs.python.org/issue44497.
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://coveralls.io/github/agronholm/typeguard?branch=master
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://coveralls.io/repos/agronholm/typeguard/badge.svg?branch=master&service=github
Source: main.exe, 00000002.00000003.1807517996.000001D6979E5000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3.11/library/binascii.html#binascii.a2b_base64
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3.8/library/zipfile.html#path-objects
Source: main.exe, 00000002.00000002.1812814191.000001D69707C000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/howto/mro.html.
Source: main.exe, 00000002.00000002.1812814191.000001D697000000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.ExecutionLoader.get_filename
Source: main.exe, 00000002.00000002.1812814191.000001D69707C000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.InspectLoader.get_code
Source: main.exe, 00000002.00000002.1812814191.000001D69707C000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.InspectLoader.get_source
Source: main.exe, 00000002.00000002.1812814191.000001D69707C000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.InspectLoader.is_package
Source: main.exe, 00000002.00000002.1812814191.000001D697000000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.Loader.create_module
Source: main.exe, 00000002.00000002.1814086284.000001D697350000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.Loader.exec_module
Source: main.exe, 00000002.00000002.1814086284.000001D697350000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.MetaPathFinder.invalidate_caches
Source: main.exe, 00000002.00000002.1812814191.000001D69707C000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.PathEntryFinder.find_spec
Source: main.exe, 00000002.00000002.1812971528.000001D697110000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/importlib.html#importlib.abc.ResourceLoader.get_data
Source: METADATA15.0.drString found in binary or memory: https://docs.python.org/3/library/importlib.metadata.html
Source: main.exe, 00000002.00000003.1795289284.000001D69712F000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1808338368.000001D69713E000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805683337.000001D69713D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://docs.python.org/3/library/multiprocessing.html
Source: METADATA15.0.drString found in binary or memory: https://docs.python.org/3/reference/import.html#finders-and-loaders
Source: main.exe, 00000002.00000002.1824950126.000001D6992D0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://foss.heptapod.net/pypy/pypy/-/issues/3539
Source: main.exe, 00000002.00000002.1822012845.000001D697ED0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbca
Source: METADATA0.0.drString found in binary or memory: https://github.com/Lucretiel/autocommand/issues/18
Source: main.exe, 00000002.00000003.1795183177.000001D697639000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1817449152.000001D6976A1000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797549447.000001D697669000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794517273.000001D6975E2000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795398300.000001D697660000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797886364.000001D6976A0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/Ousret/charset_normalizer
Source: main.exe, 00000002.00000002.1812971528.000001D697110000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/Unidata/MetPy/blob/a3424de66a44bf3a92b0dcacf4dff82ad7b86712/src/metpy/plots/wx_sy
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/agronholm/typeguard
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/agronholm/typeguard/actions/workflows/test.yml
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/agronholm/typeguard/actions/workflows/test.yml/badge.svg
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/agronholm/typeguard/issues
Source: METADATA14.0.dr, METADATA0.0.dr, METADATA15.0.dr, METADATA.0.drString found in binary or memory: https://github.com/astral-sh/ruff
Source: METADATA14.0.drString found in binary or memory: https://github.com/jaraco/backports.tarfile
Source: METADATA14.0.drString found in binary or memory: https://github.com/jaraco/backports.tarfile/actions/workflows/main.yml/badge.svg
Source: METADATA14.0.drString found in binary or memory: https://github.com/jaraco/backports.tarfile/actions?query=workflow%3A%22tests%22
Source: METADATA0.0.drString found in binary or memory: https://github.com/jaraco/jaraco.context
Source: METADATA0.0.drString found in binary or memory: https://github.com/jaraco/jaraco.context/actions/workflows/main.yml/badge.svg
Source: METADATA0.0.drString found in binary or memory: https://github.com/jaraco/jaraco.context/actions?query=workflow%3A%22tests%22
Source: METADATA.0.drString found in binary or memory: https://github.com/jaraco/jaraco.functools
Source: METADATA.0.drString found in binary or memory: https://github.com/jaraco/jaraco.functools/actions/workflows/main.yml/badge.svg
Source: METADATA.0.drString found in binary or memory: https://github.com/jaraco/jaraco.functools/actions?query=workflow%3A%22tests%22
Source: main.exe, 00000002.00000002.1822012845.000001D697ED0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/jaraco/jaraco.functools/issues/5
Source: METADATA0.0.drString found in binary or memory: https://github.com/jaraco/keyring/commit/a85a7cbc6c909f8121660ed1f7b487f99a1c2bf7
Source: main.exe, 00000002.00000002.1822195414.000001D698100000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/platformdirs/platformdirs
Source: main.exe, 00000002.00000002.1825470399.000001D6995D0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/psf/requests/pull/6710
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/.github/blob/main/CODE_OF_CONDUCT.md
Source: main.exe, 00000002.00000002.1822012845.000001D697ED0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/packaging
Source: main.exe, 00000002.00000002.1822290542.000001D698210000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/setuptools/issues/1024.
Source: main.exe, 00000002.00000002.1819470816.000001D6978C0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/setuptools/issues/417#issuecomment-392298401
Source: main.exe, 00000002.00000002.1822195414.000001D698100000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/setuptools/issues/new?template=distutils-deprecation.yml
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/wheel
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/pypa/wheel/issues
Source: main.exe, 00000002.00000002.1822697021.000001D698410000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/python-pillow/Pillow/
Source: main.exe, 00000002.00000002.1812814191.000001D697000000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/blob/3.9/Lib/importlib/_bootstrap_external.py#L679-L688
Source: main.exe, 00000002.00000002.1812971528.000001D697110000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/blob/839d7893943782ee803536a47f1d4de160314f85/Lib/importlib/abc.py
Source: main.exe, 00000002.00000002.1812971528.000001D697110000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/blob/839d7893943782ee803536a47f1d4de160314f85/Lib/importlib/reader
Source: main.exe, 00000002.00000003.1794235892.000001D69718A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1751064719.000001D69770B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1813869078.000001D6971E0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794495869.000001D6971DE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/cpython/issues/86361.
Source: METADATA15.0.drString found in binary or memory: https://github.com/python/importlib_metadata
Source: METADATA15.0.drString found in binary or memory: https://github.com/python/importlib_metadata/actions/workflows/main.yml/badge.svg
Source: METADATA15.0.drString found in binary or memory: https://github.com/python/importlib_metadata/actions?query=workflow%3A%22tests%22
Source: METADATA15.0.drString found in binary or memory: https://github.com/python/importlib_metadata/issues
Source: main.exe, 00000002.00000002.1822012845.000001D697ED0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/python/importlib_metadata/wiki/Development-Methodology
Source: main.exe, 00000002.00000002.1812971528.000001D697110000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/tensorflow/datasets/blob/master/tensorflow_datasets/core/utils/resource_utils.py#
Source: main.exe, 00000002.00000002.1824950126.000001D6992D0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/2192#issuecomment-821832963
Source: main.exe, 00000002.00000003.1793703061.000001D697C62000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821509080.000001D697C70000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1803101027.000001D697C6B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/2513#issuecomment-1152559900.
Source: main.exe, 00000002.00000002.1825037011.000001D699488000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/2920
Source: main.exe, 00000002.00000002.1825037011.000001D699488000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://github.com/urllib3/urllib3/issues/3290
Source: main.exe, 00000002.00000003.1808650169.000001D697A31000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805250576.000001D69860D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795183177.000001D697639000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1817449152.000001D6976AD000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797431650.000001D6976A6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795074686.000001D69860D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805856231.000001D698612000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807215037.000001D697A29000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807101539.000001D6971FB000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1808832495.000001D697A34000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1803576833.000001D697A26000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794173302.000001D6971F0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797655692.000001D6971F7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1811104557.000001D697A42000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794517273.000001D6975E2000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1810296670.000001D697A3E000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795398300.000001D697660000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806994937.000001D698618000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://google.com/
Source: main.exe, 00000002.00000003.1808650169.000001D697A31000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795183177.000001D697639000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1817449152.000001D6976AD000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797431650.000001D6976A6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807215037.000001D697A29000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1808832495.000001D697A34000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1803576833.000001D697A26000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1811104557.000001D697A42000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794517273.000001D6975E2000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1810296670.000001D697A3E000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795398300.000001D697660000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://google.com/mail
Source: main.exe, 00000002.00000003.1801115049.000001D697B02000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://google.com/mail/
Source: main.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://html.spec.whatwg.org/multipage/
Source: main.exe, 00000002.00000003.1806994937.000001D698618000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/
Source: main.exe, 00000002.00000002.1825170214.000001D6994D0000.00000004.00001000.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1809296187.000001D697C1A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/get
Source: main.exe, 00000002.00000003.1793703061.000001D697C62000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821509080.000001D697C79000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804206735.000001D697C76000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1803101027.000001D697C6B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://httpbin.org/post
Source: main.exe, 00000002.00000002.1825470399.000001D6995F8000.00000004.00001000.00020000.00000000.sdmp, main.exe, 00000002.00000002.1822586111.000001D698310000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://i.ibb.co/f9BPTny/Nouveau-projet-2-1.png
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmp, METADATA14.0.dr, METADATA0.0.dr, METADATA15.0.dr, METADATA.0.drString found in binary or memory: https://img.shields.io/badge/skeleton-2024-informational
Source: METADATA14.0.dr, METADATA0.0.dr, METADATA15.0.dr, METADATA.0.drString found in binary or memory: https://img.shields.io/endpoint?url=https://raw.githubusercontent.com/charliermarsh/ruff/main/assets
Source: METADATA14.0.drString found in binary or memory: https://img.shields.io/pypi/pyversions/backports.tarfile.svg
Source: METADATA15.0.drString found in binary or memory: https://img.shields.io/pypi/pyversions/importlib_metadata.svg
Source: METADATA0.0.drString found in binary or memory: https://img.shields.io/pypi/pyversions/jaraco.context.svg
Source: METADATA.0.drString found in binary or memory: https://img.shields.io/pypi/pyversions/jaraco.functools.svg
Source: METADATA14.0.drString found in binary or memory: https://img.shields.io/pypi/v/backports.tarfile.svg
Source: METADATA15.0.drString found in binary or memory: https://img.shields.io/pypi/v/importlib_metadata.svg
Source: METADATA0.0.drString found in binary or memory: https://img.shields.io/pypi/v/jaraco.context.svg
Source: METADATA.0.drString found in binary or memory: https://img.shields.io/pypi/v/jaraco.functools.svg
Source: METADATA15.0.drString found in binary or memory: https://importlib-metadata.readthedocs.io/
Source: METADATA15.0.drString found in binary or memory: https://importlib-metadata.readthedocs.io/en/latest/?badge=latest
Source: main.exe, 00000002.00000002.1821925873.000001D697DC0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://importlib-resources.readthedocs.io/en/latest/using.html#migrating-from-legacy
Source: METADATA0.0.drString found in binary or memory: https://jaracocontext.readthedocs.io/en/latest/?badge=latest
Source: METADATA.0.drString found in binary or memory: https://jaracofunctools.readthedocs.io/en/latest/?badge=latest
Source: main.exe, 00000002.00000003.1803101027.000001D697C6B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://json.org
Source: main.exe, 00000002.00000003.1808502903.000001D697B02000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1759374271.000001D697B57000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797937359.000001D697ACC000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1799559383.000001D697B01000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1761451233.000001D697AF7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1820516001.000001D697B03000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1757664941.000001D697B57000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1758592599.000001D697B07000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1801115049.000001D697B02000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806620146.000001D697B02000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://mahler:8092/site-updates.py
Source: main.exe, 00000002.00000002.1822290542.000001D698210000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/en/latest/guides/packaging-namespace-packages/.
Source: main.exe, 00000002.00000002.1822586111.000001D698310000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/en/latest/specifications/core-metadata/
Source: main.exe, 00000002.00000002.1822290542.000001D698210000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/en/latest/specifications/entry-points/
Source: main.exe, 00000002.00000002.1822290542.000001D698210000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/en/latest/specifications/entry-points/P
Source: main.exe, 00000002.00000003.1804902377.000001D697A86000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1799844785.000001D697A85000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1820164882.000001D697A86000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797937359.000001D697A75000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/en/latest/specifications/pyproject-toml/#declaring-project-metadata-the
Source: main.exe, 00000002.00000002.1822195414.000001D698100000.00000004.00001000.00020000.00000000.sdmp, main.exe, 00000002.00000002.1822290542.000001D698210000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://packaging.python.org/specifications/entry-points/
Source: METADATA0.0.drString found in binary or memory: https://path.readthedocs.io/en/latest/api.html
Source: main.exe, 00000002.00000002.1819262665.000001D6977A0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://peps.python.org/pep-0205/
Source: main.exe, 00000002.00000002.1829460779.00007FFDFB810000.00000002.00000001.01000000.00000004.sdmpString found in binary or memory: https://peps.python.org/pep-0263/
Source: main.exe, 00000002.00000002.1822586111.000001D698310000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://peps.python.org/pep-0685/
Source: METADATA14.0.drString found in binary or memory: https://pypi.org/project/backports.tarfile
Source: main.exe, 00000002.00000002.1822195414.000001D698100000.00000004.00001000.00020000.00000000.sdmp, main.exe, 00000002.00000002.1822290542.000001D698210000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://pypi.org/project/build/).
Source: METADATA15.0.drString found in binary or memory: https://pypi.org/project/importlib_metadata
Source: METADATA0.0.drString found in binary or memory: https://pypi.org/project/jaraco.context
Source: METADATA.0.drString found in binary or memory: https://pypi.org/project/jaraco.functools
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://pypi.org/project/setuptools/
Source: METADATA14.0.drString found in binary or memory: https://readthedocs.org/projects/backportstarfile/badge/?version=latest
Source: METADATA15.0.drString found in binary or memory: https://readthedocs.org/projects/importlib-metadata/badge/?version=latest
Source: METADATA0.0.drString found in binary or memory: https://readthedocs.org/projects/jaracocontext/badge/?version=latest
Source: METADATA.0.drString found in binary or memory: https://readthedocs.org/projects/jaracofunctools/badge/?version=latest
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://readthedocs.org/projects/typeguard/badge/?version=latest
Source: main.exe, 00000002.00000002.1822012845.000001D697ED0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://refspecs.linuxfoundation.org/elf/gabi4
Source: main.exe, 00000002.00000003.1793703061.000001D697C62000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821509080.000001D697C79000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804206735.000001D697C76000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1825170214.000001D6995BC000.00000004.00001000.00020000.00000000.sdmp, main.exe, 00000002.00000003.1803101027.000001D697C6B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://requests.readthedocs.io
Source: main.exe, 00000002.00000002.1825170214.000001D6995BC000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://requests.readthedocs.io$
Source: main.exe, 00000002.00000002.1822290542.000001D698210000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/
Source: main.exe, 00000002.00000003.1751753731.000001D697727000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1751693738.000001D697A7A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/pkg_resources.html
Source: main.exe, 00000002.00000003.1795398300.000001D697746000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1751753731.000001D697727000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1751693738.000001D697A33000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1758085717.000001D697746000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802657209.000001D697755000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1751693738.000001D697A7A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1753616758.000001D697746000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1796507200.000001D697754000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1752588215.000001D697746000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1754382093.000001D697746000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1759485920.000001D697746000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1756090650.000001D697746000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/pkg_resources.html#basic-resource-access
Source: main.exe, 00000002.00000002.1821925873.000001D697DC0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/references/keywords.html#keyword-namespace-packages
Source: main.exe, 00000002.00000002.1821925873.000001D697DC0000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/references/keywords.html#keyword-namespace-packages0C
Source: main.exe, 00000002.00000003.1751693738.000001D697A33000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1751693738.000001D697A7A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/references/keywords.html#keyword-namespace-packagesr;
Source: main.exe, 00000002.00000003.1751693738.000001D697A33000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1751693738.000001D697A7A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://setuptools.pypa.io/en/latest/references/keywords.html#keyword-namespace-packagesr;r
Source: main.exe, 00000002.00000002.1822586111.000001D698310000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://spclient.wg.spotify.com/signup/public/v1/account/?validate=1&suggest=1&key=142b583129b2df829
Source: main.exe, 00000002.00000002.1822697021.000001D698410000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/questions/11993290/truly-custom-font-in-tkinter/30631309#30631309
Source: main.exe, 00000002.00000002.1822697021.000001D698410000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://stackoverflow.com/questions/23836000/can-i-change-the-title-bar-in-tkinter/70724666#70724666
Source: main.exe, 00000002.00000002.1824236271.000001D6989A1000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://support.apple.com/en-us/HT20
Source: tk.tcl.0.drString found in binary or memory: https://support.apple.com/en-us/HT201236
Source: main.exe, 00000002.00000002.1822586111.000001D698310000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://t.me/deepwing
Source: METADATA15.0.drString found in binary or memory: https://tidelift.com/badges/package/pypi/importlib-metadata
Source: METADATA0.0.drString found in binary or memory: https://tidelift.com/badges/package/pypi/jaraco.context
Source: METADATA.0.drString found in binary or memory: https://tidelift.com/badges/package/pypi/jaraco.functools
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tidelift.com/badges/package/pypi/zipp
Source: METADATA15.0.drString found in binary or memory: https://tidelift.com/subscription/pkg/pypi-importlib-metadata?utm_source=pypi-importlib-metadata&utm
Source: METADATA0.0.drString found in binary or memory: https://tidelift.com/subscription/pkg/pypi-jaraco.context?utm_source=pypi-jaraco.context&utm_medium=
Source: METADATA.0.drString found in binary or memory: https://tidelift.com/subscription/pkg/pypi-jaraco.functools?utm_source=pypi-jaraco.functools&utm_med
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tidelift.com/subscription/pkg/pypi-zipp?utm_source=pypi-zipp&utm_medium=readme
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tidelift.com/subscription/pkg/pypi-zipp?utm_source=pypi-zipp&utm_medium=referral&utm_campaig
Source: main.exe, 00000002.00000003.1797726747.000001D6976CB000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795183177.000001D697639000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797431650.000001D6976A6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805904213.000001D6976CC000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1817449152.000001D6976CC000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794517273.000001D6975E2000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795398300.000001D697660000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/rfc2388#section-4.4
Source: main.exe, 00000002.00000003.1761451233.000001D697AF7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805031409.000001D697581000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1810747879.000001D69758E000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1761177341.000001D697B27000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://tools.ietf.org/html/rfc7231#section-4.3.6)
Source: main.exe, 00000002.00000003.1805250576.000001D69860D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795074686.000001D69860D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805856231.000001D698612000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807101539.000001D6971FB000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794173302.000001D6971F0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797655692.000001D6971F7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806994937.000001D698618000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://twitter.com/
Source: main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://typeguard.readthedocs.io/en/latest/
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://typeguard.readthedocs.io/en/latest/?badge=latest
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://typeguard.readthedocs.io/en/latest/versionhistory.html
Source: main.exe, 00000002.00000002.1825037011.000001D699488000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io/en/latest/advanced-usage.html#https-proxy-error-http-proxy
Source: main.exe, 00000002.00000002.1825037011.000001D699464000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io/en/latest/advanced-usage.html#tls-warnings
Source: main.exe, 00000002.00000003.1809719132.000001D6985E2000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795074686.000001D6985D7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1803839819.000001D6985D9000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io/en/latest/advanced-usage.html#tls-warningsN
Source: main.exe, 00000002.00000002.1825037011.000001D699464000.00000004.00001000.00020000.00000000.sdmpString found in binary or memory: https://urllib3.readthedocs.io/en/latest/advanced-usage.html#tls-warningsP
Source: main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wheel.readthedocs.io/
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wheel.readthedocs.io/en/stable/news.html
Source: main.exe, 00000002.00000003.1758592599.000001D697AF7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1755658499.000001D697B57000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1809087144.000001D697AF6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1801115049.000001D697ACC000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1799844785.000001D697ACC000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797937359.000001D697ACC000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1761451233.000001D697AF7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1820455951.000001D697AF7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1754290348.000001D697B57000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1754290348.000001D697B18000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www-cs-faculty.stanford.edu/~knuth/fasc2a.ps.gz
Source: main.exe, 00000002.00000002.1827940144.00007FFDFAF00000.00000002.00000001.01000000.00000014.sdmp, main.exe, 00000002.00000002.1829028032.00007FFDFB404000.00000002.00000001.01000000.00000012.sdmpString found in binary or memory: https://www.openssl.org/H
Source: main.exe, 00000002.00000003.1793703061.000001D697C62000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821509080.000001D697C79000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804206735.000001D697C76000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1803101027.000001D697C6B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.python.org
Source: main.exe, 00000002.00000003.1808502903.000001D697B02000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1759374271.000001D697B57000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797937359.000001D697ACC000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1799559383.000001D697B01000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1761451233.000001D697AF7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1820516001.000001D697B03000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1757664941.000001D697B57000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1758592599.000001D697B07000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1801115049.000001D697B02000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806620146.000001D697B02000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.python.org/
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.python.org/dev/peps/pep-0427/
Source: main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.python.org/dev/peps/pep-0484/
Source: main.exe, 00000002.00000002.1829940629.00007FFDFB9A3000.00000004.00000001.01000000.00000004.sdmpString found in binary or memory: https://www.python.org/psf/license/
Source: main.exe, 00000002.00000002.1829460779.00007FFDFB810000.00000002.00000001.01000000.00000004.sdmpString found in binary or memory: https://www.python.org/psf/license/)
Source: main.exe, 00000002.00000003.1795398300.000001D697746000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805250576.000001D69860D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804699405.000001D697746000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807812178.000001D697746000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795074686.000001D69860D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805856231.000001D698612000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1818529585.000001D69774A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802657209.000001D697746000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806994937.000001D698618000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1810380047.000001D697746000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1811046239.000001D697749000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://www.rfc-editor.org/rfc/rfc8259#section-8.1
Source: main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1823609428.000001D6987BA000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806885649.000001D6987B4000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1803240027.000001D6987B0000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wwww.certigna.fr/autorites/
Source: main.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797726747.000001D6976CB000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795183177.000001D697639000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797431650.000001D6976A6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1809201841.000001D6976DF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1818154964.000001D6976DF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797908449.000001D6976DB000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794517273.000001D6975E2000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795398300.000001D697660000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806707953.000001D6976DE000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://wwww.certigna.fr/autorites/0m
Source: main.exe, 00000002.00000003.1808650169.000001D697A31000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795183177.000001D697639000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1817449152.000001D6976AD000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797431650.000001D6976A6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807215037.000001D697A29000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1808832495.000001D697A34000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1803576833.000001D697A26000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1811104557.000001D697A42000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794517273.000001D6975E2000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1810296670.000001D697A3E000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795398300.000001D697660000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://yahoo.com/
Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49731
Source: unknownNetwork traffic detected: HTTP traffic on port 49731 -> 443
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35E7B740_2_00007FF7B35E7B74
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35C7E300_2_00007FF7B35C7E30
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35E6E100_2_00007FF7B35E6E10
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35D6C900_2_00007FF7B35D6C90
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35D14D80_2_00007FF7B35D14D8
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35D0CB80_2_00007FF7B35D0CB8
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35D3B280_2_00007FF7B35D3B28
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35D43F00_2_00007FF7B35D43F0
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35D23C00_2_00007FF7B35D23C0
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35E2A840_2_00007FF7B35E2A84
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35E1AD80_2_00007FF7B35E1AD8
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35DEAC40_2_00007FF7B35DEAC4
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35E52BC0_2_00007FF7B35E52BC
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35D12CC0_2_00007FF7B35D12CC
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35EA9380_2_00007FF7B35EA938
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35CA20D0_2_00007FF7B35CA20D
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35C99DB0_2_00007FF7B35C99DB
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35E708C0_2_00007FF7B35E708C
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35C983B0_2_00007FF7B35C983B
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35D10C80_2_00007FF7B35D10C8
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35DEF580_2_00007FF7B35DEF58
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35D27580_2_00007FF7B35D2758
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35D3F2C0_2_00007FF7B35D3F2C
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35D8FC00_2_00007FF7B35D8FC0
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35D96700_2_00007FF7B35D9670
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35E4E200_2_00007FF7B35E4E20
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35E1AD80_2_00007FF7B35E1AD8
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35E76280_2_00007FF7B35E7628
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35D16DC0_2_00007FF7B35D16DC
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35D36F00_2_00007FF7B35D36F0
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35D0EBC0_2_00007FF7B35D0EBC
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35C8D600_2_00007FF7B35C8D60
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35DF5D80_2_00007FF7B35DF5D8
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35DADC00_2_00007FF7B35DADC0
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35E7B742_2_00007FF7B35E7B74
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35D3F2C2_2_00007FF7B35D3F2C
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35D6C902_2_00007FF7B35D6C90
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35D14D82_2_00007FF7B35D14D8
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35D0CB82_2_00007FF7B35D0CB8
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35D3B282_2_00007FF7B35D3B28
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35D43F02_2_00007FF7B35D43F0
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35D23C02_2_00007FF7B35D23C0
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35E2A842_2_00007FF7B35E2A84
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35E1AD82_2_00007FF7B35E1AD8
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35DEAC42_2_00007FF7B35DEAC4
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35E52BC2_2_00007FF7B35E52BC
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35D12CC2_2_00007FF7B35D12CC
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35EA9382_2_00007FF7B35EA938
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35CA20D2_2_00007FF7B35CA20D
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35C99DB2_2_00007FF7B35C99DB
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFDFADE02D02_2_00007FFDFADE02D0
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFDFAD11BD02_2_00007FFDFAD11BD0
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFDFACB73A02_2_00007FFDFACB73A0
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFDFACF4B902_2_00007FFDFACF4B90
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFDFAC810FE2_2_00007FFDFAC810FE
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFDFAC960C02_2_00007FFDFAC960C0
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFDFAC9C9F82_2_00007FFDFAC9C9F8
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFDFAC990502_2_00007FFDFAC99050
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFDFAD37FE02_2_00007FFDFAD37FE0
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFDFACF3D602_2_00007FFDFACF3D60
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFDFACF6B302_2_00007FFDFACF6B30
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFDFACD7B402_2_00007FFDFACD7B40
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFDFADAAAD02_2_00007FFDFADAAAD0
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFDFAD9EA902_2_00007FFDFAD9EA90
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFDFADC42602_2_00007FFDFADC4260
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFDFADB5A602_2_00007FFDFADB5A60
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFE0CFD09802_2_00007FFE0CFD0980
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFE0CFCC4802_2_00007FFE0CFCC480
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFE0E1626F02_2_00007FFE0E1626F0
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFE0E16F7302_2_00007FFE0E16F730
Source: C:\Users\user\Desktop\main.exeCode function: String function: 00007FFDFAD7A3F0 appears 255 times
Source: C:\Users\user\Desktop\main.exeCode function: String function: 00007FF7B35C1E50 appears 90 times
Source: C:\Users\user\Desktop\main.exeCode function: String function: 00007FFE0CFC3880 appears 114 times
Source: C:\Users\user\Desktop\main.exeCode function: String function: 00007FFE0CFC3800 appears 51 times
Source: unicodedata.pyd.0.drStatic PE information: Resource name: RT_VERSION type: COM executable for DOS
Source: _overlapped.pyd.0.drStatic PE information: Resource name: RT_VERSION type: COM executable for DOS
Source: zlib1.dll.0.drStatic PE information: Number of sections : 12 > 10
Source: python3.dll.0.drStatic PE information: No import functions for PE file found
Source: main.exe, 00000000.00000003.1668272048.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename_ssl.pyd. vs main.exe
Source: main.exe, 00000000.00000003.1666635056.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename_ctypes.pyd. vs main.exe
Source: main.exe, 00000000.00000003.1665998538.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140.dllT vs main.exe
Source: main.exe, 00000000.00000003.1666228969.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename_asyncio.pyd. vs main.exe
Source: main.exe, 00000000.00000003.1666802997.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename_decimal.pyd. vs main.exe
Source: main.exe, 00000000.00000003.1667117359.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename_lzma.pyd. vs main.exe
Source: main.exe, 00000000.00000003.1668165313.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename_socket.pyd. vs main.exe
Source: main.exe, 00000000.00000003.1667910143.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename_multiprocessing.pyd. vs main.exe
Source: main.exe, 00000000.00000003.1666138884.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenamevcruntime140_1.dllT vs main.exe
Source: main.exe, 00000000.00000003.1668083850.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename_queue.pyd. vs main.exe
Source: main.exe, 00000000.00000003.1666974627.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename_hashlib.pyd. vs main.exe
Source: main.exe, 00000000.00000003.1667991159.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename_overlapped.pyd. vs main.exe
Source: main.exe, 00000000.00000003.1666360098.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilename_bz2.pyd. vs main.exe
Source: main.exeBinary or memory string: OriginalFilename vs main.exe
Source: main.exe, 00000002.00000002.1834247811.00007FFE12E19000.00000002.00000001.01000000.0000000E.sdmpBinary or memory string: OriginalFilenamevcruntime140_1.dllT vs main.exe
Source: main.exe, 00000002.00000002.1831010005.00007FFE0EB69000.00000002.00000001.01000000.00000013.sdmpBinary or memory string: OriginalFilename_ssl.pyd. vs main.exe
Source: main.exe, 00000002.00000002.1831434867.00007FFE1025E000.00000002.00000001.01000000.0000000F.sdmpBinary or memory string: OriginalFilenamepyexpat.pyd. vs main.exe
Source: main.exe, 00000002.00000002.1831189877.00007FFE101DE000.00000002.00000001.01000000.00000015.sdmpBinary or memory string: OriginalFilename_tkinter.pyd. vs main.exe
Source: main.exe, 00000002.00000002.1833368812.00007FFE11EE2000.00000002.00000001.01000000.00000009.sdmpBinary or memory string: OriginalFilename_bz2.pyd. vs main.exe
Source: main.exe, 00000002.00000002.1834449014.00007FFE130C8000.00000002.00000001.01000000.0000000D.sdmpBinary or memory string: OriginalFilename_wmi.pyd. vs main.exe
Source: main.exe, 00000002.00000002.1826699759.00007FFDFA8A4000.00000002.00000001.01000000.0000001D.sdmpBinary or memory string: OriginalFilenameunicodedata.pyd. vs main.exe
Source: main.exe, 00000002.00000002.1830762935.00007FFE0E188000.00000008.00000001.01000000.00000018.sdmpBinary or memory string: OriginalFilenamezlib1.dll* vs main.exe
Source: main.exe, 00000002.00000002.1827940144.00007FFDFAF00000.00000002.00000001.01000000.00000014.sdmpBinary or memory string: OriginalFilenamelibsslH vs main.exe
Source: main.exe, 00000002.00000002.1831737011.00007FFE1030E000.00000002.00000001.01000000.00000011.sdmpBinary or memory string: OriginalFilename_hashlib.pyd. vs main.exe
Source: main.exe, 00000002.00000002.1827514343.00007FFDFAC55000.00000002.00000001.01000000.00000017.sdmpBinary or memory string: OriginalFilenametk86.dllP vs main.exe
Source: main.exe, 00000002.00000002.1834586963.00007FFE13306000.00000002.00000001.01000000.0000000C.sdmpBinary or memory string: OriginalFilenameselect.pyd. vs main.exe
Source: main.exe, 00000002.00000002.1833056144.00007FFE11EC4000.00000002.00000001.01000000.0000000A.sdmpBinary or memory string: OriginalFilename_lzma.pyd. vs main.exe
Source: main.exe, 00000002.00000002.1834061711.00007FFE126FA000.00000002.00000001.01000000.00000005.sdmpBinary or memory string: OriginalFilenamevcruntime140.dllT vs main.exe
Source: main.exe, 00000002.00000002.1829028032.00007FFDFB404000.00000002.00000001.01000000.00000012.sdmpBinary or memory string: OriginalFilenamelibcryptoH vs main.exe
Source: main.exe, 00000002.00000002.1833717055.00007FFE126DE000.00000002.00000001.01000000.00000007.sdmpBinary or memory string: OriginalFilename_ctypes.pyd. vs main.exe
Source: main.exe, 00000002.00000002.1833551113.00007FFE120C6000.00000002.00000001.01000000.00000010.sdmpBinary or memory string: OriginalFilename_queue.pyd. vs main.exe
Source: main.exe, 00000002.00000002.1814403344.000001D697450000.00000002.00000001.01000000.00000006.sdmpBinary or memory string: OriginalFilenamepython3.dll. vs main.exe
Source: main.exe, 00000002.00000002.1832188491.00007FFE11523000.00000002.00000001.01000000.0000000B.sdmpBinary or memory string: OriginalFilename_socket.pyd. vs main.exe
Source: main.exe, 00000002.00000002.1830418129.00007FFDFBAAE000.00000002.00000001.01000000.00000004.sdmpBinary or memory string: OriginalFilenamepython312.dll. vs main.exe
Source: main.exe, 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpBinary or memory string: OriginalFilenametcl86.dllP vs main.exe
Source: classification engineClassification label: mal48.winEXE@4/1026@1/1
Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7592:120:WilError_03
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842Jump to behavior
Source: main.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Users\user\Desktop\main.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT Architecture FROM Win32_Processor
Source: C:\Users\user\Desktop\main.exeKey opened: HKEY_LOCAL_MACHINE\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
Source: main.exeVirustotal: Detection: 11%
Source: main.exeString found in binary or memory: -help
Source: main.exeString found in binary or memory: -startline must be less than or equal to -endline
Source: C:\Users\user\Desktop\main.exeFile read: C:\Users\user\Desktop\main.exeJump to behavior
Source: unknownProcess created: C:\Users\user\Desktop\main.exe "C:\Users\user\Desktop\main.exe"
Source: C:\Users\user\Desktop\main.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
Source: C:\Users\user\Desktop\main.exeProcess created: C:\Users\user\Desktop\main.exe "C:\Users\user\Desktop\main.exe"
Source: C:\Users\user\Desktop\main.exeProcess created: C:\Users\user\Desktop\main.exe "C:\Users\user\Desktop\main.exe"Jump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: version.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: vcruntime140.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: libffi-8.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: iphlpapi.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: propsys.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: vcruntime140_1.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: libcrypto-3.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: libssl-3.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: tcl86t.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: tk86t.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: netapi32.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: userenv.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: zlib1.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: logoncli.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: netutils.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: samcli.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: kernel.appcore.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: uxtheme.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: wbemcomn.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: amsi.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: profapi.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: wbemcomn.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: mswsock.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: textinputframework.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: coreuicomponents.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: ntmarta.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: coremessaging.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: wintypes.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: dwmapi.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: textshaping.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: dnsapi.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: rasadhlp.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeSection loaded: fwpuclnt.dllJump to behavior
Source: C:\Users\user\Desktop\main.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4590F811-1D3A-11D0-891F-00AA004B2E24}\InprocServer32Jump to behavior
Source: Window RecorderWindow detected: More than 3 window changes detected
Source: main.exeStatic PE information: Image base 0x140000000 > 0x60000000
Source: main.exeStatic file information: File size 20202747 > 1048576
Source: main.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IMPORT
Source: main.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_RESOURCE
Source: main.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_BASERELOC
Source: main.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: main.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG
Source: main.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_IAT
Source: main.exeStatic PE information: HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
Source: main.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG
Source: Binary string: D:\a\1\b\bin\amd64\python312.pdb source: main.exe, 00000002.00000002.1829460779.00007FFDFB810000.00000002.00000001.01000000.00000004.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\unicodedata.pdb source: main.exe, 00000002.00000002.1826417962.00007FFDFA89F000.00000002.00000001.01000000.0000001D.sdmp
Source: Binary string: D:\a\1\b\libcrypto-3.pdb| source: main.exe, 00000002.00000002.1828585678.00007FFDFB35A000.00000002.00000001.01000000.00000012.sdmp
Source: Binary string: D:\a\1\b\libssl-3.pdbDD source: main.exe, 00000002.00000002.1827879391.00007FFDFAEC5000.00000002.00000001.01000000.00000014.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_wmi.pdb(('GCTL source: main.exe, 00000002.00000002.1834391227.00007FFE130C4000.00000002.00000001.01000000.0000000D.sdmp, _wmi.pyd.0.dr
Source: Binary string: @ compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG"OpenSSL 3.0.15 3 Sep 20243.0.15built on: Wed Sep 4 15:52:04 2024 UTCplatform: VC-WIN64A-masmOPENSSLDIR: "C:\Program Files\Common Files\SSL"ENGINESDIR: "C:\Program Files\OpenSSL\lib\engines-3"MODULESDIR: "C:\Program Files\OpenSSL\lib\ossl-modules"CPUINFO: N/Anot availableget_and_lock..\s\crypto\ex_data.cossl_crypto_get_ex_new_index_exossl_crypto_new_ex_data_exCRYPTO_dup_ex_dataCRYPTO_set_ex_dataOPENSSL_WIN32_UTF8..\s\crypto\getenv.ccompiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG";CPUINFO: OPENSSL_ia32cap=0x%llx:0x%llxOPENSSL_ia32cap env:%sos-specificC:\Program Files\Common Files\SSLC:\Program Files\OpenSSL\lib\ossl-modules.dllCPUINFO: ..\s\crypto\init.cOPENSSL_init_cryptoOPENSSL_atexit..\s\crypto\initthread.c..\s\crypto\mem_sec.cassertion failed: (bit & 1) == 0assertion failed: list >= 0 && list < sh.freelist_sizeassertion failed: ((ptr - sh.arena) & ((sh.arena_size >> list) - 1)) == 0assertion failed: bit > 0 && bit < sh.bittable_sizeassertion failed: TESTBIT(table, bit)assertion failed: !TESTBIT(table, bit)assertion failed: WITHIN_FREELIST(list)assertion failed: WITHIN_ARENA(ptr)assertion failed: temp->next == NULL || WITHIN_ARENA(temp->next)assertion failed: (char **)temp->next->p_next == listassertion failed: WITHIN_FREELIST(temp2->p_next) || WITHIN_ARENA(temp2->p_next)assertion failed: size > 0assertion failed: (size & (size - 1)) == 0assertion failed: (minsize & (minsize - 1)) == 0assertion failed: sh.freelist != NULLassertion failed: sh.bittable != NULLassertion failed: sh.bitmalloc != NULLassertion failed: !sh_testbit(temp, slist, sh.bitmalloc)assertion failed: temp != sh.freelist[slist]assertion failed: sh.freelist[slist] == tempassertion failed: temp-(sh.arena_size >> slist) == sh_find_my_buddy(temp, slist)assertion failed: sh_testbit(chunk, list, sh.bittable)assertion failed: WITHIN_ARENA(chunk)assertion failed: sh_testbit(ptr, list, sh.bittable)assertion failed: ptr == sh_find_my_buddy(buddy, list)assertion failed: ptr != NULLassertion failed: !sh_testbit(ptr, list, sh.bitmalloc)assertion failed: sh.freelist[list] == ptr/*0123456789ABCDEFCRYPTO_memdup..\s\crypto\o_str.chexstr2buf_sepossl_hexstr2buf_sepbuf2hexstr_sepossl_buf2hexstr_sep..\s\crypto\packet.cwpacket_intern_init_lenWPACKET_start_sub_packet_len__..\s\crypto\param_build.cparam_pushparam_push_numOSSL_PARAM_BLD_push_BN_padNegative big numbers are unsupported for OSSL_PARAMOSSL_PARAM_BLD_push_utf8_stringOSSL_PARAM_BLD_push_utf8_ptrOSSL_PARAM_BLD_push_octet_stringOSSL_PARAM_BLD_p
Source: Binary string: D:\a\1\b\bin\amd64\_overlapped.pdb source: main.exe, 00000000.00000003.1667991159.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdb source: main.exe, 00000000.00000003.1665998538.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1834001257.00007FFE126F4000.00000002.00000001.01000000.00000005.sdmp
Source: Binary string: compiler: cl /Zi /Fdossl_static.pdb /Gs0 /GF /Gy /MD /W3 /wd4090 /nologo /O2 -DL_ENDIAN -DOPENSSL_PIC -D"OPENSSL_BUILDING_OPENSSL" -D"OPENSSL_SYS_WIN32" -D"WIN32_LEAN_AND_MEAN" -D"UNICODE" -D"_UNICODE" -D"_CRT_SECURE_NO_DEPRECATE" -D"_WINSOCK_DEPRECATED_NO_WARNINGS" -D"NDEBUG" source: main.exe, 00000002.00000002.1828585678.00007FFDFB2C2000.00000002.00000001.01000000.00000012.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140.amd64.pdbGCTL source: main.exe, 00000000.00000003.1665998538.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1834001257.00007FFE126F4000.00000002.00000001.01000000.00000005.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_tkinter.pdb source: main.exe, 00000002.00000002.1831127830.00007FFE101D8000.00000002.00000001.01000000.00000015.sdmp
Source: Binary string: D:\a\1\b\libcrypto-3.pdb source: main.exe, 00000002.00000002.1828585678.00007FFDFB35A000.00000002.00000001.01000000.00000012.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_multiprocessing.pdb source: main.exe, 00000000.00000003.1667910143.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdb source: main.exe, 00000000.00000003.1666138884.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1834183539.00007FFE12E15000.00000002.00000001.01000000.0000000E.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\select.pdb source: main.exe, 00000002.00000002.1834528698.00007FFE13303000.00000002.00000001.01000000.0000000C.sdmp, select.pyd.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_ctypes.pdb source: main.exe, 00000002.00000002.1833649384.00007FFE126D1000.00000002.00000001.01000000.00000007.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_hashlib.pdb source: main.exe, 00000000.00000003.1666974627.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1831572786.00007FFE10307000.00000002.00000001.01000000.00000011.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_lzma.pdbNN source: main.exe, 00000000.00000003.1667117359.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1832908322.00007FFE11EBB000.00000002.00000001.01000000.0000000A.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_asyncio.pdb source: main.exe, 00000000.00000003.1666228969.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\pyexpat.pdb source: main.exe, 00000002.00000002.1831275137.00007FFE10252000.00000002.00000001.01000000.0000000F.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_queue.pdb source: main.exe, 00000000.00000003.1668083850.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1833462927.00007FFE120C3000.00000002.00000001.01000000.00000010.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_lzma.pdb source: main.exe, 00000000.00000003.1667117359.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1832908322.00007FFE11EBB000.00000002.00000001.01000000.0000000A.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_bz2.pdb source: main.exe, 00000000.00000003.1666360098.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1833278196.00007FFE11EDD000.00000002.00000001.01000000.00000009.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_wmi.pdb source: main.exe, 00000002.00000002.1834391227.00007FFE130C4000.00000002.00000001.01000000.0000000D.sdmp, _wmi.pyd.0.dr
Source: Binary string: D:\a\1\b\bin\amd64\_socket.pdb source: main.exe, 00000000.00000003.1668165313.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1832117869.00007FFE11519000.00000002.00000001.01000000.0000000B.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\python3.pdb source: main.exe, 00000002.00000002.1814403344.000001D697450000.00000002.00000001.01000000.00000006.sdmp
Source: Binary string: D:\a\_work\1\s\binaries\amd64ret\bin\amd64\\vcruntime140_1.amd64.pdbGCTL source: main.exe, 00000000.00000003.1666138884.000001BD26EA0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1834183539.00007FFE12E15000.00000002.00000001.01000000.0000000E.sdmp
Source: Binary string: D:\a\1\b\libssl-3.pdb source: main.exe, 00000002.00000002.1827879391.00007FFDFAEC5000.00000002.00000001.01000000.00000014.sdmp
Source: Binary string: D:\a\1\b\bin\amd64\_ssl.pdb source: main.exe, 00000002.00000002.1830886823.00007FFE0EB4D000.00000002.00000001.01000000.00000013.sdmp
Source: main.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IMPORT is in: .rdata
Source: main.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_RESOURCE is in: .rsrc
Source: main.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_BASERELOC is in: .reloc
Source: main.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG is in: .rdata
Source: main.exeStatic PE information: Data directory: IMAGE_DIRECTORY_ENTRY_IAT is in: .rdata
Source: VCRUNTIME140.dll.0.drStatic PE information: 0x78BDDED1 [Sat Mar 11 17:01:05 2034 UTC]
Source: VCRUNTIME140.dll.0.drStatic PE information: section name: fothk
Source: VCRUNTIME140.dll.0.drStatic PE information: section name: _RDATA
Source: zlib1.dll.0.drStatic PE information: section name: .xdata
Source: libcrypto-3.dll.0.drStatic PE information: section name: .00cfg
Source: libssl-3.dll.0.drStatic PE information: section name: .00cfg
Source: python312.dll.0.drStatic PE information: section name: PyRuntim
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\_socket.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\unicodedata.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\PIL\_webp.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\select.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\_lzma.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\PIL\_imaging.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\_ssl.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\_tkinter.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\_ctypes.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\_queue.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\libssl-3.dllJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\PIL\_imagingmath.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\VCRUNTIME140.dllJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\_wmi.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\libffi-8.dllJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\PIL\_imagingcms.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\zlib1.dllJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\PIL\_imagingtk.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\_cffi_backend.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\python312.dllJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\python3.dllJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\_bz2.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\tcl86t.dllJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\VCRUNTIME140_1.dllJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\_hashlib.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\_overlapped.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\charset_normalizer\md__mypyc.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\pyexpat.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\_multiprocessing.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\cryptography\hazmat\bindings\_rust.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\libcrypto-3.dllJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\_asyncio.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\_decimal.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\tk86t.dllJump to dropped file
Source: C:\Users\user\Desktop\main.exeFile created: C:\Users\user\AppData\Local\Temp\_MEI75842\charset_normalizer\md.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35C4C50 GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,GetProcAddress,GetLastError,0_2_00007FF7B35C4C50
Source: C:\Users\user\Desktop\main.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\_socket.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\unicodedata.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\PIL\_webp.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\select.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\_lzma.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\PIL\_imaging.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\_ssl.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\_tkinter.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\_ctypes.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\_queue.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\PIL\_imagingmath.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\_wmi.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\PIL\_imagingcms.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\PIL\_imagingtk.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\_cffi_backend.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\python312.dllJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\python3.dllJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\_bz2.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\_hashlib.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\_overlapped.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\charset_normalizer\md__mypyc.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\pyexpat.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\_multiprocessing.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\cryptography\hazmat\bindings\_rust.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\_asyncio.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\_decimal.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeDropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\_MEI75842\charset_normalizer\md.cp312-win_amd64.pydJump to dropped file
Source: C:\Users\user\Desktop\main.exeCheck user administrative privileges: GetTokenInformation,DecisionNodesgraph_0-18734
Source: C:\Users\user\Desktop\main.exeAPI coverage: 5.8 %
Source: C:\Users\user\Desktop\main.exeWMI Queries: IWbemServices::ExecQuery - ROOT\CIMV2 : SELECT Architecture FROM Win32_Processor
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35C7810 FindFirstFileW,RemoveDirectoryW,DeleteFileW,FindNextFileW,FindClose,RemoveDirectoryW,0_2_00007FF7B35C7810
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35C87E0 FindFirstFileExW,FindClose,0_2_00007FF7B35C87E0
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35E2A84 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,0_2_00007FF7B35E2A84
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35C87E0 FindFirstFileExW,FindClose,2_2_00007FF7B35C87E0
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35E2A84 _invalid_parameter_noinfo,FindFirstFileExW,FindNextFileW,FindClose,FindClose,2_2_00007FF7B35E2A84
Source: C:\Users\user\Desktop\main.exeFile opened: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\Jump to behavior
Source: C:\Users\user\Desktop\main.exeFile opened: C:\Users\user\AppData\Local\Temp\_MEI75842\Jump to behavior
Source: C:\Users\user\Desktop\main.exeFile opened: C:\Users\user\AppData\Local\Temp\Jump to behavior
Source: C:\Users\user\Desktop\main.exeFile opened: C:\Users\user\AppData\Local\Jump to behavior
Source: C:\Users\user\Desktop\main.exeFile opened: C:\Users\user\AppData\Jump to behavior
Source: C:\Users\user\Desktop\main.exeFile opened: C:\Users\user\Jump to behavior
Source: cacert.pem.0.drBinary or memory string: j2aTPs+9xYa9+bG3tD60B8jzljHz7aRP+KNOjSkVWLjVb3/ubCK1sK9IRQq9qEmU
Source: main.exe, 00000002.00000003.1794235892.000001D69718A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805617387.000001D6971D5000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1813837136.000001D6971D8000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1808560637.000001D6971D7000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
Source: cacert.pem.0.drBinary or memory string: zJVSk/BwJVmcIGfE7vmLV2H0knZ9P4SNVbfo5azV8fUZVqZa+5Acr5Pr5RzUZ5dd
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35DB4F8 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7B35DB4F8
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35E4690 GetProcessHeap,0_2_00007FF7B35E4690
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35DB4F8 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7B35DB4F8
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35CC840 SetUnhandledExceptionFilter,0_2_00007FF7B35CC840
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35CC69C IsProcessorFeaturePresent,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_00007FF7B35CC69C
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35CBE00 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_00007FF7B35CBE00
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FF7B35DB4F8 RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FF7B35DB4F8
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFDFADE1260 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFDFADE1260
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFE0CFD42E8 IsProcessorFeaturePresent,memset,RtlCaptureContext,RtlLookupFunctionEntry,RtlVirtualUnwind,memset,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00007FFE0CFD42E8
Source: C:\Users\user\Desktop\main.exeCode function: 2_2_00007FFE0CFD3D20 SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00007FFE0CFD3D20
Source: C:\Users\user\Desktop\main.exeProcess created: C:\Users\user\Desktop\main.exe "C:\Users\user\Desktop\main.exe"Jump to behavior
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35EA780 cpuid 0_2_00007FF7B35EA780
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\PIL VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\PIL VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\PIL VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\PIL VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\encoding VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\http1.0 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\msgs VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\Africa VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\Africa VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\Africa VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\Africa VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\Africa VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\Africa VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\Africa VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\Africa VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\Africa VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\Africa VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\America VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\America VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\America VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\America VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\America VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\America\Argentina VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\America VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\America\Argentina VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\America VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\America\Argentina VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\America VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\America\Argentina VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\America\Argentina VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\America\Argentina VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\America VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\America VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\America VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_tcl_data\tzdata\America VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_ctypes.pyd VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_bz2.pyd VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\_lzma.pyd VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842 VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\AppData\Local\Temp\_MEI75842\base_library.zip VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeQueries volume information: C:\Users\user\Desktop\main.exe VolumeInformationJump to behavior
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35CC580 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_00007FF7B35CC580
Source: C:\Users\user\Desktop\main.exeCode function: 0_2_00007FF7B35E6E10 _get_daylight,_get_daylight,_get_daylight,_get_daylight,_get_daylight,GetTimeZoneInformation,0_2_00007FF7B35E6E10
ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
Gather Victim Identity InformationAcquire InfrastructureValid Accounts11
Windows Management Instrumentation
1
DLL Side-Loading
11
Process Injection
1
Virtualization/Sandbox Evasion
OS Credential Dumping2
System Time Discovery
Remote Services1
Archive Collected Data
12
Encrypted Channel
Exfiltration Over Other Network MediumAbuse Accessibility Features
CredentialsDomainsDefault Accounts2
Command and Scripting Interpreter
Boot or Logon Initialization Scripts1
DLL Side-Loading
11
Process Injection
LSASS Memory31
Security Software Discovery
Remote Desktop ProtocolData from Removable Media1
Non-Application Layer Protocol
Exfiltration Over BluetoothNetwork Denial of Service
Email AddressesDNS ServerDomain Accounts1
Native API
Logon Script (Windows)Logon Script (Windows)1
Deobfuscate/Decode Files or Information
Security Account Manager1
Virtualization/Sandbox Evasion
SMB/Windows Admin SharesData from Network Shared Drive2
Application Layer Protocol
Automated ExfiltrationData Encrypted for Impact
Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook1
Obfuscated Files or Information
NTDS2
File and Directory Discovery
Distributed Component Object ModelInput CaptureProtocol ImpersonationTraffic DuplicationData Destruction
Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
Timestomp
LSA Secrets23
System Information Discovery
SSHKeyloggingFallback ChannelsScheduled TransferData Encrypted for Impact
Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
DLL Side-Loading
Cached Domain CredentialsWi-Fi DiscoveryVNCGUI Input CaptureMultiband CommunicationData Transfer Size LimitsService Stop
Hide Legend

Legend:

  • Process
  • Signature
  • Created File
  • DNS/IP Info
  • Is Dropped
  • Is Windows Process
  • Number of created Registry Values
  • Number of created Files
  • Visual Basic
  • Delphi
  • Java
  • .Net C# or VB.NET
  • C, C++ or other language
  • Is malicious
  • Internet

This section contains all screenshots as thumbnails, including those not shown in the slideshow.


windows-stand
SourceDetectionScannerLabelLink
main.exe3%ReversingLabsWin64.Malware.Generic
main.exe11%VirustotalBrowse
SourceDetectionScannerLabelLink
C:\Users\user\AppData\Local\Temp\_MEI75842\PIL\_imaging.cp312-win_amd64.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\PIL\_imagingcms.cp312-win_amd64.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\PIL\_imagingmath.cp312-win_amd64.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\PIL\_imagingtk.cp312-win_amd64.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\PIL\_webp.cp312-win_amd64.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\VCRUNTIME140.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\VCRUNTIME140_1.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\_asyncio.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\_bz2.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\_cffi_backend.cp312-win_amd64.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\_ctypes.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\_decimal.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\_hashlib.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\_lzma.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\_multiprocessing.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\_overlapped.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\_queue.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\_socket.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\_ssl.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\_tkinter.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\_wmi.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\charset_normalizer\md.cp312-win_amd64.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\charset_normalizer\md__mypyc.cp312-win_amd64.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\cryptography\hazmat\bindings\_rust.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\libcrypto-3.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\libffi-8.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\libssl-3.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\pyexpat.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\python3.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\python312.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\select.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\setuptools\_vendor\autocommand-2.2.2.dist-info\METADATA0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\setuptools\_vendor\tomli-2.0.1.dist-info\METADATA0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\tcl86t.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\tk86t.dll0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\unicodedata.pyd0%ReversingLabs
C:\Users\user\AppData\Local\Temp\_MEI75842\zlib1.dll0%ReversingLabs
No Antivirus matches
No Antivirus matches
SourceDetectionScannerLabelLink
http://crl.dhimyotis.com/certignarootca.crl0%URL Reputationsafe
http://curl.haxx.se/rfc/cookie_spec.html0%URL Reputationsafe
https://docs.python.org/3/library/importlib.html#importlib.abc.ExecutionLoader.get_filename0%URL Reputationsafe
https://wwww.certigna.fr/autorites/0m0%URL Reputationsafe
https://httpbin.org/0%URL Reputationsafe
https://docs.python.org/3/library/importlib.html#importlib.abc.Loader.exec_module0%URL Reputationsafe
https://docs.python.org/3/library/importlib.html#importlib.abc.MetaPathFinder.invalidate_caches0%URL Reputationsafe
http://hg.python.org/cpython/file/603b4d593758/Lib/socket.py#l5350%URL Reputationsafe
http://crl.securetrust.com/STCA.crl0%URL Reputationsafe
http://tools.ietf.org/html/rfc6125#section-6.4.30%URL Reputationsafe
http://www.cert.fnmt.es/dpcs/0%URL Reputationsafe
http://www.accv.es000%URL Reputationsafe
http://www.firmaprofesional.com/cps00%URL Reputationsafe
https://docs.python.org/3/library/importlib.html#importlib.abc.PathEntryFinder.find_spec0%URL Reputationsafe
http://crl.securetrust.com/SGCA.crl00%URL Reputationsafe
https://docs.python.org/3/library/importlib.html#importlib.abc.ResourceLoader.get_data0%URL Reputationsafe
http://www.quovadisglobal.com/cps00%URL Reputationsafe
http://ocsp.accv.es00%URL Reputationsafe
NameIPActiveMaliciousAntivirus DetectionReputation
i.ibb.co
169.197.85.95
truefalse
    unknown
    NameSourceMaliciousAntivirus DetectionReputation
    https://github.com/jaraco/keyring/commit/a85a7cbc6c909f8121660ed1f7b487f99a1c2bf7METADATA0.0.drfalse
      unknown
      https://anzeljg.github.io/rin2/book2/2405/docs/tkinter/text.htmlmain.exe, 00000002.00000003.1796601019.000001D697D67000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1793703061.000001D697C62000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821509080.000001D697C79000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794304823.000001D697D63000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804206735.000001D697C76000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D72000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D6B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1803101027.000001D697C6B000.00000004.00000020.00020000.00000000.sdmpfalse
        unknown
        https://img.shields.io/pypi/pyversions/backports.tarfile.svgMETADATA14.0.drfalse
          unknown
          https://github.com/astral-sh/ruffMETADATA14.0.dr, METADATA0.0.dr, METADATA15.0.dr, METADATA.0.drfalse
            unknown
            https://readthedocs.org/projects/typeguard/badge/?version=latestmain.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpfalse
              unknown
              https://setuptools.pypa.io/en/latest/references/keywords.html#keyword-namespace-packagesmain.exe, 00000002.00000002.1821925873.000001D697DC0000.00000004.00001000.00020000.00000000.sdmpfalse
                unknown
                https://readthedocs.org/projects/jaracofunctools/badge/?version=latestMETADATA.0.drfalse
                  unknown
                  https://github.com/python/importlib_metadata/actions/workflows/main.yml/badge.svgMETADATA15.0.drfalse
                    unknown
                    https://github.com/jaraco/jaraco.functoolsMETADATA.0.drfalse
                      unknown
                      http://crl.dhimyotis.com/certignarootca.crl0main.exe, 00000002.00000003.1797726747.000001D6976CB000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795183177.000001D697639000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797431650.000001D6976A6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1809201841.000001D6976DF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1818154964.000001D6976DF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797908449.000001D6976DB000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794517273.000001D6975E2000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795398300.000001D697660000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806707953.000001D6976DE000.00000004.00000020.00020000.00000000.sdmpfalse
                        unknown
                        https://tidelift.com/badges/package/pypi/jaraco.contextMETADATA0.0.drfalse
                          unknown
                          https://github.com/python/importlib_metadata/issuesMETADATA15.0.drfalse
                            unknown
                            https://requests.readthedocs.io$main.exe, 00000002.00000002.1825170214.000001D6995BC000.00000004.00001000.00020000.00000000.sdmpfalse
                              unknown
                              https://github.com/tensorflow/datasets/blob/master/tensorflow_datasets/core/utils/resource_utils.py#main.exe, 00000002.00000002.1812971528.000001D697110000.00000004.00000020.00020000.00000000.sdmpfalse
                                unknown
                                https://wheel.readthedocs.io/en/stable/news.htmlmain.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpfalse
                                  unknown
                                  https://importlib-metadata.readthedocs.io/METADATA15.0.drfalse
                                    unknown
                                    https://packaging.python.org/en/latest/specifications/core-metadata/main.exe, 00000002.00000002.1822586111.000001D698310000.00000004.00001000.00020000.00000000.sdmpfalse
                                      unknown
                                      https://docs.python.org/3.11/library/binascii.html#binascii.a2b_base64main.exe, 00000002.00000003.1807517996.000001D6979E5000.00000004.00000020.00020000.00000000.sdmpfalse
                                        unknown
                                        https://github.com/pypa/packagingmain.exe, 00000002.00000002.1822012845.000001D697ED0000.00000004.00001000.00020000.00000000.sdmpfalse
                                          unknown
                                          https://pypi.org/project/backports.tarfileMETADATA14.0.drfalse
                                            unknown
                                            https://readthedocs.org/projects/importlib-metadata/badge/?version=latestMETADATA15.0.drfalse
                                              unknown
                                              https://refspecs.linuxfoundation.org/elf/gabi4main.exe, 00000002.00000002.1822012845.000001D697ED0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                unknown
                                                http://repository.swisssign.com/fmain.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmpfalse
                                                  unknown
                                                  https://setuptools.pypa.io/en/latest/references/keywords.html#keyword-namespace-packages0Cmain.exe, 00000002.00000002.1821925873.000001D697DC0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                    unknown
                                                    https://readthedocs.org/projects/backportstarfile/badge/?version=latestMETADATA14.0.drfalse
                                                      unknown
                                                      https://github.com/urllib3/urllib3/issues/2192#issuecomment-821832963main.exe, 00000002.00000002.1824950126.000001D6992D0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                        unknown
                                                        https://blog.jaraco.com/skeletonmain.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmp, METADATA14.0.dr, METADATA0.0.dr, METADATA15.0.dr, METADATA.0.drfalse
                                                          unknown
                                                          https://t.me/deepwingmain.exe, 00000002.00000002.1822586111.000001D698310000.00000004.00001000.00020000.00000000.sdmpfalse
                                                            unknown
                                                            http://www.accv.es/legislacion_c.htm?main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806163545.000001D69877A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                              unknown
                                                              https://github.com/platformdirs/platformdirsmain.exe, 00000002.00000002.1822195414.000001D698100000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                unknown
                                                                http://crl.dhimyotis.com/certignarootca.crlmain.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807277668.000001D6987A6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806885649.000001D698797000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804605192.000001D698794000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                • URL Reputation: safe
                                                                unknown
                                                                http://curl.haxx.se/rfc/cookie_spec.htmlmain.exe, 00000002.00000003.1794709862.000001D69862B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1825170214.000001D699510000.00000004.00001000.00020000.00000000.sdmp, main.exe, 00000002.00000002.1823114770.000001D69862D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806994937.000001D69862D000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                • URL Reputation: safe
                                                                unknown
                                                                https://github.com/pypa/.github/blob/main/CODE_OF_CONDUCT.mdmain.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                  unknown
                                                                  https://setuptools.pypa.io/en/latest/references/keywords.html#keyword-namespace-packagesr;main.exe, 00000002.00000003.1751693738.000001D697A33000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1751693738.000001D697A7A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                    unknown
                                                                    https://docs.python.org/3/library/importlib.html#importlib.abc.ExecutionLoader.get_filenamemain.exe, 00000002.00000002.1812814191.000001D697000000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                    • URL Reputation: safe
                                                                    unknown
                                                                    https://urllib3.readthedocs.io/en/latest/advanced-usage.html#https-proxy-error-http-proxymain.exe, 00000002.00000002.1825037011.000001D699488000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                      unknown
                                                                      https://github.com/jaraco/jaraco.context/actions?query=workflow%3A%22tests%22METADATA0.0.drfalse
                                                                        unknown
                                                                        https://pypi.org/project/build/).main.exe, 00000002.00000002.1822195414.000001D698100000.00000004.00001000.00020000.00000000.sdmp, main.exe, 00000002.00000002.1822290542.000001D698210000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                          unknown
                                                                          https://wwww.certigna.fr/autorites/0mmain.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797726747.000001D6976CB000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795183177.000001D697639000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797431650.000001D6976A6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1809201841.000001D6976DF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1818154964.000001D6976DF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797908449.000001D6976DB000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794517273.000001D6975E2000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795398300.000001D697660000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806707953.000001D6976DE000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                          • URL Reputation: safe
                                                                          unknown
                                                                          https://github.com/pypa/wheelmain.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                            unknown
                                                                            https://www.python.org/dev/peps/pep-0427/main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                              unknown
                                                                              https://github.com/python/cpython/blob/839d7893943782ee803536a47f1d4de160314f85/Lib/importlib/readermain.exe, 00000002.00000002.1812971528.000001D697110000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                unknown
                                                                                https://github.com/python/cpython/issues/86361.main.exe, 00000002.00000003.1794235892.000001D69718A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1751064719.000001D69770B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1813869078.000001D6971E0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794495869.000001D6971DE000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                  unknown
                                                                                  https://httpbin.org/main.exe, 00000002.00000003.1806994937.000001D698618000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                  • URL Reputation: safe
                                                                                  unknown
                                                                                  https://docs.python.org/3/library/importlib.html#importlib.abc.Loader.exec_modulemain.exe, 00000002.00000002.1814086284.000001D697350000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                  • URL Reputation: safe
                                                                                  unknown
                                                                                  https://docs.python.org/3/library/importlib.html#importlib.abc.MetaPathFinder.invalidate_cachesmain.exe, 00000002.00000002.1814086284.000001D697350000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                  • URL Reputation: safe
                                                                                  unknown
                                                                                  https://img.shields.io/badge/skeleton-2024-informationalmain.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmp, METADATA14.0.dr, METADATA0.0.dr, METADATA15.0.dr, METADATA.0.drfalse
                                                                                    unknown
                                                                                    https://packaging.python.org/en/latest/specifications/pyproject-toml/#declaring-project-metadata-themain.exe, 00000002.00000003.1804902377.000001D697A86000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1799844785.000001D697A85000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1820164882.000001D697A86000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797937359.000001D697A75000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                      unknown
                                                                                      http://hg.python.org/cpython/file/603b4d593758/Lib/socket.py#l535main.exe, 00000002.00000003.1796601019.000001D697D67000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794304823.000001D697D63000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804820833.000001D697D68000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                      • URL Reputation: safe
                                                                                      unknown
                                                                                      https://docs.python.org/3.8/library/zipfile.html#path-objectsmain.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                        unknown
                                                                                        https://github.com/pypa/setuptools/issues/417#issuecomment-392298401main.exe, 00000002.00000002.1819470816.000001D6978C0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                          unknown
                                                                                          http://crl.securetrust.com/STCA.crlmain.exe, 00000002.00000002.1823433559.000001D698768000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806118626.000001D69875B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806834143.000001D69875C000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                          • URL Reputation: safe
                                                                                          unknown
                                                                                          http://www.accv.es/fileadmin/Archivos/certificados/raizaccv1.crt0main.exe, 00000002.00000003.1808891761.000001D69877B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807129538.000001D69877D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1823511945.000001D69877C000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806163545.000001D69877A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                            unknown
                                                                                            http://tools.ietf.org/html/rfc6125#section-6.4.3main.exe, 00000002.00000002.1825170214.000001D6994D0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                            • URL Reputation: safe
                                                                                            unknown
                                                                                            http://www.zlib.net/Dmain.exe, 00000000.00000003.1838975876.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26ED3000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1830762935.00007FFE0E188000.00000008.00000001.01000000.00000018.sdmpfalse
                                                                                              unknown
                                                                                              http://www.quovadisglobal.com/cpstmain.exe, 00000002.00000003.1793534097.000001D6986AF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1808021528.000001D6986AF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805455063.000001D6986AF000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1823250819.000001D6986AF000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                unknown
                                                                                                http://www.cert.fnmt.es/dpcs/main.exe, 00000002.00000002.1821760220.000001D697D53000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1808256570.000001D697D51000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1823562297.000001D6987A1000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802945421.000001D697D42000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806757691.000001D697D44000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806885649.000001D698797000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804605192.000001D698794000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1796152323.000001D697D41000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                • URL Reputation: safe
                                                                                                unknown
                                                                                                https://google.com/mailmain.exe, 00000002.00000003.1808650169.000001D697A31000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795183177.000001D697639000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1817449152.000001D6976AD000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797431650.000001D6976A6000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807215037.000001D697A29000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1808832495.000001D697A34000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1803576833.000001D697A26000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1811104557.000001D697A42000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794517273.000001D6975E2000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1810296670.000001D697A3E000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795398300.000001D697660000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                  unknown
                                                                                                  https://img.shields.io/pypi/v/importlib_metadata.svgMETADATA15.0.drfalse
                                                                                                    unknown
                                                                                                    https://github.com/jaraco/jaraco.functools/issues/5main.exe, 00000002.00000002.1822012845.000001D697ED0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                      unknown
                                                                                                      https://typeguard.readthedocs.io/en/latest/main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                        unknown
                                                                                                        https://www.python.org/dev/peps/pep-0484/main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                          unknown
                                                                                                          http://www.accv.es00main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807129538.000001D69877D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806163545.000001D69877A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                          • URL Reputation: safe
                                                                                                          unknown
                                                                                                          https://github.com/jaraco/backports.tarfile/actions/workflows/main.yml/badge.svgMETADATA14.0.drfalse
                                                                                                            unknown
                                                                                                            https://github.com/urllib3/urllib3/issues/2513#issuecomment-1152559900.main.exe, 00000002.00000003.1793703061.000001D697C62000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821509080.000001D697C70000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1803101027.000001D697C6B000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                              unknown
                                                                                                              https://mahler:8092/site-updates.pymain.exe, 00000002.00000003.1808502903.000001D697B02000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1759374271.000001D697B57000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797937359.000001D697ACC000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1799559383.000001D697B01000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1761451233.000001D697AF7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1820516001.000001D697B03000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1757664941.000001D697B57000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1758592599.000001D697B07000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1801115049.000001D697B02000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806620146.000001D697B02000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                unknown
                                                                                                                https://tools.ietf.org/html/rfc7231#section-4.3.6)main.exe, 00000002.00000003.1761451233.000001D697AF7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805031409.000001D697581000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1810747879.000001D69758E000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1761177341.000001D697B27000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                  unknown
                                                                                                                  https://anzeljg.github.io/rin2/book2/2405/docs/tkinter/fonts.htmlmain.exe, 00000002.00000003.1793703061.000001D697C62000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1764334948.000001D697CCE000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821509080.000001D697C79000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821657183.000001D697CB9000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804206735.000001D697C76000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1764794908.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1764334948.000001D697C6A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804979469.000001D697CB7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1803101027.000001D697C6B000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                    unknown
                                                                                                                    https://tidelift.com/subscription/pkg/pypi-zipp?utm_source=pypi-zipp&utm_medium=referral&utm_campaigmain.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                      unknown
                                                                                                                      https://urllib3.readthedocs.io/en/latest/advanced-usage.html#tls-warningsPmain.exe, 00000002.00000002.1825037011.000001D699464000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                        unknown
                                                                                                                        https://urllib3.readthedocs.io/en/latest/advanced-usage.html#tls-warningsNmain.exe, 00000002.00000003.1809719132.000001D6985E2000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795074686.000001D6985D7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1803839819.000001D6985D9000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                          unknown
                                                                                                                          http://www.firmaprofesional.com/cps0main.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1809875226.000001D697B2D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805948789.000001D697B17000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1820684603.000001D697B3C000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797937359.000001D697ACC000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1799559383.000001D697B01000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1801115049.000001D697B02000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                          • URL Reputation: safe
                                                                                                                          unknown
                                                                                                                          https://docs.python.org/3/library/importlib.html#importlib.abc.PathEntryFinder.find_specmain.exe, 00000002.00000002.1812814191.000001D69707C000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                          • URL Reputation: safe
                                                                                                                          unknown
                                                                                                                          https://github.com/urllib3/urllib3/issues/2920main.exe, 00000002.00000002.1825037011.000001D699488000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                            unknown
                                                                                                                            http://crl.securetrust.com/SGCA.crl0main.exe, 00000002.00000003.1796601019.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1821858765.000001D697D87000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802573321.000001D697D87000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                            • URL Reputation: safe
                                                                                                                            unknown
                                                                                                                            https://docs.python.org/3/library/importlib.html#importlib.abc.ResourceLoader.get_datamain.exe, 00000002.00000002.1812971528.000001D697110000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                            • URL Reputation: safe
                                                                                                                            unknown
                                                                                                                            https://github.com/jaraco/jaraco.functools/actions?query=workflow%3A%22tests%22METADATA.0.drfalse
                                                                                                                              unknown
                                                                                                                              http://tip.tcl.tk/48)main.exe, 00000002.00000003.1809875226.000001D697B2D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805948789.000001D697B17000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1820684603.000001D697B3C000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797937359.000001D697ACC000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1799559383.000001D697B01000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1801115049.000001D697B02000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                unknown
                                                                                                                                https://stackoverflow.com/questions/23836000/can-i-change-the-title-bar-in-tkinter/70724666#70724666main.exe, 00000002.00000002.1822697021.000001D698410000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                  unknown
                                                                                                                                  https://github.com/python/importlib_metadata/actions?query=workflow%3A%22tests%22METADATA15.0.drfalse
                                                                                                                                    unknown
                                                                                                                                    https://pypi.org/project/jaraco.contextMETADATA0.0.drfalse
                                                                                                                                      unknown
                                                                                                                                      http://cacerts.digicert.comain.exe, 00000000.00000003.1838975876.000001BD26EC3000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                        unknown
                                                                                                                                        http://www.quovadisglobal.com/cps0main.exe, 00000002.00000003.1810059205.000001D697C1E000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1796910286.000001D697C1A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1809296187.000001D697C1A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                        • URL Reputation: safe
                                                                                                                                        unknown
                                                                                                                                        https://github.com/agronholm/typeguard/issuesmain.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                          unknown
                                                                                                                                          https://github.com/pypa/setuptools/issues/new?template=distutils-deprecation.ymlmain.exe, 00000002.00000002.1822195414.000001D698100000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                            unknown
                                                                                                                                            http://docs.python.org/library/itertools.html#recipesmain.exe, 00000002.00000002.1822012845.000001D697ED0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                              unknown
                                                                                                                                              https://readthedocs.org/projects/jaracocontext/badge/?version=latestMETADATA0.0.drfalse
                                                                                                                                                unknown
                                                                                                                                                https://gist.github.com/lyssdod/f51579ae8d93c8657a5564aefc2ffbcamain.exe, 00000002.00000002.1822012845.000001D697ED0000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                  unknown
                                                                                                                                                  https://pypi.org/project/setuptools/main.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                    unknown
                                                                                                                                                    https://github.com/jaraco/jaraco.contextMETADATA0.0.drfalse
                                                                                                                                                      unknown
                                                                                                                                                      https://github.com/pypa/setuptools/issues/1024.main.exe, 00000002.00000002.1822290542.000001D698210000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                        unknown
                                                                                                                                                        http://code.activestate.com/recipes/577452-a-memoize-decorator-for-instance-methods/main.exe, 00000002.00000003.1805162336.000001D697661000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795183177.000001D697639000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1808806949.000001D697664000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1796277650.000001D697701000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1804699405.000001D697722000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1759485920.000001D697716000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1754382093.000001D697716000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1758085717.000001D697716000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1756090650.000001D697716000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802657209.000001D697702000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794517273.000001D6975E2000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795398300.000001D697660000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                          unknown
                                                                                                                                                          https://img.shields.io/pypi/pyversions/jaraco.functools.svgMETADATA.0.drfalse
                                                                                                                                                            unknown
                                                                                                                                                            http://ocsp.accv.es0main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807129538.000001D69877D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806163545.000001D69877A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                            • URL Reputation: safe
                                                                                                                                                            unknown
                                                                                                                                                            https://www.python.org/main.exe, 00000002.00000003.1808502903.000001D697B02000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1759374271.000001D697B57000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797937359.000001D697ACC000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1799559383.000001D697B01000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1761451233.000001D697AF7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1820516001.000001D697B03000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1757664941.000001D697B57000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1758592599.000001D697B07000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1801115049.000001D697B02000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806620146.000001D697B02000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                              unknown
                                                                                                                                                              http://ocsp.accv.es%main.exe, 00000002.00000003.1808891761.000001D69877B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1793198338.000001D69874A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000002.1823511945.000001D69877C000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1802466061.000001D69876A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806163545.000001D69877A000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1800858329.000001D69874A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                unknown
                                                                                                                                                                https://tidelift.com/subscription/pkg/pypi-importlib-metadata?utm_source=pypi-importlib-metadata&utmMETADATA15.0.drfalse
                                                                                                                                                                  unknown
                                                                                                                                                                  https://github.com/agronholm/typeguard/actions/workflows/test.ymlmain.exe, 00000000.00000003.1838975876.000001BD26E8B000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000000.00000002.1839931409.000001BD26E9A000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                    unknown
                                                                                                                                                                    https://docs.python.org/3/howto/mro.html.main.exe, 00000002.00000002.1812814191.000001D69707C000.00000004.00001000.00020000.00000000.sdmpfalse
                                                                                                                                                                      unknown
                                                                                                                                                                      https://twitter.com/main.exe, 00000002.00000003.1805250576.000001D69860D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1795074686.000001D69860D000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1805856231.000001D698612000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1807101539.000001D6971FB000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1794173302.000001D6971F0000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1797655692.000001D6971F7000.00000004.00000020.00020000.00000000.sdmp, main.exe, 00000002.00000003.1806994937.000001D698618000.00000004.00000020.00020000.00000000.sdmpfalse
                                                                                                                                                                        unknown
                                                                                                                                                                        • No. of IPs < 25%
                                                                                                                                                                        • 25% < No. of IPs < 50%
                                                                                                                                                                        • 50% < No. of IPs < 75%
                                                                                                                                                                        • 75% < No. of IPs
                                                                                                                                                                        IPDomainCountryFlagASNASN NameMalicious
                                                                                                                                                                        169.197.85.95
                                                                                                                                                                        i.ibb.coUnited States
                                                                                                                                                                        26548PUREVOLTAGE-INCUSfalse
                                                                                                                                                                        Joe Sandbox version:41.0.0 Charoite
                                                                                                                                                                        Analysis ID:1547827
                                                                                                                                                                        Start date and time:2024-11-03 06:51:08 +01:00
                                                                                                                                                                        Joe Sandbox product:CloudBasic
                                                                                                                                                                        Overall analysis duration:0h 7m 5s
                                                                                                                                                                        Hypervisor based Inspection enabled:false
                                                                                                                                                                        Report type:full
                                                                                                                                                                        Cookbook file name:default.jbs
                                                                                                                                                                        Analysis system description:Windows 10 x64 22H2 with Office Professional Plus 2019, Chrome 117, Firefox 118, Adobe Reader DC 23, Java 8 Update 381, 7zip 23.01
                                                                                                                                                                        Number of analysed new started processes analysed:6
                                                                                                                                                                        Number of new started drivers analysed:0
                                                                                                                                                                        Number of existing processes analysed:0
                                                                                                                                                                        Number of existing drivers analysed:0
                                                                                                                                                                        Number of injected processes analysed:0
                                                                                                                                                                        Technologies:
                                                                                                                                                                        • HCA enabled
                                                                                                                                                                        • EGA enabled
                                                                                                                                                                        • AMSI enabled
                                                                                                                                                                        Analysis Mode:default
                                                                                                                                                                        Analysis stop reason:Timeout
                                                                                                                                                                        Sample name:main.exe
                                                                                                                                                                        Detection:MAL
                                                                                                                                                                        Classification:mal48.winEXE@4/1026@1/1
                                                                                                                                                                        EGA Information:
                                                                                                                                                                        • Successful, ratio: 100%
                                                                                                                                                                        HCA Information:Failed
                                                                                                                                                                        Cookbook Comments:
                                                                                                                                                                        • Found application associated with file extension: .exe
                                                                                                                                                                        • Stop behavior analysis, all processes terminated
                                                                                                                                                                        • Exclude process from analysis (whitelisted): MpCmdRun.exe, SIHClient.exe, conhost.exe
                                                                                                                                                                        • Excluded domains from analysis (whitelisted): ocsp.digicert.com, slscr.update.microsoft.com, otelrules.azureedge.net, ctldl.windowsupdate.com, fe3cr.delivery.mp.microsoft.com
                                                                                                                                                                        • Not all processes where analyzed, report is missing behavior information
                                                                                                                                                                        • Report size exceeded maximum capacity and may have missing disassembly code.
                                                                                                                                                                        • Report size getting too big, too many NtCreateFile calls found.
                                                                                                                                                                        • Report size getting too big, too many NtOpenFile calls found.
                                                                                                                                                                        • Report size getting too big, too many NtProtectVirtualMemory calls found.
                                                                                                                                                                        • Report size getting too big, too many NtQueryValueKey calls found.
                                                                                                                                                                        • Report size getting too big, too many NtQueryVolumeInformationFile calls found.
                                                                                                                                                                        • Report size getting too big, too many NtSetInformationFile calls found.
                                                                                                                                                                        No simulations
                                                                                                                                                                        MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                        169.197.85.95https://www.phsinc.com/?bwfan-track-action=click&bwfan-track-id=0ecdd1bdf2276cad3fa2d27ffa918e84&bwfan-uid=e2dffed46dd69d19d18bc527d6255bd5&bwfan-link=%68%74%74%70%73%3A%2F%2F%6D%61%69%6C%2E%72%69%67%6F%74%69%6C%65%73%2E%63%6F%6D%2F%6A%50%73%51%57%55%63%42Get hashmaliciousHTMLPhisher, ReCaptcha PhishBrowse
                                                                                                                                                                          TJXpRilNkh.exeGet hashmaliciousXWormBrowse
                                                                                                                                                                            https://inspyrehomedesign.comGet hashmaliciousNetSupport RATBrowse
                                                                                                                                                                              https://inspyrehomedesign.com/Ray-verify.htmlGet hashmaliciousNetSupport RATBrowse
                                                                                                                                                                                index.htmlGet hashmaliciousUnknownBrowse
                                                                                                                                                                                  index.htmlGet hashmaliciousUnknownBrowse
                                                                                                                                                                                    r8k29DBraE.exeGet hashmaliciousXWormBrowse
                                                                                                                                                                                      https://meaoee-fc3f.elamzioehr.workers.dev/Get hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                        https://oaemk-f29f.hmnaitswiaa.workers.dev/Get hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                          http://pub-0b94d4f0b06646c5bbfca320d917c04a.r2.dev/insured.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                            i.ibb.coSecureMessageATT.htmlGet hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                            • 104.194.8.184
                                                                                                                                                                                            https://www.phsinc.com/?bwfan-track-action=click&bwfan-track-id=0ecdd1bdf2276cad3fa2d27ffa918e84&bwfan-uid=e2dffed46dd69d19d18bc527d6255bd5&bwfan-link=%68%74%74%70%73%3A%2F%2F%6D%61%69%6C%2E%72%69%67%6F%74%69%6C%65%73%2E%63%6F%6D%2F%6A%50%73%51%57%55%63%42Get hashmaliciousHTMLPhisher, ReCaptcha PhishBrowse
                                                                                                                                                                                            • 162.19.58.157
                                                                                                                                                                                            TJXpRilNkh.exeGet hashmaliciousXWormBrowse
                                                                                                                                                                                            • 169.197.85.95
                                                                                                                                                                                            https://webdemo.biz/Get hashmaliciousNetSupport RAT, CAPTCHA ScamBrowse
                                                                                                                                                                                            • 162.19.58.159
                                                                                                                                                                                            https://inspyrehomedesign.comGet hashmaliciousNetSupport RATBrowse
                                                                                                                                                                                            • 169.197.85.95
                                                                                                                                                                                            https://inspyrehomedesign.com/Ray-verify.htmlGet hashmaliciousNetSupport RATBrowse
                                                                                                                                                                                            • 162.19.58.157
                                                                                                                                                                                            http://www.holidaybunch.comGet hashmaliciousUnknownBrowse
                                                                                                                                                                                            • 162.19.58.161
                                                                                                                                                                                            http://holidaybunch.com/Get hashmaliciousUnknownBrowse
                                                                                                                                                                                            • 162.19.58.158
                                                                                                                                                                                            http://holidaybunch.comGet hashmaliciousUnknownBrowse
                                                                                                                                                                                            • 162.19.58.159
                                                                                                                                                                                            http://holidaybunch.comGet hashmaliciousUnknownBrowse
                                                                                                                                                                                            • 104.194.8.184
                                                                                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                            PUREVOLTAGE-INCUShttps://www.phsinc.com/?bwfan-track-action=click&bwfan-track-id=0ecdd1bdf2276cad3fa2d27ffa918e84&bwfan-uid=e2dffed46dd69d19d18bc527d6255bd5&bwfan-link=%68%74%74%70%73%3A%2F%2F%6D%61%69%6C%2E%72%69%67%6F%74%69%6C%65%73%2E%63%6F%6D%2F%6A%50%73%51%57%55%63%42Get hashmaliciousHTMLPhisher, ReCaptcha PhishBrowse
                                                                                                                                                                                            • 169.197.85.95
                                                                                                                                                                                            TJXpRilNkh.exeGet hashmaliciousXWormBrowse
                                                                                                                                                                                            • 169.197.85.95
                                                                                                                                                                                            https://inspyrehomedesign.comGet hashmaliciousNetSupport RATBrowse
                                                                                                                                                                                            • 169.197.85.95
                                                                                                                                                                                            https://inspyrehomedesign.com/Ray-verify.htmlGet hashmaliciousNetSupport RATBrowse
                                                                                                                                                                                            • 169.197.85.95
                                                                                                                                                                                            index.htmlGet hashmaliciousUnknownBrowse
                                                                                                                                                                                            • 169.197.85.95
                                                                                                                                                                                            index.htmlGet hashmaliciousUnknownBrowse
                                                                                                                                                                                            • 169.197.85.95
                                                                                                                                                                                            r8k29DBraE.exeGet hashmaliciousXWormBrowse
                                                                                                                                                                                            • 169.197.85.95
                                                                                                                                                                                            https://ducati-mlbb.shop/Get hashmaliciousHTMLPhisherBrowse
                                                                                                                                                                                            • 162.249.168.129
                                                                                                                                                                                            https://dlce.cc/fbacdcb212bcbb323077d5a99ef04c07Get hashmaliciousUnknownBrowse
                                                                                                                                                                                            • 104.244.159.148
                                                                                                                                                                                            https://dlce.cc/fbacdcb212bcbb323077d5a99ef04c07Get hashmaliciousUnknownBrowse
                                                                                                                                                                                            • 104.244.159.148
                                                                                                                                                                                            No context
                                                                                                                                                                                            MatchAssociated Sample Name / URLSHA 256DetectionThreat NameLinkContext
                                                                                                                                                                                            C:\Users\user\AppData\Local\Temp\_MEI75842\PIL\_imaging.cp312-win_amd64.pydcPl7CoJTBx.exeGet hashmaliciousLuna Grabber, Luna LoggerBrowse
                                                                                                                                                                                              file.exeGet hashmaliciousLummaC, Clipboard Hijacker, Cryptbot, LummaC StealerBrowse
                                                                                                                                                                                                Cryptofarm.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                  Bot.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                    XmS_Project.rarGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                      SecuriteInfo.com.Win64.Evo-gen.19407.6877.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                        neverlose.exeGet hashmaliciousDiscord Token StealerBrowse
                                                                                                                                                                                                          SecuriteInfo.com.FileRepMalware.11429.3462.exeGet hashmaliciousUnknownBrowse
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2343424
                                                                                                                                                                                                            Entropy (8bit):6.507291548306534
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24576:11/7+Ny6imt6M5BRI+kDx1y0IQphHAokIEEKfMbrE8EPsoU0eJct/jVM5HFd5:11/7w95ctyTQHAjIEx2EPsoU0Lto7
                                                                                                                                                                                                            MD5:45ED5B175FF3FEB7D39F8482C5E60848
                                                                                                                                                                                                            SHA1:C0EB6EF9978FA1A62FFE8403870475B22DE3C7E7
                                                                                                                                                                                                            SHA-256:FFADC62922AAC7F93D4EC6F2EB41CD836104F88D86B45E9FC295087FAD7D262E
                                                                                                                                                                                                            SHA-512:69E24B20822B413EE3C7A5FFBD60F41AFB420E4BAC45DABEF31CCB2C9C3F9DC50B48E01E5C870B3367208F3A85FCEAF51F052C0B3ADF2B7A7F209A9532E36BEE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Joe Sandbox View:
                                                                                                                                                                                                            • Filename: cPl7CoJTBx.exe, Detection: malicious, Browse
                                                                                                                                                                                                            • Filename: file.exe, Detection: malicious, Browse
                                                                                                                                                                                                            • Filename: Cryptofarm.exe, Detection: malicious, Browse
                                                                                                                                                                                                            • Filename: Bot.exe, Detection: malicious, Browse
                                                                                                                                                                                                            • Filename: XmS_Project.rar, Detection: malicious, Browse
                                                                                                                                                                                                            • Filename: SecuriteInfo.com.Win64.Evo-gen.19407.6877.exe, Detection: malicious, Browse
                                                                                                                                                                                                            • Filename: neverlose.exe, Detection: malicious, Browse
                                                                                                                                                                                                            • Filename: SecuriteInfo.com.FileRepMalware.11429.3462.exe, Detection: malicious, Browse
                                                                                                                                                                                                            Reputation:moderate, very likely benign file
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......`...$...$...$...-.o.4....`..&....`.. ....`.. ....`..,....`..*...7g..&...o...#...$...,...$...?...7g......7g..n...7g..%...7g..%...7g..%...Rich$...........PE..d..._J.f.........." ...(.2...................................................@$...........`.........................................0F".`....F".......$.......#.h............ $.....0. ....................... .(..... .@............P..(............................text....1.......2.................. ..`.rdata..$....P.......6..............@..@.data........p"..b...J".............@....pdata..h.....#.......".............@..@.rsrc.........$.......#.............@..@.reloc....... $.......#.............@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):262656
                                                                                                                                                                                                            Entropy (8bit):6.282156679924657
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6144:gXnnqhP8Sq5V6SuRI7OzhHTnLg9uP1+74/LgHmPr9qvZqhLaHLTLrLfqeqwLii66:gXnIPE5GhHTnLg9uP1+74/LgHmPr9qvG
                                                                                                                                                                                                            MD5:30CEC332935A3E27B399A0939BDBECD7
                                                                                                                                                                                                            SHA1:3FDB19380F95B3299C0C0CAC4D8F21EDFC14C368
                                                                                                                                                                                                            SHA-256:91D0D471C50CFCC9FD8688AE2350477408BB987E67A1C5F508D17C5DD021314F
                                                                                                                                                                                                            SHA-512:091B3FE2F4F4FA6FCAE8F920D9F97089CDB9DB8E57980588198873D07E12C994CBC860B02597BD128862E475AE0C54A283D6DBC194F1F2D3978BA77F7D39965B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Reputation:moderate, very likely benign file
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......E.}..s...s...s.......s.......s.......s.......s.......s.......s..J....s...s..ms.......s.......s.......s.......s..Rich.s..................PE..d...OJ.f.........." ...(..... ...............................................@............`.........................................@...h............ ..........|/...........0.......`..............................._..@...............`............................text............................... ..`.rdata.............................@..@.data....>.......:..................@....pdata..|/.......0..................@..@.rsrc........ ......................@..@.reloc.......0......................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):24064
                                                                                                                                                                                                            Entropy (8bit):5.671576218459356
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:Bl6YwU58iEr4Pp/zosXH1UXAN+I6kIbHOKZHMxgaUJ:Bl6Yp8jrszoE1UXvTHOCHM6a
                                                                                                                                                                                                            MD5:D80E23C523BEA5ACA6EC702EF6DCBF8D
                                                                                                                                                                                                            SHA1:A363362E722B68AAEA9BA30965AF18AAB505BFE1
                                                                                                                                                                                                            SHA-256:C480EDC4EBD5757B92F543B0589AF0C6FEBF1153992B948322B7E69F2A0EAF61
                                                                                                                                                                                                            SHA-512:D1381B1B929DCDBDFF8AEF1D09E05E7DF8F31E8A6C2CB89015B343FE963CA04AFB448E84436C4A04A5EF704FAADBF290AD1780D28F940FAE11D06359F66553F6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Reputation:moderate, very likely benign file
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$...........B...B...B...K...F....t..@.......@....t..A....t..J....t..N...Qs..A...B...m...Qs..C...Qs..C...Qso.C...Qs..C...RichB...........PE..d...PJ.f.........." ...(.6...*......@9....................................................`.........................................@`..h....`..x...............8...............@....U...............................S..@............P..`............................text...(5.......6.................. ..`.rdata.......P.......:..............@..@.data...P....p.......P..............@....pdata..8............R..............@..@.rsrc................Z..............@..@.reloc..@............\..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):14848
                                                                                                                                                                                                            Entropy (8bit):5.083733997082165
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:sGrzuJtIEepKl1Cxmnyx1ttkobpsE0BDAXR09IckgTd2T:puJgp6Dy7XDbpsEiAXG9GgTd2
                                                                                                                                                                                                            MD5:6469B7315A33774D1C7EF7459058F889
                                                                                                                                                                                                            SHA1:FF37C958770C2BA3897D168A4AFBFFAD93E5E3BA
                                                                                                                                                                                                            SHA-256:317E4219DE122F058C86F858F11B9510B6D196FD8027DD35352E7784E6968500
                                                                                                                                                                                                            SHA-512:F56EA8983DA251908F7830A42EA57FEE1C6CD18EF00238693E108A9E58A560690769F69BBD639D2E5F239051012ACC17BC556CF3F5A09962B51ACE476FF471A2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Reputation:low
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........>.mm.mm.mm...m.mm.9ll.mm.9nl.mm.9il.mm.9hl.mm.>ll.mm..ll.mm.lm.mm.>el.mm.>ml.mm.>.m.mm.>ol.mmRich.mm................PE..d...PJ.f.........." ...(.....$......@.....................................................`..........................................;..d...$<.......p.......`..................<...`5.............................. 4..@............0...............................text...x........................... ..`.rdata.......0......................@..@.data...X....P.......0..............@....pdata.......`.......2..............@..@.rsrc........p.......6..............@..@.reloc..<............8..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):412160
                                                                                                                                                                                                            Entropy (8bit):6.5323629884961605
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6144:Tt4e4UJ0STq5yCQCGNmwNby50erYs2uhCKeg09wd:TtZT6SGwCrxsOrYQe
                                                                                                                                                                                                            MD5:C09A7A8EA25DDC38DC498806EAAAE8E4
                                                                                                                                                                                                            SHA1:9E96616D04B6E02EB5018A63A35069ED8C1FFF98
                                                                                                                                                                                                            SHA-256:78896672E2CD8346717F06EFED551347B3158DC10AAEC2FC61071C1791C06437
                                                                                                                                                                                                            SHA-512:2AD92553AFB5C40844AC66466E043750D8FC5E324B8700D518068F638C0AE7B9C963CA9D22F91FD5A462C6718FF742E3CFD2BF7E3658437C73935719AA8FEEB2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Reputation:moderate, very likely benign file
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........|.k...k...k.......k..]....k.......k..]....k..]....k..]....k.......k...k...k.......k.......k.......k.....k.......k..Rich.k..........................PE..d...OJ.f.........." ...(.....\............................................................`.........................................0...\....................`...<..................p...............................0...@............0...............................text...(........................... ..`.rdata.......0......................@..@.data....2... ......................@....pdata...<...`...>..................@..@.rsrc................F..............@..@.reloc...............H..............@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):120400
                                                                                                                                                                                                            Entropy (8bit):6.6017475353076716
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:1536:N9TXF5LLXQLlNycKW+D4SdqJk6aN1ACuyxLiyazYaCVoecbdhgOwAd+zfZ1zu:N9jelDoD9uyxLizzFzecbdPwA87S
                                                                                                                                                                                                            MD5:862F820C3251E4CA6FC0AC00E4092239
                                                                                                                                                                                                            SHA1:EF96D84B253041B090C243594F90938E9A487A9A
                                                                                                                                                                                                            SHA-256:36585912E5EAF83BA9FEA0631534F690CCDC2D7BA91537166FE53E56C221E153
                                                                                                                                                                                                            SHA-512:2F8A0F11BCCC3A8CB99637DEEDA0158240DF0885A230F38BB7F21257C659F05646C6B61E993F87E0877F6BA06B347DDD1FC45D5C44BC4E309EF75ED882B82E4E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......\=..\...\...\..S$...\...$...\...\..5\...\...\.....\.....\.....\.....\......\.....\..Rich.\..........PE..d.....x.........." ...).$...d............................................................`A........................................0u..4...d}..........................PP...........^..p............................\..@............@...............................text............................... ..`fothk........0...................... ..`.rdata...C...@...D...(..............@..@.data................l..............@....pdata...............p..............@..@_RDATA...............|..............@..@.rsrc................~..............@..@.reloc..............................@..B................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):49744
                                                                                                                                                                                                            Entropy (8bit):6.701724666218339
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:ApzzO6ujT3MbR3v0Cz6SR8q83yaFdWr9zRcmgEl6U9zSC:9q/oGw3fFdwzRcmZFzSC
                                                                                                                                                                                                            MD5:68156F41AE9A04D89BB6625A5CD222D4
                                                                                                                                                                                                            SHA1:3BE29D5C53808186EBA3A024BE377EE6F267C983
                                                                                                                                                                                                            SHA-256:82A2F9AE1E6146AE3CB0F4BC5A62B7227E0384209D9B1AEF86BBCC105912F7CD
                                                                                                                                                                                                            SHA-512:F7BF8AD7CD8B450050310952C56F6A20B378A972C822CCC253EF3D7381B56FFB3CA6CE3323BEA9872674ED1C02017F78AB31E9EB9927FC6B3CBA957C247E5D57
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......?.{...{...{...0...y.......y...r.H.p...{...H.......|.......`.......~.......z.....$.z.......z...Rich{...........PE..d...l0.?.........." ...).<...8.......@...............................................b....`A........................................pm.......m..x....................r..PP......D....c..p...........................`b..@............P..`............................text....;.......<.................. ..`.rdata.."#...P...$...@..............@..@.data................d..............@....pdata...............f..............@..@.rsrc................l..............@..@.reloc..D............p..............@..B................................................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):71448
                                                                                                                                                                                                            Entropy (8bit):6.274367479203647
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:1536:zF44laLwm4HS8NywUlz4dIvOnW7Sy85x4:zO4eBCxNywWEdIvOnWaA
                                                                                                                                                                                                            MD5:E74E8B37BD359F581F368BA092EED90E
                                                                                                                                                                                                            SHA1:E6BDC3494DBC5D4AE0434BF4DC3B2952E4827F18
                                                                                                                                                                                                            SHA-256:184FC13677C7856E7A8B31DFE79CE68DCEA10CDF83A205DE2B0D5497FB0FFDF3
                                                                                                                                                                                                            SHA-512:29D33593758945A02844E1333ED99D66A0E42EB7E8D0C881197F05D4EC9DAD3F1BB490739BC2D64EA9451F4BBBFCC05089A57A7AA1EC22C4091C7EDD604B7F7C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........Z...........%.....................................................K...................I...........Rich...................PE..d....g.f.........." ...).f................................................... ......HM....`.............................................P......d......................../..............T...........................P...@...............(............................text....e.......f.................. ..`.rdata...O.......P...j..............@..@.data...p...........................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):84760
                                                                                                                                                                                                            Entropy (8bit):6.5949173382940405
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:1536:ZWNz7JrA+VLsS53XtGHagwIF27YuLw8emTayR12FIvCVv7Sy+xJ:0Nzdb53XfoxKrbTBkFIvCVv4
                                                                                                                                                                                                            MD5:FE499B0A9F7F361FA705E7C81E1011FA
                                                                                                                                                                                                            SHA1:CC1C98754C6DAB53F5831B05B4DF6635AD3F856D
                                                                                                                                                                                                            SHA-256:160B5218C2035CCCBAAB9DC4CA26D099F433DCB86DBBD96425C933DC796090DF
                                                                                                                                                                                                            SHA-512:60520C5EB5CCC72AE2A4C0F06C8447D9E9922C5F9F1F195757362FC47651ADCC1CDBFEF193AE4FEC7D7C1A47CF1D9756BD820BE996AE145F0FBBBFBA327C5742
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......e...!...!...!...(.o.+...1I..#...1I.."...1I..%...1I..)...1I..,...iH.."...j...#...!...~...iH..)...iH.. ...iH.. ...iH.. ...Rich!...........PE..d....g.f.........." ...).....^......`........................................P............`.........................................0...H...x........0....... ..,......../...@..........T...........................p...@............................................text............................... ..`.rdata...>.......@..................@..@.data...............................@....pdata..,.... ......................@..@.rsrc........0......................@..@.reloc.......@......................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):179712
                                                                                                                                                                                                            Entropy (8bit):6.180800197956408
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3072:IULjhBCx8qImKrUltSfGzdMcbb9CF8OS7jkSTLkKWlgeml:IgCeqImzSfIMcNCvOkSTLLWWem
                                                                                                                                                                                                            MD5:FCB71CE882F99EC085D5875E1228BDC1
                                                                                                                                                                                                            SHA1:763D9AFA909C15FEA8E016D321F32856EC722094
                                                                                                                                                                                                            SHA-256:86F136553BA301C70E7BADA8416B77EB4A07F76CCB02F7D73C2999A38FA5FA5B
                                                                                                                                                                                                            SHA-512:4A0E98AB450453FD930EDC04F0F30976ABB9214B693DB4B6742D784247FB062C57FAFAFB51EB04B7B4230039AB3B07D2FFD3454D6E261811F34749F2E35F04D6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......a..#%p.p%p.p%p.p,..p)p.p5.q'p.p5.zp!p.p5.q!p.p5.q-p.p5.q)p.pn..q!p.p6.q&p.p%p.p.p.pm..q!p.p,..p$p.pm..q$p.pm.xp$p.pm..q$p.pRich%p.p........................PE..d...W..f.........." ...).....B......`........................................0............`..........................................h..l....i..................T............ .......O...............................M..@............................................text............................... ..`.rdata..............................@..@.data....].......0...p..............@....pdata..T...........................@..@.rsrc...............................@..@.reloc....... ......................@..B................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):125208
                                                                                                                                                                                                            Entropy (8bit):6.136121476280913
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3072:4LIBXrBDuYifTbergyzjsckxf/EfCODh1NlL5IvLPJjL:XBbBDuBf2HfUxf/EfBDn0
                                                                                                                                                                                                            MD5:302DDF5F83B5887AB9C4B8CC4E40B7A6
                                                                                                                                                                                                            SHA1:0AA06AF65D072EB835C8D714D0F0733DC2F47E20
                                                                                                                                                                                                            SHA-256:8250B4C102ABD1DBA49FC5B52030CAA93CA34E00B86CEE6547CC0A7F22326807
                                                                                                                                                                                                            SHA-512:5DDC2488FA192D8B662771C698A63FAAF109862C8A4DD0DF10FB113AEF839D012DF58346A87178AFF9A1B369F82D8AE7819CEF4AAD542D8BD3F91327FEACE596
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........f~.............................................................................){.............................................Rich............PE..d....g.f.........." ...)............P_....................................................`.........................................``.......`.........................../......t.......T...............................@............................................text............................... ..`.rdata..zl.......n..................@..@.data...,5.......0...j..............@....pdata..............................@..@.rsrc...............................@..@.reloc..t...........................@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):256792
                                                                                                                                                                                                            Entropy (8bit):6.572286948518575
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6144:hJ1fsF1yTr4Q6Vll9INhWyZHV89Ilxe99qWM53pLW1AdZZZEgtLMwDrijc:VvUVlEhBX2YcQaAnDOY
                                                                                                                                                                                                            MD5:82321FB8245333842E1C31F874329170
                                                                                                                                                                                                            SHA1:81ABB1D3D5C55DB53E8ACA9BDF74F2DEC0ABA1A3
                                                                                                                                                                                                            SHA-256:B7F9603F98EF232A2C5BCE7001D842C01D76ED35171AFBD898E6D17FACF38B56
                                                                                                                                                                                                            SHA-512:0CF932EE0D1242EA9377D054ADCD71FDD7EC335ABBAC865E82987E3979E24CEAD6939CCA19DA63A08E08AC64FACE16950EDCE7918E02BFC7710F09645FD2FA19
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........J6U.+X..+X..+X..S...+X..Y..+X..[..+X..\..+X..]..+X...Y..+X..SY..+X..+Y.E+X...[..+X...U..+X...X..+X......+X...Z..+X.Rich.+X.................PE..d....g.f.........." ...).....:............................................................`.........................................@c..P....c..................d&......./......T.......T...............................@............................................text............................... ..`.rdata..............................@..@.data...X*.......$...`..............@....pdata..d&.......(..................@..@.rsrc...............................@..@.reloc..T...........................@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):66328
                                                                                                                                                                                                            Entropy (8bit):6.229205873282761
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:mHhSlKxOZdShtmgHbGmZOEoSK3Ic0V3QBdIvOI25YiSyv/AMxkEU:CxO3I17DZRoh3Ic43WdIvOIM7Sy3xg
                                                                                                                                                                                                            MD5:0ABFEE1DB6C16E8DDAFF12CD3E86475B
                                                                                                                                                                                                            SHA1:B2DDA9635EDE4F2841912CC50CB3AE67EEA89FE7
                                                                                                                                                                                                            SHA-256:B4CEC162B985D34AB768F66E8FA41ED28DC2F273FDE6670EEACE1D695789B137
                                                                                                                                                                                                            SHA-512:0A5CAE4E3442AF1D62B65E8BF91E0F2A61563C2B971BBF008BFB2DE0F038EE472E7BFCC88663DC503B2712E92E6A7E6A5F518DDAB1FAB2EB435D387B740D2D44
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........WH@.6&..6&..6&..N...6&...'..6&...%..6&..."..6&...#..6&...'..6&..N'..6&...'..6&..6'.16&...+..6&...&..6&......6&...$..6&.Rich.6&.........................PE..d....g.f.........." ...).V..........0@....................................................`.........................................p...P................................/......X...@}..T............................|..@............p..(............................text....T.......V.................. ..`.rdata...O...p...P...Z..............@..@.data...............................@....pdata..............................@..@.rsrc...............................@..@.reloc..X...........................@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):158488
                                                                                                                                                                                                            Entropy (8bit):6.857717041623552
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3072:kf7P77jrFDn7NjQDRX17znfV9mNoHnIjN1VbHNiFIvZ1AB:kf7j9OD9YOH+bHNiJ
                                                                                                                                                                                                            MD5:E3E7E99B3C2EA56065740B69F1A0BC12
                                                                                                                                                                                                            SHA1:79FA083D6E75A18E8B1E81F612ACB92D35BB2AEA
                                                                                                                                                                                                            SHA-256:B095FA2EAC97496B515031FBEA5737988B18DEEE86A11F2784F5A551732DDC0C
                                                                                                                                                                                                            SHA-512:35CBC30B1CCDC4F5CC9560FC0149373CCD9399EB9297E61D52E6662BB8C56C6A7569D8CFAD85AEB057C10558C9352AE086C0467F684FDCF72A137EADF563A909
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........7...V.,.V.,.V.,..:,.V.,..-.V.,..-.V.,..-.V.,..-.V.,..-.V.,...-.V.,.V.,.V.,..-.V.,..-.V.,..V,.V.,..-.V.,Rich.V.,........PE..d....g.f.........." ...).`..........`2..............................................HP....`.............................................L...<...x....`.......@.......<.../...p..4....|..T............................{..@............p...............................text...f_.......`.................. ..`.rdata.......p.......d..............@..@.data...p....0......................@....pdata.......@......................@..@.rsrc........`.......0..............@..@.reloc..4....p.......:..............@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):35608
                                                                                                                                                                                                            Entropy (8bit):6.431265882453482
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:CI9pp7OBajKCD2yil0uduNIvWtR5YiSyv/7AMxkEsR:CoptOBaJDil0uINIvWtf7SyLxC
                                                                                                                                                                                                            MD5:4DAA82AAFC49DD75DAEA468CC37EF4B0
                                                                                                                                                                                                            SHA1:CBF05ABC0EB9A6529AA01955D5FEAC200E602C89
                                                                                                                                                                                                            SHA-256:A197F3485BBE30B3A1612EA2198CEF121AF440BA799FD6CBF0AD3493150DF3CA
                                                                                                                                                                                                            SHA-512:473CAA70EC832B645296EBA3DA2DC0BBFC90DF15281A9DE612A2FEBF10B7E86D7F20F1C265C7BE693BC0D25E11D3D2904F4C2B1039A81AE0E192CFCA625408D5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......2.W)v.9zv.9zv.9z..zt.9zf,8{t.9zf,:{u.9zf,={~.9zf,<{{.9z>-8{t.9zv.8z..9z=.8{s.9z>-4{t.9z>-9{w.9z>-.zw.9z>-;{w.9zRichv.9z................PE..d....g.f.........." ...). ...>......@...............................................&.....`.........................................@E..`....E..x............p.......\.../...........4..T............................3..@............0...............................text............ .................. ..`.rdata... ...0..."...$..............@..@.data...`....`.......F..............@....pdata.......p.......L..............@..@.rsrc................P..............@..@.reloc...............Z..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):56088
                                                                                                                                                                                                            Entropy (8bit):6.331887829832768
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:1536:+5i+rYIgKZPXZCJ/+SdwDDrxIvXtF7SySxP4:+50J/+SdwDDrxIvXtFy4
                                                                                                                                                                                                            MD5:B89FCA6EDBA418768147E455085F7CC7
                                                                                                                                                                                                            SHA1:5D41E0990E19EE0D131B4FE8C6AC5B7371D1F83E
                                                                                                                                                                                                            SHA-256:2AF91C5AB6F05C4BE357B93673920ECCF3EBCAD5E5EC6B0A7B53EF94A5FEAAD7
                                                                                                                                                                                                            SHA-512:A6BD8D62FB1FBEBBFA9FEE9037EFFBCBBB48BFA2E6C8B398E036C0BD5F402A4B1C0BF0AD8D80585FE501E00D7FE21B387A0F0E05AD2FCDF3AEB248010CB3F1BE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........N.{X/.(X/.(X/.(QW_(\/.(H..)Z/.(H..)[/.(H..)P/.(H..)T/.(...)Z/.(X/.(//.(.W.)]/.(.W.)Y/.(...)Y/.(...)Y/.(..3(Y/.(...)Y/.(RichX/.(........................PE..d....g.f.........." ...).N...`.......................................................8....`.............................................X.............................../......(....f..T............................e..@............`...............................text...7L.......N.................. ..`.rdata...8...`...:...R..............@..@.data...0...........................@....pdata..............................@..@.rsrc...............................@..@.reloc..(...........................@..B........................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):32536
                                                                                                                                                                                                            Entropy (8bit):6.553393437193411
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:g1zRmezk6rGq17W45IvQUcV5YiSyvRfAMxkE4:QRm0lGY7W45IvQUc77SyhxM
                                                                                                                                                                                                            MD5:941A3757931719DD40898D88D04690CB
                                                                                                                                                                                                            SHA1:177EDE06A3669389512BFC8A9B282D918257BF8B
                                                                                                                                                                                                            SHA-256:BBE7736CAED8C17C97E2B156F686521A788C25F2004AAE34AB0C282C24D57DA7
                                                                                                                                                                                                            SHA-512:7CFBA5C69695C492BF967018B3827073B0C2797B24E1BD43B814FBBB39D1A8B32A2D7EF240E86046E4E07AA06F7266A31B5512D04D98A0D2D3736630C044546E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........\...........%.........................................................................I...........Rich...................PE..d....g.f.........." ...).....8............................................................`..........................................C..L...<D..d....p.......`.......P.../...........4..T...........................@3..@............0..8............................text............................... ..`.rdata.......0......................@..@.data........P.......<..............@....pdata.......`.......@..............@..@.rsrc........p.......D..............@..@.reloc...............N..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):83736
                                                                                                                                                                                                            Entropy (8bit):6.318116609837273
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:1536:3OYxHEUZql2HLSyypHb9/s+S+pzG8iFWmIHJqKN5IvLw767SyZxqND:+dUZqzyypHb9/sT+pzG8CxIpdN5IvLwD
                                                                                                                                                                                                            MD5:632336EEEAD53CFAD22EB57F795D5657
                                                                                                                                                                                                            SHA1:62F5F73D21B86CD3B73B68E5FAEC032618196745
                                                                                                                                                                                                            SHA-256:CE3090FFF8575B21287DF5FC69AE98806646FC302EEFADF85E369AD3DEBAD92B
                                                                                                                                                                                                            SHA-512:77965B45060545E210CDB044F25E5FD68D6A9150CAF1CAD7645DBAFCF1CE8E1CCBDF8436FBDCBF5F9C293321C8916E114DE30ED8897C7DB72DF7F8D1F98DFB55
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........,...Ml}.Ml}.Ml}.5.}.Ml}..m|.Ml}..o|.Ml}..h|.Ml}..i|.Ml}..m|.Ml}.Mm}.Ml}.5m|.Ml}..a|.Ml}..l|.Ml}..}.Ml}..n|.Ml}Rich.Ml}................PE..d....g.f.........." ...).x..........0-.......................................`......75....`.........................................@...P............@.......0.........../...P......P...T...............................@............................................text....v.......x.................. ..`.rdata...x.......z...|..............@..@.data...............................@....pdata.......0......................@..@.rsrc........@......................@..@.reloc.......P......................@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):177944
                                                                                                                                                                                                            Entropy (8bit):5.9708659528965855
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3072:V1l+KugCpMRjN/ft6X6k7GxOnvvkKuFBZd4rYcvsswCfyX0NoFFIvC75/:V1QKugCpAJHt6X6nKvv9gF5
                                                                                                                                                                                                            MD5:EEA3E12970E28545A964A95DA7E84E0B
                                                                                                                                                                                                            SHA1:C3CCAC86975F2704DABC1FFC3918E81FEB3B9AC1
                                                                                                                                                                                                            SHA-256:61F00B0543464BBA61E0BD1128118326C9BD0CDC592854DD1A31C3D6D8DF2B83
                                                                                                                                                                                                            SHA-512:9BD5C83E7E0AB24D6BE40A31AC469A0D9B4621A2A279A5F3AB2FC6401A08C54AEC421BC9461AED533A0211D7DBDA0C264C5F05AEB39138403DA25C8CDA0339E6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........I.^.(k..(k..(k..P...(k...j..(k...h..(k...o..(k...n..(k..j..(k...j..(k..(j..)k..Pj..(k..f..(k..k..(k.....(k..i..(k.Rich.(k.........PE..d....g.f.........." ...).............,...................................................`.............................................d...T...................D......../......x...p...T...........................0...@............................................text...D........................... ..`.rdata..x".......$..................@..@.data...p...........................@....pdata..D............`..............@..@.rsrc................l..............@..@.reloc..x............v..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):21523
                                                                                                                                                                                                            Entropy (8bit):4.827830596623684
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:UqT9XC9VZv9QXCTxsCTHI7672ORgS0mzBvxFRTX7Xvt3wBTnFXhCUvuyqz:LT9XC9VZviXCVsCLI7JlmzBvTxvt3gTW
                                                                                                                                                                                                            MD5:08EDF746B4A088CB4185C165177BD604
                                                                                                                                                                                                            SHA1:395CDA114F23E513EEF4618DA39BB86D034124BF
                                                                                                                                                                                                            SHA-256:517204EE436D08EFC287ABC97433C3BFFCAF42EC6592A3009B9FD3B985AD772C
                                                                                                                                                                                                            SHA-512:C1727E265A6B0B54773C886A1BCE73512E799BA81A4FCEEEB84CDC33F5505A5E0984E96326A78C46BF142BC4652A80E213886F60EB54ADF92E4DFFE953C87F6B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# auto.tcl --..#..# utility procs formerly in init.tcl dealing with auto execution of commands..# and can be auto loaded themselves...#..# Copyright (c) 1991-1993 The Regents of the University of California...# Copyright (c) 1994-1998 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# auto_reset --..#..# Destroy all cached information for auto-loading and auto-execution, so that..# the information gets recomputed the next time it's needed. Also delete any..# commands that are listed in the auto-load index...#..# Arguments:..# None.....proc auto_reset {} {.. global auto_execs auto_index auto_path.. if {[array exists auto_index]} {...foreach cmdName [array names auto_index] {... set fqcn [namespace which $cmdName]... if {$fqcn eq ""} {....continue... }... rename $fqcn {}...}.. }.. unset -nocomplain auto_execs auto_index ::tcl::auto_oldpath.. if {
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):133439
                                                                                                                                                                                                            Entropy (8bit):5.044814789288095
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3072:Cbn4IAhYvuCg9epsArAzqpSMpWzP7ejMiIAxBPqGYkPAPaZpHYM8EN4LhVLlarXL:Cbn4IM9epsArSqpSMpWzP7ejM/eBPqG3
                                                                                                                                                                                                            MD5:88BB44A1364147FDD80F9FD78FBCEF61
                                                                                                                                                                                                            SHA1:2C3454D2669F0CA83FECF17976D599C85B86E615
                                                                                                                                                                                                            SHA-256:1947F8B188AB4AB6AA72EA68A58D2D9ADD0894FDF320F6B074EAE0F198368FB7
                                                                                                                                                                                                            SHA-512:010B13E8A2D50521B5D7ADCC5F32F7CDE3F12E1053961C575D967DC6CFD368640BF45D23832E5E9C3868CDCA9FE0505698F949C5557D4169353634C94AA196B5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#----------------------------------------------------------------------..#..# clock.tcl --..#..#.This file implements the portions of the [clock] ensemble that are..#.coded in Tcl. Refer to the users' manual to see the description of..#.the [clock] command and its subcommands...#..#..#----------------------------------------------------------------------..#..# Copyright (c) 2004-2007 Kevin B. Kenny..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#..#----------------------------------------------------------------------....# We must have message catalogs that support the root locale, and we need..# access to the Registry on Windows systems.....uplevel \#0 {.. package require msgcat 1.6.. if { $::tcl_platform(platform) eq {windows} } {...if { [catch { package require registry 1.1 }] } {... namespace eval ::tcl::clock [list variable NoRegistry {}]...}.. }..}....# Put the library directory in
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1110
                                                                                                                                                                                                            Entropy (8bit):2.1033474959326957
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:5c2VBUvEWVrVJ/eyN9j2iV2NdWWT0VbusV7EV7KVAMmVZyd851VFpsGkliX:5HVBUlJvRj7SOVbusZhAMiZyi77qsX
                                                                                                                                                                                                            MD5:9E3A454FA480E9A99D2D5ACDAA775233
                                                                                                                                                                                                            SHA1:493637BB570A5C96BB62F998BD0391FB59AFC5F0
                                                                                                                                                                                                            SHA-256:FB87BF197F4F485B08EA81F7534BC07D9C3A538D022424BE11011A1FE3C413FD
                                                                                                                                                                                                            SHA-512:EDFCB2BB6AB052D28D5CEBD08AD57F36D3A4CB83D557B1359B0ADE1266E24D8F3CE87B8240881396A5BA4FB45F8B74014784E8885CDB86680D98977CC0D130F0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: ascii, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E0000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):94389
                                                                                                                                                                                                            Entropy (8bit):3.3217406555698195
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:UAHU3LIkZlmXrd/uQ0ao98zgKSTEvZPHb6qRL5NpiadDp0ZBFR6YR/fd:UVduBGf94gFMT6q95GDRBfd
                                                                                                                                                                                                            MD5:41A874778111CC218BD421CF9C795EC2
                                                                                                                                                                                                            SHA1:80857D106F71199CE187833D38DB091A819A520C
                                                                                                                                                                                                            SHA-256:AD1ED201B69855BFD353BF969DFC55576DA35A963ABF1BF7FC6D8B5142A61A61
                                                                                                                                                                                                            SHA-512:4244624124F86A3EFAB4C70B115A46C8ADF02D708860FA5F327CDBFA24BC3F9EFAD0C6EE58DE96B0B6BBC4CF6D99B322BB8657129007C86D6482F41C1503AAD4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: big5, multi-byte..M..003F 0 89..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..00000000000000000000000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):98634
                                                                                                                                                                                                            Entropy (8bit):2.438904802083714
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:MPFOsOKqBLPf62X4lgQeLHj6RHUn0TQb8G47Ianrd28gr:MPAsknjX4OQe7aoMMarAFr
                                                                                                                                                                                                            MD5:B6A7C59E6A48D91CC2DBCB2BBA7E4510
                                                                                                                                                                                                            SHA1:16A9338F18202B26981F2028BEA412DD03BB0FF2
                                                                                                                                                                                                            SHA-256:8924545CC92584169138AADB64683C07BBF846A57014C2E668D23B63F43F3610
                                                                                                                                                                                                            SHA-512:3D644CF394A528A8699BE3679F787A4E1DAD657C04B810580A4C520F2C043471640FBE080AC46DFD3924C47A73BEE12A6AC69D291D09EB791AD0D64A73750B43
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cns11643, double-byte..D..2134 0 93..21..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..00004E284E364E3F4E854E054E04518251965338536953B64E2A4E874E4951E2..4E464E8F4EBC4EBE516651E35204529C53B95902590A5B805DDB5E7A5E7F5EF4..5F505F515F61961D4E3C4E634E624EA351854EC54ECF4ECE4ECC518451865722..572351E45205529E529D52FD5300533A5C735346535D538653B7620953CC6C15..53CE57216C3F5E005F0C623762386534653565E04F0E738D4E974EE04F144EF1..4EE74EF74EE64F1D4F024F054F2256D8518B518C519951E55213520B52A60000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1111
                                                                                                                                                                                                            Entropy (8bit):3.3578844928761034
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CqHVBUlJvRj7SOVbusZhAMiZyi77q8ujr4z8tjsuVO6ys2K:JMlBVnrAMiwMm8ujr4z8emTys2K
                                                                                                                                                                                                            MD5:9568EDE60D3F917F1671F5A625A801C4
                                                                                                                                                                                                            SHA1:4F5B3308FE7F6845B46779DECF9B395E47AC7396
                                                                                                                                                                                                            SHA-256:E2991A6F7A7A4D8D3C4C97947298FD5BACB3EAA2F898CEE17F5E21A9861B9626
                                                                                                                                                                                                            SHA-512:9C32BE3E25FC2211CE91F7B9AE1F9EBA20071272BE2BBBA63A8B6E3CD6543C4C32CD62C4C4D153C94F5BE212E974A61EEFD70DDC005F1688D09D9D56E8E298A8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp1250, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC0081201A0083201E2026202020210088203001602039015A0164017D0179..009020182019201C201D202220132014009821220161203A015B0165017E017A..00A002C702D8014100A4010400A600A700A800A9015E00AB00AC00AD00AE017B..00B000B102DB014200B400B500B600B700B80105015F00BB013D02DD013E017C..015400C100C2010200C40139010600C7010C00C9011800CB011A00CD00CE010E..01100143014700D300D4015000D600D70158016E00DA017000DC00DD016200DF..015500E100E2010300E40
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1111
                                                                                                                                                                                                            Entropy (8bit):3.358948900439905
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CTHVBUlJvRj7SOVbusZhAMiZyi77qpREwKsF/+++SAJlz9aRme3cJI:wMlBVnrAMiwMmpKwKm/EYnsJI
                                                                                                                                                                                                            MD5:83DAF47FD1F87B7B1E9E086F14C39E5B
                                                                                                                                                                                                            SHA1:77AE330512EBFEF430A02213644BD1CFCE174298
                                                                                                                                                                                                            SHA-256:0AA66DFF8A7AE570FEE83A803F8F5391D9F0C9BD6311796592D9B6E8E36BE6FC
                                                                                                                                                                                                            SHA-512:D7CE2F44EDFE1DA6D3E07E9A41BB08AD42430BAAFADD09FD217F4B524323A01A1F4913B640C552D38AAEBFF75B0D50ED7A813A2A57C4019311158890C0162DF9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp1251, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..04020403201A0453201E20262020202120AC203004092039040A040C040B040F..045220182019201C201D202220132014009821220459203A045A045C045B045F..00A0040E045E040800A4049000A600A7040100A9040400AB00AC00AD00AE0407..00B000B104060456049100B500B600B704512116045400BB0458040504550457..0410041104120413041404150416041704180419041A041B041C041D041E041F..0420042104220423042404250426042704280429042A042B042C042D042E042F..043004310432043304340
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1111
                                                                                                                                                                                                            Entropy (8bit):3.292994562910468
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:C4HVBUlJvRj7SOVbusZhAMiZyi77qdmV/rcwvGNNlkL+rSMH+tKv:rMlBVnrAMiwMmd2r/okLz0
                                                                                                                                                                                                            MD5:E9117326C06FEE02C478027CB625C7D8
                                                                                                                                                                                                            SHA1:2ED4092D573289925A5B71625CF43CC82B901DAF
                                                                                                                                                                                                            SHA-256:741859CF238C3A63BBB20EC6ED51E46451372BB221CFFF438297D261D0561C2E
                                                                                                                                                                                                            SHA-512:D0A39BC41ADC32F2F20B1A0EBAD33BF48DFA6ED5CC1D8F92700CDD431DB6C794C09D9F08BB5709B394ACF54116C3A1E060E2ABCC6B503E1501F8364D3EEBCD52
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp1252, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC0081201A0192201E20262020202102C62030016020390152008D017D008F..009020182019201C201D20222013201402DC21220161203A0153009D017E0178..00A000A100A200A300A400A500A600A700A800A900AA00AB00AC00AD00AE00AF..00B000B100B200B300B400B500B600B700B800B900BA00BB00BC00BD00BE00BF..00C000C100C200C300C400C500C600C700C800C900CA00CB00CC00CD00CE00CF..00D000D100D200D300D400D500D600D700D800D900DA00DB00DC00DD00DE00DF..00E000E100E200E300E40
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1111
                                                                                                                                                                                                            Entropy (8bit):3.422723556981327
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CRHVBUlJvRj7SOVbusZhAMiZyi77qduWn4T5K9QQSqiWeIDDdn:CMlBVnrAMiwMmduWnSKyQSqiWeIVn
                                                                                                                                                                                                            MD5:441B86A0DE77F25C91DF1CD4685F651D
                                                                                                                                                                                                            SHA1:D1E429916BC9423F55EEC8F17941521E9FE9D32B
                                                                                                                                                                                                            SHA-256:5B8D47451F847C1BDE12CACA3739CA29860553C0B6399EE990D51B26F9A69722
                                                                                                                                                                                                            SHA-512:35DF342DDA4E8790C6D53762465DF8B93B49B7B7E211D7A5753078EF559C9C9383EFF7285A90FF5C0020FBB16AF380EE3C8643F4CEB1E41917E72021079D722F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp1253, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC0081201A0192201E20262020202100882030008A2039008C008D008E008F..009020182019201C201D20222013201400982122009A203A009C009D009E009F..00A00385038600A300A400A500A600A700A800A9000000AB00AC00AD00AE2015..00B000B100B200B3038400B500B600B703880389038A00BB038C00BD038E038F..0390039103920393039403950396039703980399039A039B039C039D039E039F..03A003A1000003A303A403A503A603A703A803A903AA03AB03AC03AD03AE03AF..03B003B103B203B303B40
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1111
                                                                                                                                                                                                            Entropy (8bit):3.307590929679485
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CWHVBUlJvRj7SOVbusZhAMiZyi77qdjrcFvGNNlkBSMH+tA/b:lMlBVnrAMiwMmdjriokgzAD
                                                                                                                                                                                                            MD5:5FA9162BEC5A4DEA97B5EA2840CFB065
                                                                                                                                                                                                            SHA1:F26858E3D2FB928F39CA87CBB8446AF099570CAD
                                                                                                                                                                                                            SHA-256:31639CA96A4D3602D59BD012540FE179917E0561CB11A0D0B61F1B950EB76911
                                                                                                                                                                                                            SHA-512:3CE7BEABBE1A0CB946149D263D3317A8B791F6D72C49DEC4621E27F50CC359D8FA3EE97C03FF05D44E47DAA59DB87F219386467614B8B3FF8CC21AB3E3BED5E6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp1254, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC0081201A0192201E20262020202102C62030016020390152008D008E008F..009020182019201C201D20222013201402DC21220161203A0153009D009E0178..00A000A100A200A300A400A500A600A700A800A900AA00AB00AC00AD00AE00AF..00B000B100B200B300B400B500B600B700B800B900BA00BB00BC00BD00BE00BF..00C000C100C200C300C400C500C600C700C800C900CA00CB00CC00CD00CE00CF..011E00D100D200D300D400D500D600D700D800D900DA00DB00DC0130015E00DF..00E000E100E200E300E40
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1111
                                                                                                                                                                                                            Entropy (8bit):3.3385880810272774
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CfHVBUlJvRj7SOVbusZhAMiZyi77qdIn2hEeGlRhv6Mw6Kcv:MMlBVnrAMiwMmdInSEdhvrj7
                                                                                                                                                                                                            MD5:6DEA4179969D6C81C66C3B0F91B39769
                                                                                                                                                                                                            SHA1:7E2722576BFFABC3258C5EDB2D99FA2468D6A4B0
                                                                                                                                                                                                            SHA-256:47576CAE321C80E69C7F35205639680BF28010111E86E228ED191B084FAC6B91
                                                                                                                                                                                                            SHA-512:91CC626B6454517F06FB3616E9ED623D1A2A4BFE74AFA9885F00F6AEC835D8825A5587091B9D9AB0E5ABDA291FA3FE7CE87E2618E21EB2974D9118AE27B8A2FF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp1255, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC0081201A0192201E20262020202102C62030008A2039008C008D008E008F..009020182019201C201D20222013201402DC2122009A203A009C009D009E009F..00A000A100A200A320AA00A500A600A700A800A900D700AB00AC00AD00AE00AF..00B000B100B200B300B400B500B600B700B800B900F700BB00BC00BD00BE00BF..05B005B105B205B305B405B505B605B705B805B9000005BB05BC05BD05BE05BF..05C005C105C205C305F005F105F205F305F40000000000000000000000000000..05D005D105D205D305D40
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1111
                                                                                                                                                                                                            Entropy (8bit):3.4033510023542655
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:C0HVBUlJvRj7SOVbusZhAMiZyi77q30pPE7Lym4cwGm+AMZjyG/JQIG/Y:XMlBVnrAMiwMm30FQLym4ys6Jg/Y
                                                                                                                                                                                                            MD5:D50DFAFEE5C605C5C00A25A9EEE4D4CF
                                                                                                                                                                                                            SHA1:7D51BC17931D3D809716C06E7F07C6011286A144
                                                                                                                                                                                                            SHA-256:29340EA8E5AD3532BF67FA77CC852F055081B1238925CB109908AA72804CCC04
                                                                                                                                                                                                            SHA-512:D0A9B422A1061D6239E442767069B987E33239FCBA9BACE677923888F5F8BD1DCAABC71B83A985A0A86A15DCC44316781665BBFBF24558FCB94FDA6783285BCB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp1256, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC067E201A0192201E20262020202102C62030067920390152068606980688..06AF20182019201C201D20222013201406A921220691203A0153200C200D06BA..00A0060C00A200A300A400A500A600A700A800A906BE00AB00AC00AD00AE00AF..00B000B100B200B300B400B500B600B700B800B9061B00BB00BC00BD00BE061F..06C1062106220623062406250626062706280629062A062B062C062D062E062F..063006310632063306340635063600D7063706380639063A0640064106420643..00E0064400E2064506460
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1111
                                                                                                                                                                                                            Entropy (8bit):3.344584404753015
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CNHVBUlJvRj7SOVbusZhAMiZyi77q8uWTfNL4wIBUioGndt:uMlBVnrAMiwMm8uWJDNIt
                                                                                                                                                                                                            MD5:CC3D24543FDD4644BBBD4AAB30CA71BC
                                                                                                                                                                                                            SHA1:8E2658E7F782F005411BCB8423BDFC3C68BDED14
                                                                                                                                                                                                            SHA-256:C15AB85438728BF2C60D72B1A66AF80E8B1CE3CF5EB08BA6421FF1B2F73ACDF4
                                                                                                                                                                                                            SHA-512:5ECABF820098F7D24AB806ADD9CA3E1087C29914FB2DE6BA3DC656234202DE3FDF80A7E9ED433CCB2149FF07184F74884CEB37A1B689E9E0C1402916F3E13AFE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp1257, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC0081201A0083201E20262020202100882030008A2039008C00A802C700B8..009020182019201C201D20222013201400982122009A203A009C00AF02DB009F..00A0000000A200A300A4000000A600A700D800A9015600AB00AC00AD00AE00C6..00B000B100B200B300B400B500B600B700F800B9015700BB00BC00BD00BE00E6..0104012E0100010600C400C501180112010C00C90179011601220136012A013B..01600143014500D3014C00D500D600D701720141015A016A00DC017B017D00DF..0105012F0101010700E40
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1111
                                                                                                                                                                                                            Entropy (8bit):3.2984943182702593
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CKlHVBUlJvRj7SOVbusZhAMiZyi77qdIQ2jFvGNNykoxWi3/i:xMlBVnrAMiwMmdIQufkoxn3q
                                                                                                                                                                                                            MD5:12BCEAE6B6A5FAE5AE9C42F5998BA485
                                                                                                                                                                                                            SHA1:C9620DA0C763D2C3770386E69EE7E421BD1BA965
                                                                                                                                                                                                            SHA-256:29D93DEE7C01B2264778BC6B75F6EF76EA6AC53E9F4A334D83707229E7F482D2
                                                                                                                                                                                                            SHA-512:714BAF58462FB0E84A32D82C8FC2D63EDF78DF8CCE578391E2521737F94F860B5CCFE41B481E1D09879A6811FCFD8B98A2724DB1D15749BD5293A9B33BCAD071
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp1258, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC0081201A0192201E20262020202102C62030008A20390152008D008E008F..009020182019201C201D20222013201402DC2122009A203A0153009D009E0178..00A000A100A200A300A400A500A600A700A800A900AA00AB00AC00AD00AE00AF..00B000B100B200B300B400B500B600B700B800B900BA00BB00BC00BD00BE00BF..00C000C100C2010200C400C500C600C700C800C900CA00CB030000CD00CE00CF..011000D1030900D300D401A000D600D700D800D900DA00DB00DC01AF030300DF..00E000E100E2010300E40
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1110
                                                                                                                                                                                                            Entropy (8bit):3.515546664597914
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CFyHVBUlJvRj7SOVbusZhAMiZyi77qZpuHVBIqE18wDyV8mK:wyMlBVnrAMiwMm+VhE1LmK
                                                                                                                                                                                                            MD5:CE6D8A6542DC12D1783084FA4B2B63EA
                                                                                                                                                                                                            SHA1:5039A350C8E3E2C6F353B438B41BD0B6A7AB8069
                                                                                                                                                                                                            SHA-256:E5613C04D3D2EE44CCAD85AE53A37C257674491C540836E5D942BBCC4E4A8DB4
                                                                                                                                                                                                            SHA-512:E8C5CFB747486BBE0E567B6E87B59D5246D749A80C8F64F6669227C7FD849886F98A1F94451922AC099409AC14890F1A8B1E5F25EA584FDB1522ACE3AD0BE6A6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp437, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C700FC00E900E200E400E000E500E700EA00EB00E800EF00EE00EC00C400C5..00C900E600C600F400F600F200FB00F900FF00D600DC00A200A300A520A70192..00E100ED00F300FA00F100D100AA00BA00BF231000AC00BD00BC00A100AB00BB..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..03B100DF039303C003A303
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1110
                                                                                                                                                                                                            Entropy (8bit):3.6177058818384693
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CjHVBUlJvRj7SOVbusZhAMiZyi77qSKOQFhWehDrq18wDyVKockoiH:WMlBVnrAMiwMmSKOQFhWeh3q1odH
                                                                                                                                                                                                            MD5:8EF3CBCA101F5777846D12D3C96A0A7D
                                                                                                                                                                                                            SHA1:5EC5418B861894E0F18EA15AA4414019815E2EA2
                                                                                                                                                                                                            SHA-256:A0415F14F5D72AD24E9C3A5C91517A0E3D22E1ADBC3505C0C6E918B961F7A07D
                                                                                                                                                                                                            SHA-512:FB14C88E61E5459B4A8706751D88D0A261AC6B4171F72912D87CE78A2BC97A821CCF5B53676FB229C08F9E557BE624F4DC649B722A906B9B7944ED2D5E7F9065
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp737, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..039103920393039403950396039703980399039A039B039C039D039E039F03A0..03A103A303A403A503A603A703A803A903B103B203B303B403B503B603B703B8..03B903BA03BB03BC03BD03BE03BF03C003C103C303C203C403C503C603C703C8..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..03C903AC03AD03AE03CA03
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1110
                                                                                                                                                                                                            Entropy (8bit):3.451057608106102
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CsOHVBUlJvRj7SOVbusZhAMiZyi77qoo9ecL067J4ZNUPVw3PfA:AMlBVnrAMiwMm59T067KDLPo
                                                                                                                                                                                                            MD5:9656761FA02EA24773EAD3E5C4BDB975
                                                                                                                                                                                                            SHA1:366228F25392708FA799E9CC0830CE9917EF6CA7
                                                                                                                                                                                                            SHA-256:C3C6542E902DEC2C44DDCFD8B5CB7ABF309B0413A7CED1614DC0B20CF7C5E35F
                                                                                                                                                                                                            SHA-512:A6A44B9A2193D75764DC284BE53264E57BFEB2A221FD54B4577DD90752F69A45E6B9D293108A7AB895F347A24FD10AAE84954A043AB1F466F485D707D7412380
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp775, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..010600FC00E9010100E4012300E501070142011301560157012B017900C400C5..00C900E600C6014D00F6012200A2015A015B00D600DC00F800A300D800D700A4..0100012A00F3017B017C017A201D00A600A900AE00AC00BD00BC014100AB00BB..259125922593250225240104010C01180116256325512557255D012E01602510..25142534252C251C2500253C0172016A255A25542569256625602550256C017D..0105010D01190117012F01610173016B017E2518250C25882584258C25902580..00D300DF014C014300F500
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1110
                                                                                                                                                                                                            Entropy (8bit):3.3718781469586827
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:C9HVBUlJvRj7SOVbusZhAMiZyi77qZpuHVBc+myS5LeQDTVwA:EMlBVnrAMiwMm+VeyS5SQn/
                                                                                                                                                                                                            MD5:2169EE726DCC011E6C3505D586C88FC3
                                                                                                                                                                                                            SHA1:094252AD0634787E2D7F0D28A448437054D359C7
                                                                                                                                                                                                            SHA-256:13DF611F429A9B331DA1B34F3C718CCCAF0BD4AB44F71A9C632197987B4D643B
                                                                                                                                                                                                            SHA-512:BC5831EF1C131095A22C76FFCB5C4217081AF796B60455BE2DE2E2689CFE1033F07E8B45449F77E7804A7D52CBCFB916B0B4639828E65B14475BB3367F47C8EE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp850, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C700FC00E900E200E400E000E500E700EA00EB00E800EF00EE00EC00C400C5..00C900E600C600F400F600F200FB00F900FF00D600DC00F800A300D800D70192..00E100ED00F300FA00F100D100AA00BA00BF00AE00AC00BD00BC00A100AB00BB..2591259225932502252400C100C200C000A9256325512557255D00A200A52510..25142534252C251C2500253C00E300C3255A25542569256625602550256C00A4..00F000D000CA00CB00C8013100CD00CE00CF2518250C2588258400A600CC2580..00D300DF00D400D200F500
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1110
                                                                                                                                                                                                            Entropy (8bit):3.4509005787389877
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CPHVBUlJvRj7SOVbusZhAMiZyi77q7EUsOtycwQIc+922V:mMlBVnrAMiwMmwvOtycwQIc+9R
                                                                                                                                                                                                            MD5:48402B424B5101BDEEB0192BBA96DB7D
                                                                                                                                                                                                            SHA1:C9EB93A37AF70F4134AA9CF05D914A30FB3201DD
                                                                                                                                                                                                            SHA-256:F3A18A8C7934F6586F023477E08D3F9D5EAD9A45E9E58A3F8D018AF9BB13F868
                                                                                                                                                                                                            SHA-512:4EE615605BFF3D94A7FC4FE23D8288F0F20F6792C8C69ECACABAE82F1A334D8417C5DFFC0DA3702E2DB09B7BE1E5FF19C6A0F460C9A5EC84D1856BB9C8061CA5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp852, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C700FC00E900E200E4016F010700E7014200EB0150015100EE017900C40106..00C90139013A00F400F6013D013E015A015B00D600DC01640165014100D7010D..00E100ED00F300FA01040105017D017E0118011900AC017A010C015F00AB00BB..2591259225932502252400C100C2011A015E256325512557255D017B017C2510..25142534252C251C2500253C01020103255A25542569256625602550256C00A4..01110110010E00CB010F014700CD00CE011B2518250C258825840162016E2580..00D300DF00D40143014401
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1110
                                                                                                                                                                                                            Entropy (8bit):3.4277025591531864
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CoHVBUlJvRj7SOVbusZhAMiZyi77qLHVWjwk/rMZC032SLnD2JbD:hMlBVnrAMiwMmx8whM03VLDy
                                                                                                                                                                                                            MD5:8B8AA56F83BA750EB73FAE542E76FF1A
                                                                                                                                                                                                            SHA1:2F3C3BA4B854A7D6B0A3D27BC519EE66A042E05A
                                                                                                                                                                                                            SHA-256:E64FD2E639DA6F654D9BFBB2266F9432259A6A55941622F5CDDC3797E382EB0A
                                                                                                                                                                                                            SHA-512:8B4061176663F7AC01B3969D25F680B5870A8EAD864CFAD897F18E75409CE721E6CC367A88EBABAF72E77D4542EE1894F2A6EE47A43FB3D4C650CFA18DFD3D71
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp855, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0452040204530403045104010454040404550405045604060457040704580408..04590409045A040A045B040B045C040C045E040E045F040F044E042E044A042A..0430041004310411044604260434041404350415044404240433041300AB00BB..259125922593250225240445042504380418256325512557255D043904192510..25142534252C251C2500253C043A041A255A25542569256625602550256C00A4..043B041B043C041C043D041D043E041E043F2518250C25882584041F044F2580..042F044004200441042104
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1110
                                                                                                                                                                                                            Entropy (8bit):3.364496856690505
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CaHVBUlJvRj7SOVbusZhAMiZyi77qZpu6uUV5Dw5LeBCVHjzA:jMlBVnrAMiwMmyUVFw5SYdI
                                                                                                                                                                                                            MD5:BA52A031DE1B1A6ED1C41BED8946750C
                                                                                                                                                                                                            SHA1:BD54C0E2F62FD36675892A61FD8B340A56845D20
                                                                                                                                                                                                            SHA-256:B6CD5C6F2B54D89142679D599ED0A5DEE6955A3B3F6B6673E46AFE7A5A303CDC
                                                                                                                                                                                                            SHA-512:5F915AABE39F31CE9337B4B9B0239DF8ADA898D2D9F111DD09D97689DB89CF45B093AC187FC28484CFB213D14B0D8F58C5668D0A59726282D6F52D5D24697816
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp857, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C700FC00E900E200E400E000E500E700EA00EB00E800EF00EE013100C400C5..00C900E600C600F400F600F200FB00F9013000D600DC00F800A300D8015E015F..00E100ED00F300FA00F100D1011E011F00BF00AE00AC00BD00BC00A100AB00BB..2591259225932502252400C100C200C000A9256325512557255D00A200A52510..25142534252C251C2500253C00E300C3255A25542569256625602550256C00A4..00BA00AA00CA00CB00C8000000CD00CE00CF2518250C2588258400A600CC2580..00D300DF00D400D200F500
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1110
                                                                                                                                                                                                            Entropy (8bit):3.506813480871637
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CMHVBUlJvRj7SOVbusZhAMiZyi77qij4Axlt49Y18wDyV8mK:VMlBVnrAMiwMm/g+9Y1LmK
                                                                                                                                                                                                            MD5:C416471B57FB894DC45D30C31B4BD2E2
                                                                                                                                                                                                            SHA1:BA378F8122280992AE51245A06814D8155564220
                                                                                                                                                                                                            SHA-256:804EFA345C5BBBAD2449C318A7A3F5B31F4234712AAD23DC49B3FB5AA33B7A57
                                                                                                                                                                                                            SHA-512:E7CDE706CFE573525C2DE319AD5783AE9D97C4F6D28B14A77A729F281540B0DAFAD4C14879EF76473BFDEBC38499C65CA228470983F2D1BC31938A91A2486522
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp860, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C700FC00E900E200E300E000C100E700EA00CA00E800CD00D400EC00C300C2..00C900C000C800F400F500F200DA00F900CC00D500DC00A200A300D920A700D3..00E100ED00F300FA00F100D100AA00BA00BF00D200AC00BD00BC00A100AB00BB..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..03B100DF039303C003A303
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1110
                                                                                                                                                                                                            Entropy (8bit):3.5174672833207183
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:ClHVBUlJvRj7SOVbusZhAMiZyi77qZpORVPnA2Gm18wDyV8mK:8MlBVnrAMiwMmiVPAA1LmK
                                                                                                                                                                                                            MD5:4997979FD1692063E2B9AA9870E0BE4C
                                                                                                                                                                                                            SHA1:919012354B99BBEF4C85517E89A2C9CD340FCE49
                                                                                                                                                                                                            SHA-256:4B7E76AEB75289FACA76434EA6E9874E9504AD2BC3D8D47550EADBCC8294857E
                                                                                                                                                                                                            SHA-512:C122A1AE2DE79CB97E5989535B7478A76D905CDE60B01F80F5B84EDB9DF08BE6829E1811AF19608971DA048B8DA24F40DE0217A8054AC612EC2D8B3560500FBE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp861, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C700FC00E900E200E400E000E500E700EA00EB00E800D000F000DE00C400C5..00C900E600C600F400F600FE00FB00DD00FD00D600DC00F800A300D820A70192..00E100ED00F300FA00C100CD00D300DA00BF231000AC00BD00BC00A100AB00BB..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..03B100DF039303C003A303
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1110
                                                                                                                                                                                                            Entropy (8bit):3.5573268031592717
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CdMHVBUlJvRj7SOVbusZhAMiZyi77q36AqE18wDyV8mK:iMMlBVnrAMiwMmq3E1LmK
                                                                                                                                                                                                            MD5:9B4D1B95B20BD67555517DCC3007B22A
                                                                                                                                                                                                            SHA1:2C0D6121DB49CDAB6FBAA81398BE2E44BE4E1110
                                                                                                                                                                                                            SHA-256:6C15CB256B1C22170292589C6F589E64E164EB36EC7E84F0BD48149BABB7C5FC
                                                                                                                                                                                                            SHA-512:34C3E401364D579E8AC7A4E1F1F7A29A84C62E1D5146D7664832639EA3997227DC4BAF1B64DC605E6574D680E61B55D0C69C329E35B1BEC41501FC68C5B634B7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp862, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..05D005D105D205D305D405D505D605D705D805D905DA05DB05DC05DD05DE05DF..05E005E105E205E305E405E505E605E705E805E905EA00A200A300A520A70192..00E100ED00F300FA00F100D100AA00BA00BF231000AC00BD00BC00A100AB00BB..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..03B100DF039303C003A303
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1110
                                                                                                                                                                                                            Entropy (8bit):3.518080906819747
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CXHVBUlJvRj7SOVbusZhAMiZyi77qwGuXVFq5EC18wDyV8mK:eMlBVnrAMiwMmw3VFu1LmK
                                                                                                                                                                                                            MD5:C93CCDF65F7F349F22855745660F02AE
                                                                                                                                                                                                            SHA1:604888B1FB3C57DF47277CDD1153597BA89E8C36
                                                                                                                                                                                                            SHA-256:232D6FE34D7151920232EAAE9C515F36400AB64136DCC5B802D6245AC6F5D56B
                                                                                                                                                                                                            SHA-512:D5B65AE7353F694A37AF29177BF1A95477918FC5A002C2FE199624BD5B391698807BAECF54225BC40F62B3CA7912C7066A4AAF01B9E3E399133831CAA342BF4F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp863, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C700FC00E900E200C200E000B600E700EA00EB00E800EF00EE201700C000A7..00C900C800CA00F400CB00CF00FB00F900A400D400DC00A200A300D900DB0192..00A600B400F300FA00A800B800B300AF00CE231000AC00BD00BC00BE00AB00BB..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..03B100DF039303C003A303
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1110
                                                                                                                                                                                                            Entropy (8bit):3.72017408907567
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CwHVBUlJvRj7YOVbusZhAMiZyi77qcHj92OibcDQAyUjSG:5MlrVnrAMiwMmSsNcDQvcSG
                                                                                                                                                                                                            MD5:146E0D1779D50E070E0EF875E8374DF8
                                                                                                                                                                                                            SHA1:B51E5598712598BC387DD79AE80BD879F139140D
                                                                                                                                                                                                            SHA-256:81BEBFD9A61E9F17495763B68D57742FAB2A1A43871015699A2C8E5FDED4EC19
                                                                                                                                                                                                            SHA-512:1F0DAD8E77712C5A018894332BE72FF5C546C92F481421CCB8553AD6F1E9A18617765C8CEE4187265CCCB1AB073E221289D34C9AB1F0501231D52C81FC1C932B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp864, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..00200021002200230024066A0026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00B000B72219221A259225002502253C2524252C251C25342510250C25142518..03B2221E03C600B100BD00BC224800AB00BBFEF7FEF8009B009CFEFBFEFC009F..00A000ADFE8200A300A4FE8400000000FE8EFE8FFE95FE99060CFE9DFEA1FEA5..0660066106620663066406650666066706680669FED1061BFEB1FEB5FEB9061F..00A2FE80FE81FE83FE85FECAFE8BFE8DFE91FE93FE97FE9BFE9FFEA3FEA7FEA9..FEABFEADFEAFFEB3FEB7FEBBFEBFFEC1FEC5FECBFECF00A600AC00F700D7FEC9..0640FED3FED7FEDBFEDFFE
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1110
                                                                                                                                                                                                            Entropy (8bit):3.5193842128126676
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CsKHVBUlJvRj7SOVbusZhAMiZyi77qZpuHVBnAFj18wDyV8mK:gMlBVnrAMiwMm+VRAFj1LmK
                                                                                                                                                                                                            MD5:150B2E00B3F84F8075F3653ED7A4C8E0
                                                                                                                                                                                                            SHA1:7131DC656EFE1F2277B19DA72F0EEB46B4EC54A0
                                                                                                                                                                                                            SHA-256:ADA1A52064EE93EBE6F8A5D101D01F8776038E12F21A5CA1C006EE833577C705
                                                                                                                                                                                                            SHA-512:AC56EEB0220826BF8FF6CA52768DB63961AAC46095A2F3EEBA11B5973CC92AF52DFBBE9E85A0DD04CAB8998212FA2599EDD83BAAA7FB2D394E330FF2F7C015DB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp865, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..00C700FC00E900E200E400E000E500E700EA00EB00E800EF00EE00EC00C400C5..00C900E600C600F400F600F200FB00F900FF00D600DC00F800A300D820A70192..00E100ED00F300FA00F100D100AA00BA00BF231000AC00BD00BC00A100AB00A4..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..03B100DF039303C003A303
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1110
                                                                                                                                                                                                            Entropy (8bit):3.5038992968715266
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CCHVBUlJvRj7SOVbusZhAMiZyi77qb+SAJlz9aRme3cB18wDyVNZkR:bMlBVnrAMiwMm8YnsB1wZy
                                                                                                                                                                                                            MD5:FC33B5F773E87696A69E8798446E9772
                                                                                                                                                                                                            SHA1:4FC5589C1DD88BB8171758BC173A63B3A5687AE5
                                                                                                                                                                                                            SHA-256:32A45DEBA933C7ED99141535087A4C99BA79802175E3F762ACA6EB941157F85A
                                                                                                                                                                                                            SHA-512:332D2FEC532192F58F792441E61D675A8692C36BECF768D07F64B8C31561CC1A2DF402625A4719E758A9B59DE4228FFE9F94F067E7DC0D82F9DA2D6500E50304
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp866, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0410041104120413041404150416041704180419041A041B041C041D041E041F..0420042104220423042404250426042704280429042A042B042C042D042E042F..0430043104320433043404350436043704380439043A043B043C043D043E043F..259125922593250225242561256225562555256325512557255D255C255B2510..25142534252C251C2500253C255E255F255A25542569256625602550256C2567..2568256425652559255825522553256B256A2518250C25882584258C25902580..0440044104420443044404
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1110
                                                                                                                                                                                                            Entropy (8bit):3.5261138894265507
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CtHVBUlJvRj7SOVbusZhAMiZyi77qii+lh2o5+hdVMQFhWgCDrKE:EMlBVnrAMiwMmXY2o5+hdVMQFhWf3f
                                                                                                                                                                                                            MD5:4A2C66AA630D4AE2BF1E7546DCE2DAE5
                                                                                                                                                                                                            SHA1:FABB672957D21CA2B4E0EACA5FCE6093BAACF77A
                                                                                                                                                                                                            SHA-256:AFE6ED6EB5D07C45B6B928A48BC5EF57EFCF61602D36FF9FBDE4A8EA3FA6DF75
                                                                                                                                                                                                            SHA-512:A548002EB7AF8735DBBBCC9883B44B326F261C02A3C7CE65C373755DD92212A66740112EAE0FC556CAD5B86911709C6DF12167DC5B6AD1E01C6F1EB5AB16DB37
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp869, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850386008700B700AC00A620182019038820150389..038A03AA038C00930094038E03AB00A9038F00B200B303AC00A303AD03AE03AF..03CA039003CC03CD039103920393039403950396039700BD0398039900AB00BB..25912592259325022524039A039B039C039D256325512557255D039E039F2510..25142534252C251C2500253C03A003A1255A25542569256625602550256C03A3..03A403A503A603A703A803A903B103B203B32518250C2588258403B403B52580..03B603B703B803B903BA03
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1110
                                                                                                                                                                                                            Entropy (8bit):3.33737382140564
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CSyHVBUlJvRj7SOVbusZhAMiZyi77qVQEHmEU4AyqU+TWwdd:CMlBVnrAMiwMmWr4AyqUSd
                                                                                                                                                                                                            MD5:FC8C876B4738236FC71A1AF96E4566D0
                                                                                                                                                                                                            SHA1:DDFDC3F62D99A6BD705CF0719B50F66449C8808A
                                                                                                                                                                                                            SHA-256:4F05F31CA026BBFEEEE49ED86504CB060784137A9CFAE0E5954D276E837AB5DE
                                                                                                                                                                                                            SHA-512:5BF58A810E029840825FFF3318E90415E6F2B7E46032FD428B4971923D41A64C127A6F438E4894E80EC9604CD34F1D47B4F9A02ABAB3E7D6351611811DC1F2B9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp874, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC008100820083008420260086008700880089008A008B008C008D008E008F..009020182019201C201D20222013201400980099009A009B009C009D009E009F..00A00E010E020E030E040E050E060E070E080E090E0A0E0B0E0C0E0D0E0E0E0F..0E100E110E120E130E140E150E160E170E180E190E1A0E1B0E1C0E1D0E1E0E1F..0E200E210E220E230E240E250E260E270E280E290E2A0E2B0E2C0E2D0E2E0E2F..0E300E310E320E330E340E350E360E370E380E390E3A00000000000000000E3F..0E400E410E420E430E440E
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):49008
                                                                                                                                                                                                            Entropy (8bit):3.5144574650895364
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:R/RPrUHiJrKWkyY/W2wHiwWnwWOORY+gutSY83+JRS:RVUidzJCurDGSYvW
                                                                                                                                                                                                            MD5:EF4508C84A025095B183E6BAD67B1ECD
                                                                                                                                                                                                            SHA1:D12D5381D50D578AA8687671DC542C462A7F490D
                                                                                                                                                                                                            SHA-256:6D1B512110BEAF2CD1296AC878F51D567848AB4A1CED4F18C72806BB136B3D23
                                                                                                                                                                                                            SHA-512:E695E7E6F4A11D5E8D62982E26B69B87DB2F1F3D6B6DCCD5F1DF51879F5C4533265CBD7B785E1F2652D8CA3FC913D4F862E7575F67C636314A6E6956FD96E023
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp932, multi-byte..M..003F 0 46..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080000000000000000000850086000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000FF61FF62FF63FF64FF65FF66FF67FF68FF69FF6AFF6BFF6CFF6DFF6EFF6F..FF70FF71FF72FF73FF74FF75FF76FF77FF78FF79FF7AFF7BFF7CFF7DFF7EFF7F..FF80FF81FF82FF83FF84FF85FF86FF87FF88FF89FF8AFF8BFF8CFF8DFF8EFF8F..FF90FF91FF92FF93FF94FF95FF96FF97FF98FF99FF9AFF9BFF9CFF9DFF9EFF9F..0000000000000000000000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):134671
                                                                                                                                                                                                            Entropy (8bit):3.5217328918779645
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:1536:+CwDua7D90Jz1aDJmnMfEGniOQdH6prJs3inqlW6/t9Qwf+zCt5:j1WVRpe3rpt9hf+Gt5
                                                                                                                                                                                                            MD5:CF9CFD6329A4FB6C402052B9417DAC3A
                                                                                                                                                                                                            SHA1:75CE13FE1E5898D47B67F951C0C228851F1CC04D
                                                                                                                                                                                                            SHA-256:B6EC2BE0504CA62B9D1B6857F6BAA13FFAC5A567D4432F4EAB98ADC830F5D9C3
                                                                                                                                                                                                            SHA-512:7E19607EEA5342ECFE92D56DAAE82827DE147AE5AFDA8E9D67FD0970F528902CDE20A8A07CF2F341B926E59BB4FF792872976F1C7C5CD351959A71A8B6A1924A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp936, multi-byte..M..003F 0 127..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..20AC000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):132551
                                                                                                                                                                                                            Entropy (8bit):3.100976362851161
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:1536:2UO8ecy5KnSMsDlOmNpkQ4oQHnTApv+ngLbiyEY:2U/etc/sBRZp//r
                                                                                                                                                                                                            MD5:03E19A4DE3490A7DC50D04EC1F558835
                                                                                                                                                                                                            SHA1:9DFECAE08C98109EAA358F5920AED647888F722B
                                                                                                                                                                                                            SHA-256:477F8B79B67F4A22C963EE65B9B387DBD8E4B8F62D800B0A51D2276580C6ADBB
                                                                                                                                                                                                            SHA-512:7D6AD30AF75A3AA6332A860C6ABF87BF725EB6B4AF3B37699043A10EF3235471C63D0ECB4D437D5AD9438DF5DA646EB55117A9BB8B55EF6868F71E49035C18B7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp949, multi-byte..M..003F 0 125..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):93330
                                                                                                                                                                                                            Entropy (8bit):3.319807723045599
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:aAHU3LIkZlmXrd/uQ0ao98ggKSTEvZPHb6qRL5NpiadDp0ZBFR6YR/fW:aVduBGf9PgFMT6q95GDRBfW
                                                                                                                                                                                                            MD5:1D84B025DAB127F2073947D764D307B6
                                                                                                                                                                                                            SHA1:4E3D3CBD96D084836F1FE6F2AA497E3FAA463B9B
                                                                                                                                                                                                            SHA-256:F80E05533D1A1494C32F9412E9AD2D9C11FAF9AE0668A6F9D1FA5CEEDC6870E2
                                                                                                                                                                                                            SHA-512:188D649F9717F20524AFF47F85C3B23AEC3E7825BF54975285D06C17587D581DC24A3F6A7CAB1703DE7AD5521FE2FE2572DE627A81E6A48049A47BB219ED4AF8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: cp950, multi-byte..M..003F 0 88..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1113
                                                                                                                                                                                                            Entropy (8bit):3.7780987266961663
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:vJMHkUlJvRjmf9RCsUBOdXsCbbNviANpk3m1XFAoE4xSF5HrBPkdn:vKvlA9RCs6CXrViAN51XFA9eSvdPKn
                                                                                                                                                                                                            MD5:90FE0C57BBC6C2D8A3324DEB7FD45F3D
                                                                                                                                                                                                            SHA1:06B95BE43E4C859A0F1B01384EDD26500C6C1F9E
                                                                                                                                                                                                            SHA-256:EB9B262E4D179268E6F017C0D4EF0E7034E31A5B4893595D150640CA1F6A1C45
                                                                                                                                                                                                            SHA-512:6A5E67D9F3EC6046C42793E1437B8A6E50EBD72D8EC67FEFEB6DAD6FAB6A5B5C74F939363587D5A6529E217AF54FB8A9CF0F768E114DD931C57887451CACE56E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: dingbats, single-byte..S..003F 1 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..00202701270227032704260E2706270727082709261B261E270C270D270E270F..2710271127122713271427152716271727182719271A271B271C271D271E271F..2720272127222723272427252726272726052729272A272B272C272D272E272F..2730273127322733273427352736273727382739273A273B273C273D273E273F..2740274127422743274427452746274727482749274A274B25CF274D25A0274F..27502751275225B225BC25C6275625D727582759275A275B275C275D275E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000276127622763276427652766276726632666266526602460246124622463..2464246524662467246824692776277727782779277A277B277C277D277E277F..2780278127822783278427852786278727882789278A278B278C278D278E278F..2790279127922793279421922194219527982799279A279B279C279D279E279F..27A027A127A227A327A
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1073
                                                                                                                                                                                                            Entropy (8bit):3.0039861897954805
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:XXBcIhJZDgEoQkNCGz0Jyh9lZk3Vmd2QhZLXPiALV3d:dTcNCJEhfZk3Vzox/iqVN
                                                                                                                                                                                                            MD5:F7B3771D43BDE6AFF897683BED2FE6AD
                                                                                                                                                                                                            SHA1:E70C2C0902413536CB6163752D70F3AE4AF6A967
                                                                                                                                                                                                            SHA-256:165BE658AB7D61FFC3DF1E2F1438C2F9FCEE6808A756316302157F44E6D3ACD7
                                                                                                                                                                                                            SHA-512:F87DC718EB2DD95237B144FDA090BB636121B9479E492AC94E4F7EBDD88171F070B9E9F6165BDA7B7E2BA2A3E6188B1108D8F91AA5F142CCCFDAD317628DD941
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:S..006F 0 1..00..0000000100020003008500090086007F0087008D008E000B000C000D000E000F..0010001100120013008F000A0008009700180019009C009D001C001D001E001F..0080008100820083008400920017001B00880089008A008B008C000500060007..0090009100160093009400950096000400980099009A009B00140015009E001A..002000A000E200E400E000E100E300E500E700F10060002E003C0028002B007C..002600E900EA00EB00E800ED00EE00EF00EC00DF00210024002A0029003B009F..002D002F00C200C400C000C100C300C500C700D1005E002C0025005F003E003F..00F800C900CA00CB00C800CD00CE00CF00CC00A8003A002300400027003D0022..00D800610062006300640065006600670068006900AB00BB00F000FD00FE00B1..00B0006A006B006C006D006E006F00700071007200AA00BA00E600B800C600A4..00B500AF0073007400750076007700780079007A00A100BF00D000DD00DE00AE..00A200A300A500B700A900A700B600BC00BD00BE00AC005B005C005D00B400D7..00F900410042004300440045004600470048004900AD00F400F600F200F300F5..00A6004A004B004C004D004E004F00500051005200B900FB00FC00DB00FA00FF..00D900F70053005400550056005700580059005A00B200D400D600D200D
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):86971
                                                                                                                                                                                                            Entropy (8bit):2.3925661740847697
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:UHivP+bFFScXEBFhHeUrUFESCeYjN7GC0nYX:I7FFX2nHeUr8ESCDlX
                                                                                                                                                                                                            MD5:C5AA0D11439E0F7682DAE39445F5DAB4
                                                                                                                                                                                                            SHA1:73A6D55B894E89A7D4CB1CD3CCFF82665C303D5C
                                                                                                                                                                                                            SHA-256:1700AF47DC012A48CEC89CF1DFAE6D1D0D2F40ED731EFF6CA55296A055A11C00
                                                                                                                                                                                                            SHA-512:EEE6058BD214C59BCC11E6DE7265DA2721C119CC9261CFD755A98E270FF74D2D73E3E711AA01A0E3414C46D82E291EF0DF2AD6C65CA477C888426D5A1D2A3BC5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: euc-cn, multi-byte..M..003F 0 82..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):83890
                                                                                                                                                                                                            Entropy (8bit):2.350315390677456
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:2GhX8nuQ635vlHptHzh0abNQPQA0OMS2HhFV3:2GikvRpMuNQ4P73
                                                                                                                                                                                                            MD5:F2DE0AE66A4E5DD51CC64B08D3709AAB
                                                                                                                                                                                                            SHA1:97558A51A6DD6C56FC7A42A4204141A5639021FD
                                                                                                                                                                                                            SHA-256:A3C916BA16BCAC9FAA5A1CCC62ACA61452D581CD8BA3EE07EC39122C697274C9
                                                                                                                                                                                                            SHA-512:0EAA90100527FF150D2653D7BB57647D69E592BE53B714DDD867114CFCC71E3A76882772F4FAECE040DF09FA8971D1C22DECC497E589B4CA827A6890497A48D9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: euc-jp, multi-byte..M..003F 0 79..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D0000008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):95451
                                                                                                                                                                                                            Entropy (8bit):2.4080588863614136
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:4/vO7UlClqAd8XfpUqv+mCoKRuLbtMjnIxz0DY:4nO4N9fpv+ngLbiyEY
                                                                                                                                                                                                            MD5:103843B3A57168BD574F6CACC550D439
                                                                                                                                                                                                            SHA1:982652EA2B0DCFBB55970E019A4EDFBFCFAF9C24
                                                                                                                                                                                                            SHA-256:5448643398685456A11CBB93AF2321F70B8659E2FFF3CCC534B4D53BD2F38C89
                                                                                                                                                                                                            SHA-512:27A8DE6F97DB4A96E5D0132692A32A99DAB8A6C98973A0C4E50A219F2D2F364E63D657E5E8478B2706CA33C45C376F55B5BFCC9459E06AEA88BFCD4F0E32525C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: euc-kr, multi-byte..M..003F 0 90..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):88033
                                                                                                                                                                                                            Entropy (8bit):2.3790651802316996
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:o4Is/C+0IwpRK1CkinIKUyNiNBzxOC4T/:LIsR0/RKckiIgNiDtOxT
                                                                                                                                                                                                            MD5:1A8E55DEA98B6D5EAC731ED233D3AD7C
                                                                                                                                                                                                            SHA1:1335FC0FC2AAE7E7F5EC42AC17A4168368B4A64D
                                                                                                                                                                                                            SHA-256:B4894AEDD2D5B5AE54B6D2840F7C89A88E9308EFD288F179E65936E172EF4B0D
                                                                                                                                                                                                            SHA-512:9DDCE366BA1196EB9FB913ACFDE8516BC9BB8D51894866D2E7E8CB313DC4D6C6D33C5A9E78142E83594DC423D10DA6F8DE211E69844B939198BC7DB9AED808F0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: gb12345, double-byte..D..233F 0 83..21..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000030003001300230FB02C902C700A8300330052015FF5E2225202620182019..201C201D3014301530083009300A300B300C300D300E300F3016301730103011..00B100D700F72236222722282211220F222A222922082237221A22A522252220..23122299222B222E2261224C2248223D221D2260226E226F22642265221E2235..22342642264000B0203220332103FF0400A4FFE0FFE1203000A7211626062605..25CB25CF25CE25C725C625A125A025B325B2203B219221902191219330130000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1111
                                                                                                                                                                                                            Entropy (8bit):3.270324851474969
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:qrmHVBUlJvRj76OVbusZhAMiZyi77qN8VmKfkiJt0RMFS:qSMlZVnrAMiwMmNPYPFS
                                                                                                                                                                                                            MD5:D06664ACAA478BDEB42B63941109A4E3
                                                                                                                                                                                                            SHA1:4A6196FCC1BDE988C1A23EAA69745A9979F1AEFF
                                                                                                                                                                                                            SHA-256:ACD50951F81566C8D823670F9957B2479102EB5AE4CF558453E1D8436A9E31FF
                                                                                                                                                                                                            SHA-512:CB51A36B851FFDB5C6F9B9D0333EEA6A14CEF3796E0A60530198C16999D64E638047E873333630360299C9126F79CEDDA2D9F169028CED1FC04B1D3C55FFFC5B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: gb1988, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..002000210022002300A500250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D203E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000FF61FF62FF63FF64FF65FF66FF67FF68FF69FF6AFF6BFF6CFF6DFF6EFF6F..FF70FF71FF72FF73FF74FF75FF76FF77FF78FF79FF7AFF7BFF7CFF7DFF7EFF7F..FF80FF81FF82FF83FF84FF85FF86FF87FF88FF89FF8AFF8BFF8CFF8DFF8EFF8F..FF90FF91FF92FF93FF94FF95FF96FF97FF98FF99FF9AFF9BFF9CFF9DFF9EFF9F..000000000000000000000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):85912
                                                                                                                                                                                                            Entropy (8bit):2.3945751552930936
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:D47/S+i8vdx3Tz+hpHcBrQqKtrebjMIGCx8jE:0c873T6DHcBrbKtrVlE
                                                                                                                                                                                                            MD5:9357E05C74D6A124825F46A42B280C14
                                                                                                                                                                                                            SHA1:E5106ABE12D991AFE514F41E3B9E239202A4ADFE
                                                                                                                                                                                                            SHA-256:C445E4C9F676AE997D2DDA2BBC107B746F3547D85F39479951C56F46275EE355
                                                                                                                                                                                                            SHA-512:B2187D70A92FB38572BA46F3C3443233BEED1A4ABBFBA1B860F4BBAE6B3D8C16B8C9F52A20DAA12B2B8B40972E52F816860427B743530177E4CF0D8BA34EF381
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: gb2312, double-byte..D..233F 0 81..21..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000030003001300230FB02C902C700A8300330052015FF5E2225202620182019..201C201D3014301530083009300A300B300C300D300E300F3016301730103011..00B100D700F72236222722282211220F222A222922082237221A22A522252220..23122299222B222E2261224C2248223D221D2260226E226F22642265221E2235..22342642264000B0203220332103FF0400A4FFE0FFE1203000A7211626062605..25CB25CF25CE25C725C625A125A025B325B2203B219221902191219330130000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..00000000000000000000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):86971
                                                                                                                                                                                                            Entropy (8bit):2.3925661740847697
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:UHivP+bFFScXEBFhHeUrUFESCeYjN7GC0nYX:I7FFX2nHeUr8ESCDlX
                                                                                                                                                                                                            MD5:C5AA0D11439E0F7682DAE39445F5DAB4
                                                                                                                                                                                                            SHA1:73A6D55B894E89A7D4CB1CD3CCFF82665C303D5C
                                                                                                                                                                                                            SHA-256:1700AF47DC012A48CEC89CF1DFAE6D1D0D2F40ED731EFF6CA55296A055A11C00
                                                                                                                                                                                                            SHA-512:EEE6058BD214C59BCC11E6DE7265DA2721C119CC9261CFD755A98E270FF74D2D73E3E711AA01A0E3414C46D82E291EF0DF2AD6C65CA477C888426D5A1D2A3BC5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: euc-cn, multi-byte..M..003F 0 82..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E007F..0080008100820083008400850086008700880089008A008B008C008D008E008F..0090009100920093009400950096009700980099009A009B009C009D009E009F..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..000000000000000000000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):204
                                                                                                                                                                                                            Entropy (8bit):4.949409835601965
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SOd5MNXVSVLqRIBXS4ovLE9sDXMVyXK9ow1Deq9Ts5dRPMSXcRA0kcR4X9cL+TXI:SVNFS0oyisLMsXK9okTw/BDSVKNw
                                                                                                                                                                                                            MD5:D3AC33390D31705FA4486D0B455247DF
                                                                                                                                                                                                            SHA1:2EE8613DC04A6FA84AB38FD5F3A2AA3FE330625B
                                                                                                                                                                                                            SHA-256:98074C85650A420A095ADA9138DA3A8A0AA4027BE47EA1E97A596F319EB084E9
                                                                                                                                                                                                            SHA-512:CB265B753C84968E2D1D6E706906DA9A7BB796D08F626290BCCA8F089771AFD176A9DC912773E8BA390D2AEC08592AD535C7D254E1DF92CF04848601481D4EFE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: iso2022-jp, escape-driven..E..name..iso2022-jp..init..{}..final..{}..ascii..\x1b(B..jis0201..\x1b(J..jis0208..\x1b$B..jis0208..\x1b$@..jis0212..\x1b$(D..gb2312..\x1b$A..ksc5601..\x1b$(C..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):122
                                                                                                                                                                                                            Entropy (8bit):4.978693690727393
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SOd5MNXVTEXIBXS4ovLE9sDXNvdwUHEQwqc6XWxVUNOov:SVNFSoyisL/Zzc6mYNHv
                                                                                                                                                                                                            MD5:057CB0AA9872AC3910184F67AC6621BC
                                                                                                                                                                                                            SHA1:BBA47F9D76B6690C282724C3423BD94E2C320A04
                                                                                                                                                                                                            SHA-256:234811FC8B0F8FF2B847D9CC3982F1699DF1D21A43C74DCE45BA855D22520007
                                                                                                                                                                                                            SHA-512:019F187D2D16FB51BF627ACB7E67778857E56D4C160E0E5ACA6ABC05EC5FDB624CE2715CB9E0DAD73BFF9D697982BE0D539BC55BCCD368FC7C8EE0FFC04E9F61
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: iso2022-kr, escape-driven..E..name..iso2022-kr..init..\x1b$)C..final..{}..iso8859-1.\x0f..ksc5601..\x0e..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):240
                                                                                                                                                                                                            Entropy (8bit):4.95909788984399
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SVNFUXoyisLNcs9ozc6W4Twk0sRBDSVKN6tWIHRy:oUYcLNcTzczbwRYRy
                                                                                                                                                                                                            MD5:BB186D4BE3FA67DD3E2DEE82DD8BD628
                                                                                                                                                                                                            SHA1:93CE8627038780CFFF8C06E746DD5FB2B041115C
                                                                                                                                                                                                            SHA-256:741B4C842557EED2952936204D0AE9C35FA3A0F02F826D94C50C46976291797C
                                                                                                                                                                                                            SHA-512:4921E7AA3DB8E33609603FE129B97275DFF80CFB06648D2068FA7950246C67B9B530B74827638F69F4DFB8F55CDD4AA952EA72EAEB6ABB527D52F20C6B46FB51
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: iso2022, escape-driven..E..name..iso2022..init..{}..final..{}..iso8859-1.\x1b(B..jis0201..\x1b(J..gb1988..\x1b(T..jis0208..\x1b$B..jis0208..\x1b$@..jis0212..\x1b$(D..gb2312..\x1b$A..ksc5601..\x1b$(C..jis0208..\x1b&@\x1b$B..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1112
                                                                                                                                                                                                            Entropy (8bit):3.0553142874336943
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:ZlHVBUlJvRj7SOVbusZhAMiZyi77qsDHmEU4AyqU+TWwdd:PMlBVnrAMiwMmss4AyqUSd
                                                                                                                                                                                                            MD5:467A67DE6809B796B914F5BFF98EF46D
                                                                                                                                                                                                            SHA1:C62418071A6C9CB0DCE3F67E130BFD2FB7AB0B58
                                                                                                                                                                                                            SHA-256:50B62381D6EDD4219F4292BFDC365954491B23360DE7C08033E7218A3D29C970
                                                                                                                                                                                                            SHA-512:BF98305AA7D759A087B9EABDC404714D8DC6B4F1BEED4ED0E1FFE646641E1AECA307673D64CF95FD09546D977B3409D6C04F56DCCA1D6332B0D9B6DD460B77A9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Encoding file: tis-620, single-byte..S..003F 0 1..00..0000000100020003000400050006000700080009000A000B000C000D000E000F..0010001100120013001400150016001700180019001A001B001C001D001E001F..0020002100220023002400250026002700280029002A002B002C002D002E002F..0030003100320033003400350036003700380039003A003B003C003D003E003F..0040004100420043004400450046004700480049004A004B004C004D004E004F..0050005100520053005400550056005700580059005A005B005C005D005E005F..0060006100620063006400650066006700680069006A006B006C006D006E006F..0070007100720073007400750076007700780079007A007B007C007D007E0000..0000000000000000000000000000000000000000000000000000000000000000..0000000000000000000000000000000000000000000000000000000000000000..00000E010E020E030E040E050E060E070E080E090E0A0E0B0E0C0E0D0E0E0E0F..0E100E110E120E130E140E150E160E170E180E190E1A0E1B0E1C0E1D0E1E0E1F..0E200E210E220E230E240E250E260E270E280E290E2A0E2B0E2C0E2D0E2E0E2F..0E300E310E320E330E340E350E360E370E380E390E3A00000000000000000E3F..0E400E410E420E430E44
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8235
                                                                                                                                                                                                            Entropy (8bit):4.855903177272536
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:Hf8PxPu7pUHBpqyzmY5rEk/fvs+AokFlTGHts1H/tsEGZPBtsLIVn++G:H6Pu7ELJTtyli8Ozz+L
                                                                                                                                                                                                            MD5:8609B624CD3EC63DD02DBF89455C3A9B
                                                                                                                                                                                                            SHA1:B3E1843E34C38AA668FFDDF435A1A65D55449CA0
                                                                                                                                                                                                            SHA-256:5123DB837EADF45712EA7D449BC40BFD3E8E16D3D71E7D0CE9A32F164973D767
                                                                                                                                                                                                            SHA-512:B20B75473F34209888F38EE570B8A96061760E88466DFC2EC55C814968DC7F67D92D255E8635188B60455B88F2D1D517747613AD0F366D60412D2D6ECE231B0E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# history.tcl --..#..# Implementation of the history command...#..# Copyright (c) 1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES...#.....# The tcl::history array holds the history list and some additional..# bookkeeping variables...#..# nextid.the index used for the next history list item...# keep..the max size of the history list..# oldest.the index of the oldest item in the history.....namespace eval ::tcl {.. variable history.. if {![info exists history]} {...array set history {... nextid.0... keep.20... oldest.-20...}.. }.... namespace ensemble create -command ::tcl::history -map {...add.::tcl::HistAdd...change.::tcl::HistChange...clear.::tcl::HistClear...event.::tcl::HistEvent...info.::tcl::HistInfo...keep.::tcl::HistKeep...nextid.::tcl::HistNextID...redo.::tcl::HistRedo.. }..}.....# history --..#..#.This is the main history command. See the
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):10066
                                                                                                                                                                                                            Entropy (8bit):4.806771544139381
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:kipkqA3KsZMAikGJ4kIWPa95KTBoF7dg/8YNkgQ4id:TkqWKsZ8kGJ4kIWPaDFzTd
                                                                                                                                                                                                            MD5:C2092F8CA2D761DFA8C461076D956374
                                                                                                                                                                                                            SHA1:90B4648B3BC81C30465B0BE83A5DB4127A1392FB
                                                                                                                                                                                                            SHA-256:8C474095A3ABA7DF5B488F3D35240D6DE729E57153980C2A898728B8C407A727
                                                                                                                                                                                                            SHA-512:09CE408886E2CEADDF70786A15D63AF9A930E70CAC4286AC9DDD2094C8EDCF97A2ADC2D3D2659B123F88719340D3B00D9F96E9BC7C8B55192735C290E7D24683
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# http.tcl..# Client-side HTTP for GET, POST, and HEAD commands...# These routines can be used in untrusted code that uses the Safesock..# security policy...# These procedures use a callback interface to avoid using vwait,..# which is not defined in the safe base...#..# See the http.n man page for documentation....package provide http 1.0....array set http {.. -accept */*.. -proxyhost {}.. -proxyport {}.. -useragent {Tcl http client package 1.0}.. -proxyfilter httpProxyRequired..}..proc http_config {args} {.. global http.. set options [lsort [array names http -*]].. set usage [join $options ", "].. if {[llength $args] == 0} {...set result {}...foreach name $options {... lappend result $name $http($name)...}...return $result.. }.. regsub -all -- - $options {} options.. set pat ^-([join $options |])$.. if {[llength $args] == 1} {...set flag [lindex $args 0]...if {[regexp -- $pat $flag]} {... return $http($flag)...} else {... return -code er
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):746
                                                                                                                                                                                                            Entropy (8bit):4.711041943572035
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:jHx5XRsLzhjJS42wbGlTULuUAZb3KykszLl7+HkuRz20JSv6C3l5kMn:bHRsRJS42wbGlTUcZ+yk2Lli1z2jxXkM
                                                                                                                                                                                                            MD5:A387908E2FE9D84704C2E47A7F6E9BC5
                                                                                                                                                                                                            SHA1:F3C08B3540033A54A59CB3B207E351303C9E29C6
                                                                                                                                                                                                            SHA-256:77265723959C092897C2449C5B7768CA72D0EFCD8C505BDDBB7A84F6AA401339
                                                                                                                                                                                                            SHA-512:7AC804D23E72E40E7B5532332B4A8D8446C6447BB79B4FE32402B13836079D348998EA0659802AB0065896D4F3C06F5866C6B0D90BF448F53E803D8C243BBC63
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Tcl package index file, version 1.0..# This file is generated by the "pkg_mkIndex" command..# and sourced either when an application starts up or..# by a "package unknown" script. It invokes the..# "package ifneeded" command to set up package-related..# information so that packages will be loaded automatically..# in response to "package require" commands. When this..# script is sourced, the variable $dir must contain the..# full path name of this file's directory.....package ifneeded http 1.0 [list tclPkgSetup $dir http 1.0 {{http.tcl source {httpCopyDone httpCopyStart httpEof httpEvent httpFinish httpMapReply httpProxyRequired http_code http_config http_data http_formatQuery http_get http_reset http_size http_status http_wait}}}]..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Tcl script, ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):25633
                                                                                                                                                                                                            Entropy (8bit):4.885492991636381
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:cXugPHudKlExBG+Xg3Qonlm6ofRRECLSQDjr5vkhzx/i:hgGdKli4eonlm6offLzehNi
                                                                                                                                                                                                            MD5:FE92C81BB4ACDDA00761C695344D5F1E
                                                                                                                                                                                                            SHA1:A87E1516FBD1F9751EC590273925CBC5284B16BD
                                                                                                                                                                                                            SHA-256:7A103A85413988456C2AD615C879BBCB4D91435BCFBBE23393E0EB52B56AF6E2
                                                                                                                                                                                                            SHA-512:C983076E420614D12AB2A7342F6F74DD5DCDAD21C7C547F660E73B74B3BE487A560ABD73213DF3F58BE3D9DBD061A12D2956CA85A58D7B9D9E40D9FA6E6C25EB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# init.tcl --..#..# Default system startup file for Tcl-based applications. Defines..# "unknown" procedure and auto-load facilities...#..# Copyright (c) 1991-1993 The Regents of the University of California...# Copyright (c) 1994-1996 Sun Microsystems, Inc...# Copyright (c) 1998-1999 Scriptics Corporation...# Copyright (c) 2004 Kevin B. Kenny. All rights reserved...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# This test intentionally written in pre-7.5 Tcl..if {[info commands package] == ""} {.. error "version mismatch: library\nscripts expect Tcl version 7.5b1 or later but the loaded version is\nonly [info patchlevel]"..}..package require -exact Tcl 8.6.13....# Compute the auto path to use in this interpreter...# The values on the path come from several locations:..#..# The environment variable TCLLIBPATH..#..# tcl_library, which is the directory containing this init.tcl script...# [t
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1038
                                                                                                                                                                                                            Entropy (8bit):4.10054496357204
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:4EnLB383Hcm0hH9BncmtR7tK9dUVxMmALfpKIdzVJLd3xfjTuLM+vzkHWZ6tH9H0:4aR838HH9ekCkMmEfpK2xx2jiWZ0VbY
                                                                                                                                                                                                            MD5:DA8BA1C3041998F5644382A329C3C867
                                                                                                                                                                                                            SHA1:CA0BD787A51AD9EDC02EDD679EEEEB3A2932E189
                                                                                                                                                                                                            SHA-256:A1EACA556BC0CFBD219376287C72D9DBBFAB76ECF9BF204FD02D40D341BAF7DA
                                                                                                                                                                                                            SHA-512:4F086396405FDFE7FBDA7614D143DE9DB41F75BDBD3DB18B1EE9517C3DCCED238DD240B4B64829FD04E50F602DBF371D42A321D04C4C48E4B8B2A067CA1BAF2E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset af DAYS_OF_WEEK_ABBREV [list \.. "So"\.. "Ma"\.. "Di"\.. "Wo"\.. "Do"\.. "Vr"\.. "Sa"].. ::msgcat::mcset af DAYS_OF_WEEK_FULL [list \.. "Sondag"\.. "Maandag"\.. "Dinsdag"\.. "Woensdag"\.. "Donderdag"\.. "Vrydag"\.. "Saterdag"].. ::msgcat::mcset af MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "Mar"\.. "Apr"\.. "Mei"\.. "Jun"\.. "Jul"\.. "Aug"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Des"\.. ""].. ::msgcat::mcset af MONTHS_FULL [list \.. "Januarie"\.. "Februarie"\.. "Maart"\.. "April"\.. "Mei"\.. "Junie"\.. "Julie"\.. "Augustus"\.. "September"\.. "Oktober"\.. "November"\.. "Desember"\.. ""].. ::msgcat::mcset af AM "VM
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.925537696653838
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xouFygMouFqF3v6ay/5ouFy9+3vR6HyFvn:4EnLB383RAgeYF3v6ay/RAI3voSVn
                                                                                                                                                                                                            MD5:1B9DCD1C6FCDDC95AE820EA8DA5E15B8
                                                                                                                                                                                                            SHA1:E8160353FD415BAB9FD5ACCA14E087C5E6AE836E
                                                                                                                                                                                                            SHA-256:1548988458BBF0DFCCC23B7487CEC0E9C64E4CC8E045723E50BEC37C454A8C81
                                                                                                                                                                                                            SHA-512:532AF060B95AED5E381B161BE56BC88D91A8F3DF2ACFD835491991F99FE752ADB4A3F93AB6D4E68F7042C28A3C1DD87A6312DFD9FFFAFD6ECE3F1B76837C5B7F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset af_ZA DATE_FORMAT "%d %B %Y".. ::msgcat::mcset af_ZA TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset af_ZA DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2018
                                                                                                                                                                                                            Entropy (8bit):4.477377447232708
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83gr/fsS/Sm8p4M/n1KsPktE30AiJcAxi9CEzdEvSCHvMSV:43UkiSm8p3nX0EzdCSCPV
                                                                                                                                                                                                            MD5:D264D01B46D96455715114CAEDF9F05E
                                                                                                                                                                                                            SHA1:A3F68A4C6E69433BD53E52B73041575F3B3AC3F2
                                                                                                                                                                                                            SHA-256:B69D0061A728D59F89FF8621312789CD9F540BF2E2ED297804D22F6278561D85
                                                                                                                                                                                                            SHA-512:A4163DAA6821B293EADD5D499E0641A8B7C93180C710D6B364AE8681A8FF6F35EC948C8DDBE960A8466AF1ACABC15B0D465A08B084617E8005D708459F7E74D3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ar DAYS_OF_WEEK_ABBREV [list \.. "\u062d"\.. "\u0646"\.. "\u062b"\.. "\u0631"\.. "\u062e"\.. "\u062c"\.. "\u0633"].. ::msgcat::mcset ar DAYS_OF_WEEK_FULL [list \.. "\u0627\u0644\u0623\u062d\u062f"\.. "\u0627\u0644\u0627\u062b\u0646\u064a\u0646"\.. "\u0627\u0644\u062b\u0644\u0627\u062b\u0627\u0621"\.. "\u0627\u0644\u0623\u0631\u0628\u0639\u0627\u0621"\.. "\u0627\u0644\u062e\u0645\u064a\u0633"\.. "\u0627\u0644\u062c\u0645\u0639\u0629"\.. "\u0627\u0644\u0633\u0628\u062a"].. ::msgcat::mcset ar MONTHS_ABBREV [list \.. "\u064a\u0646\u0627"\.. "\u0641\u0628\u0631"\.. "\u0645\u0627\u0631"\.. "\u0623\u0628\u0631"\.. "\u0645\u0627\u064a"\.. "\u064a\u0648\u0646"\.. "\u064a\u0648\u0644"\.. "\u0623\u063a\u0633"\.. "\u0633\u0628\u062a"\..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):265
                                                                                                                                                                                                            Entropy (8bit):4.872222510420193
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoKNvfcoKU3v6xyFjoKNo+3vfXM68vn:4EnLB3831vfD3v6g9F3vfc6+n
                                                                                                                                                                                                            MD5:430498B4AB1E77C86BC1311A49747581
                                                                                                                                                                                                            SHA1:684EAD965D9010C2A6E73DCACB2224FDE585F9FF
                                                                                                                                                                                                            SHA-256:2E04B96DA002519D28125918A22FF2BB9659A668A7BCAD34D85DDDECEC8DC0B4
                                                                                                                                                                                                            SHA-512:9F85A88A383DCFC54DAA6253D94C307A14B1CC91D5C97AF817B8122AF98025AB2430D0B2D656EBED09E78FB854D1F9CF99F3B791A6ECB7834112012739140126
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ar_IN DATE_FORMAT "%A %d %B %Y".. ::msgcat::mcset ar_IN TIME_FORMAT_12 "%I:%M:%S %z".. ::msgcat::mcset ar_IN DATE_TIME_FORMAT "%A %d %B %Y %I:%M:%S %z %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1851
                                                                                                                                                                                                            Entropy (8bit):4.08645484776227
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83sxS/Sm819+es/Ii/R91bpH0+U0c+es/Ii/R91bpH0+UO:43wiSm815MbJbHgMbJbp
                                                                                                                                                                                                            MD5:5C62D606F4F14BC8994B28F9622D70DD
                                                                                                                                                                                                            SHA1:E99F8CC5D330085545B05B69213E9D011D436990
                                                                                                                                                                                                            SHA-256:5ADBB3D37C3369E5FC80D6A462C82598D5A22FAEF0E8DF6B3148231D2C6A7F73
                                                                                                                                                                                                            SHA-512:81AC9200459B0896E27A028BD089A174F7F921B0367BC8FF1AB33D3E561417B6F8EC23DAB750ECB408AC8A11CDFDBFA4F890F9E723BB8607B017C9FEE00928A0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ar_JO DAYS_OF_WEEK_ABBREV [list \.. "\u0627\u0644\u0623\u062d\u062f"\.. "\u0627\u0644\u0627\u062b\u0646\u064a\u0646"\.. "\u0627\u0644\u062b\u0644\u0627\u062b\u0627\u0621"\.. "\u0627\u0644\u0623\u0631\u0628\u0639\u0627\u0621"\.. "\u0627\u0644\u062e\u0645\u064a\u0633"\.. "\u0627\u0644\u062c\u0645\u0639\u0629"\.. "\u0627\u0644\u0633\u0628\u062a"].. ::msgcat::mcset ar_JO MONTHS_ABBREV [list \.. "\u0643\u0627\u0646\u0648\u0646 \u0627\u0644\u062b\u0627\u0646\u064a"\.. "\u0634\u0628\u0627\u0637"\.. "\u0622\u0630\u0627\u0631"\.. "\u0646\u064a\u0633\u0627\u0646"\.. "\u0646\u0648\u0627\u0631"\.. "\u062d\u0632\u064a\u0631\u0627\u0646"\.. "\u062a\u0645\u0648\u0632"\.. "\u0622\u0628"\.. "\u0623\u064a\u0644\u0648\u0644"\.. "\u062a\u0634\u0631\u064a\u0646 \u0627\u0644\u0623\u0648\u064
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1851
                                                                                                                                                                                                            Entropy (8bit):4.083347689510237
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83LxS/Sm8S9+es/Ii/R91bpH0+U/c+es/Ii/R91bpH0+UO:431iSm8S5MbJbQgMbJbp
                                                                                                                                                                                                            MD5:6FC1CC738207E2F8E0871103841BC0D4
                                                                                                                                                                                                            SHA1:D2C62C7F6DA1EF399FCBE2BA91C9562C87E6152F
                                                                                                                                                                                                            SHA-256:1FC13070CF661488E90FECE84274C46B1F4CC7E1565EAB8F829CCAA65108DFCA
                                                                                                                                                                                                            SHA-512:E547D5CBB746654051AFDA21942075BC2224C2FF75D440C6C34C642AD24CF622E520FF919B8BD4AFC0116D9CE69B3ABA4E81EE247C1388F3C5741150201F5C60
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ar_LB DAYS_OF_WEEK_ABBREV [list \.. "\u0627\u0644\u0623\u062d\u062f"\.. "\u0627\u0644\u0627\u062b\u0646\u064a\u0646"\.. "\u0627\u0644\u062b\u0644\u0627\u062b\u0627\u0621"\.. "\u0627\u0644\u0623\u0631\u0628\u0639\u0627\u0621"\.. "\u0627\u0644\u062e\u0645\u064a\u0633"\.. "\u0627\u0644\u062c\u0645\u0639\u0629"\.. "\u0627\u0644\u0633\u0628\u062a"].. ::msgcat::mcset ar_LB MONTHS_ABBREV [list \.. "\u0643\u0627\u0646\u0648\u0646 \u0627\u0644\u062b\u0627\u0646\u064a"\.. "\u0634\u0628\u0627\u0637"\.. "\u0622\u0630\u0627\u0631"\.. "\u0646\u064a\u0633\u0627\u0646"\.. "\u0646\u0648\u0627\u0631"\.. "\u062d\u0632\u064a\u0631\u0627\u0646"\.. "\u062a\u0645\u0648\u0632"\.. "\u0622\u0628"\.. "\u0623\u064a\u0644\u0648\u0644"\.. "\u062a\u0634\u0631\u064a\u0646 \u0627\u0644\u0623\u0648\u064
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1851
                                                                                                                                                                                                            Entropy (8bit):4.084701680556524
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83lxS/Sm8M9+es/Ii/R91bpH0+UBc+es/Iv/I91bpH0+UO:43LiSm8M5MbJbSgMo0bp
                                                                                                                                                                                                            MD5:8188C37CA44FEFFF8D895AAD503AD4F6
                                                                                                                                                                                                            SHA1:C48F2E3B9FC055704D2DAFDC67E9D08EE6897D45
                                                                                                                                                                                                            SHA-256:294F3E46C55453EDAD44567E1330F9B43E69A07FA0655B24DD2780A4490C1194
                                                                                                                                                                                                            SHA-512:F86FCFC7C460473D46C472041AB2E1F9388CF34BCA9050295D1DAE454E35A2A0320D0C61D5E8CBB832AF74FFDD1A7511AF32EA2A53B481F39A1CBCF5F086D514
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ar_SY DAYS_OF_WEEK_ABBREV [list \.. "\u0627\u0644\u0623\u062d\u062f"\.. "\u0627\u0644\u0627\u062b\u0646\u064a\u0646"\.. "\u0627\u0644\u062b\u0644\u0627\u062b\u0627\u0621"\.. "\u0627\u0644\u0623\u0631\u0628\u0639\u0627\u0621"\.. "\u0627\u0644\u062e\u0645\u064a\u0633"\.. "\u0627\u0644\u062c\u0645\u0639\u0629"\.. "\u0627\u0644\u0633\u0628\u062a"].. ::msgcat::mcset ar_SY MONTHS_ABBREV [list \.. "\u0643\u0627\u0646\u0648\u0646 \u0627\u0644\u062b\u0627\u0646\u064a"\.. "\u0634\u0628\u0627\u0637"\.. "\u0622\u0630\u0627\u0631"\.. "\u0646\u064a\u0633\u0627\u0646"\.. "\u0646\u0648\u0627\u0631"\.. "\u062d\u0632\u064a\u0631\u0627\u0646"\.. "\u062a\u0645\u0648\u0632"\.. "\u0622\u0628"\.. "\u0623\u064a\u0644\u0648\u0644"\.. "\u062a\u0634\u0631\u064a\u0646 \u0627\u0644\u0623\u0648\u064
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2157
                                                                                                                                                                                                            Entropy (8bit):4.27810535662921
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:43PI8IKQGQ8mA/XxQJxQnA9QJlPyI/tbCaQICMIcQ8InVI5tNIzQFIQQLtChjsI4:2PItK5BSb9ajfycCW5IzdQNxK
                                                                                                                                                                                                            MD5:6334BDDFC1E0EAE4DBB2C90F85818FD8
                                                                                                                                                                                                            SHA1:085EDC3D027D6B5A6A6A2561717EA89C8F8B8B39
                                                                                                                                                                                                            SHA-256:A636A82C7D00CCDC0AF2496043FFA320F17B0D48A1232708810D3BB1453E881E
                                                                                                                                                                                                            SHA-512:18ADB77314FCFD534E55B234B3A53A0BC572AB60B80D099D2F3B20E0C5FE66179FDC076AA43200DB3CA123BC6216989EC41448FA624D3BA9633413AD8AD6034C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset be DAYS_OF_WEEK_ABBREV [list \.. "\u043d\u0434"\.. "\u043f\u043d"\.. "\u0430\u0442"\.. "\u0441\u0440"\.. "\u0447\u0446"\.. "\u043f\u0442"\.. "\u0441\u0431"].. ::msgcat::mcset be DAYS_OF_WEEK_FULL [list \.. "\u043d\u044f\u0434\u0437\u0435\u043b\u044f"\.. "\u043f\u0430\u043d\u044f\u0434\u0437\u0435\u043b\u0430\u043a"\.. "\u0430\u045e\u0442\u043e\u0440\u0430\u043a"\.. "\u0441\u0435\u0440\u0430\u0434\u0430"\.. "\u0447\u0430\u0446\u0432\u0435\u0440"\.. "\u043f\u044f\u0442\u043d\u0456\u0446\u0430"\.. "\u0441\u0443\u0431\u043e\u0442\u0430"].. ::msgcat::mcset be MONTHS_ABBREV [list \.. "\u0441\u0442\u0434"\.. "\u043b\u044e\u0442"\.. "\u0441\u043a\u0432"\.. "\u043a\u0440\u0441"\.. "\u043c\u0430\u0439"\.. "\u0447\u0440\u0432"\.. "\u043b\u043f\u043d"
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1871
                                                                                                                                                                                                            Entropy (8bit):4.4251657008559935
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:43EUAIlnQf/QVdQ81mnEZqEavWQEQ3QvQrQL0QjQTtQDCQSY4tqP:27xMk+nEZqE3biIYbUi+C9y
                                                                                                                                                                                                            MD5:E5225D6478C60E2502D18698BB917677
                                                                                                                                                                                                            SHA1:52D611CB5351FB873D2535246B3A3C1A37094023
                                                                                                                                                                                                            SHA-256:CFE4E44A3A751F113847667EC9EA741E762BBDE0D4284822CB337DF0F92C1ACA
                                                                                                                                                                                                            SHA-512:59AB167177101088057BF4EE0F70262987A2177ECB72C613CCAAE2F3E8D8B77F07D15DA5BE3B8728E23C31A1C9736030AA4036A8CD00A24791751A298B3A88B3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset bg DAYS_OF_WEEK_ABBREV [list \.. "\u041d\u0434"\.. "\u041f\u043d"\.. "\u0412\u0442"\.. "\u0421\u0440"\.. "\u0427\u0442"\.. "\u041f\u0442"\.. "\u0421\u0431"].. ::msgcat::mcset bg DAYS_OF_WEEK_FULL [list \.. "\u041d\u0435\u0434\u0435\u043b\u044f"\.. "\u041f\u043e\u043d\u0435\u0434\u0435\u043b\u043d\u0438\u043a"\.. "\u0412\u0442\u043e\u0440\u043d\u0438\u043a"\.. "\u0421\u0440\u044f\u0434\u0430"\.. "\u0427\u0435\u0442\u0432\u044a\u0440\u0442\u044a\u043a"\.. "\u041f\u0435\u0442\u044a\u043a"\.. "\u0421\u044a\u0431\u043e\u0442\u0430"].. ::msgcat::mcset bg MONTHS_ABBREV [list \.. "I"\.. "II"\.. "III"\.. "IV"\.. "V"\.. "VI"\.. "VII"\.. "VIII"\.. "IX"\.. "X"\.. "XI"\.. "XII"\.. ""].. ::msgcat::mcset bg MO
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2335
                                                                                                                                                                                                            Entropy (8bit):4.107102006297273
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR835e/MWrD//6HFEVcVVcCVcTUTVckVEVcT7VcEEVcby/Vcn0VcMr/0VcM8VcQ:43ktX++QalMObalMZ6IE6V
                                                                                                                                                                                                            MD5:5D25E7FC65824AC987535FEA14A4045C
                                                                                                                                                                                                            SHA1:85C10F05823CD3263FC7B3EC38796BEC261B3716
                                                                                                                                                                                                            SHA-256:890EA6521DEB1B3C3913CCD92562F6360E064DAEE2E2B0356A6DD97A46264A1F
                                                                                                                                                                                                            SHA-512:5D8A88ACAEBBF3CD721F288FA0F1FEE517EE568CA5482E30CFA1E36CD37DF011C449090E2D9041F1D046A191F13D4C5C4B6F9E2F16FD259E63CE46ECC4E4F81F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset bn DAYS_OF_WEEK_ABBREV [list \.. "\u09b0\u09ac\u09bf"\.. "\u09b8\u09cb\u09ae"\.. "\u09ae\u0999\u0997\u09b2"\.. "\u09ac\u09c1\u09a7"\.. "\u09ac\u09c3\u09b9\u09b8\u09cd\u09aa\u09a4\u09bf"\.. "\u09b6\u09c1\u0995\u09cd\u09b0"\.. "\u09b6\u09a8\u09bf"].. ::msgcat::mcset bn DAYS_OF_WEEK_FULL [list \.. "\u09b0\u09ac\u09bf\u09ac\u09be\u09b0"\.. "\u09b8\u09cb\u09ae\u09ac\u09be\u09b0"\.. "\u09ae\u0999\u0997\u09b2\u09ac\u09be\u09b0"\.. "\u09ac\u09c1\u09a7\u09ac\u09be\u09b0"\.. "\u09ac\u09c3\u09b9\u09b8\u09cd\u09aa\u09a4\u09bf\u09ac\u09be\u09b0"\.. "\u09b6\u09c1\u0995\u09cd\u09b0\u09ac\u09be\u09b0"\.. "\u09b6\u09a8\u09bf\u09ac\u09be\u09b0"].. ::msgcat::mcset bn MONTHS_ABBREV [list \.. "\u099c\u09be\u09a8\u09c1\u09df\u09be\u09b0\u09c0"\.. "\u09ab\u09c7\u09ac\u09cd\u09b0\u09c1\u09df\u09be
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):265
                                                                                                                                                                                                            Entropy (8bit):4.868201122972066
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xovtvfluo/E3v6xyFjovto+3vflm68vn:4EnLB383UtvfltE3v6g8tF3vflm6+n
                                                                                                                                                                                                            MD5:B91BB2ABC23B90962D2070B9588F2AB5
                                                                                                                                                                                                            SHA1:CBB4E9CD600773792C6E9F3E6B27E99C1846B44F
                                                                                                                                                                                                            SHA-256:B3D8A4632290B0F3DA690E47C1FDF06A8B9E171A96E938AFDB0DD52CF806CE54
                                                                                                                                                                                                            SHA-512:932FC4B8C3CA72731187D56012AD7DD7777C4D447F16EEB17B9D68235C9590DF99992FD22B8D7C85A843A610F93CD36FAFA993C34C441255A1C0A93C73BC5FE4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset bn_IN DATE_FORMAT "%A %d %b %Y".. ::msgcat::mcset bn_IN TIME_FORMAT_12 "%I:%M:%S %z".. ::msgcat::mcset bn_IN DATE_TIME_FORMAT "%A %d %b %Y %I:%M:%S %z %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1152
                                                                                                                                                                                                            Entropy (8bit):4.2880653012847985
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83FMVBNfPg+g+RjMu5+C6MB4zdiwvWvn:432g6jh65zd3gn
                                                                                                                                                                                                            MD5:72DDD60C907DD235BCE4AB0A5AEE902C
                                                                                                                                                                                                            SHA1:06150F793251687E6FBC3FDA3BC81BCBFC7DE763
                                                                                                                                                                                                            SHA-256:3BE295DCC8FCDC767FED0C68E3867359C18E7E57D7DB6C07236B5BC572AD328E
                                                                                                                                                                                                            SHA-512:3B0A85003692F1E46185D5CC09236D2DA5E6D29166C9812D07A7D6BF6AC6C3B0708F91C6899768D4DBA3528081B8B43E09F49622B70F1CF991AFAC5352B6BA37
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ca DAYS_OF_WEEK_ABBREV [list \.. "dg."\.. "dl."\.. "dt."\.. "dc."\.. "dj."\.. "dv."\.. "ds."].. ::msgcat::mcset ca DAYS_OF_WEEK_FULL [list \.. "diumenge"\.. "dilluns"\.. "dimarts"\.. "dimecres"\.. "dijous"\.. "divendres"\.. "dissabte"].. ::msgcat::mcset ca MONTHS_ABBREV [list \.. "gen."\.. "feb."\.. "mar\u00e7"\.. "abr."\.. "maig"\.. "juny"\.. "jul."\.. "ag."\.. "set."\.. "oct."\.. "nov."\.. "des."\.. ""].. ::msgcat::mcset ca MONTHS_FULL [list \.. "gener"\.. "febrer"\.. "mar\u00e7"\.. "abril"\.. "maig"\.. "juny"\.. "juliol"\.. "agost"\.. "setembre"\.. "octubre"\.. "novembre"\.. "desembre"\.. ""].. ::msg
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1354
                                                                                                                                                                                                            Entropy (8bit):4.466447248030554
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83U4nZ4yJTkkG3mYWEZqO1R3DNBEVG+PYhxrU4UF3ecCvt7/v3e6:43TJTGmnEZqE5/EVEDOGtDp
                                                                                                                                                                                                            MD5:F32EAD82CC26754C5A8E092873A28DB3
                                                                                                                                                                                                            SHA1:325124660F62242B24623B4B737CB4616F86CFF3
                                                                                                                                                                                                            SHA-256:AFEA12A16A6FA750EA610245133B90F178BA714848F89AEC37429A3E7B06BE1A
                                                                                                                                                                                                            SHA-512:04E335AAFBF4D169983635FC87BCFFE86FBA570A3E1820D20240EF7B47E7A3CD94AE3598543DCE92A1F82B5146CAAD982EFE9490EFD9E581D58515CFC3930581
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset cs DAYS_OF_WEEK_ABBREV [list \.. "Ne"\.. "Po"\.. "\u00dat"\.. "St"\.. "\u010ct"\.. "P\u00e1"\.. "So"].. ::msgcat::mcset cs DAYS_OF_WEEK_FULL [list \.. "Ned\u011ble"\.. "Pond\u011bl\u00ed"\.. "\u00dater\u00fd"\.. "St\u0159eda"\.. "\u010ctvrtek"\.. "P\u00e1tek"\.. "Sobota"].. ::msgcat::mcset cs MONTHS_ABBREV [list \.. "I"\.. "II"\.. "III"\.. "IV"\.. "V"\.. "VI"\.. "VII"\.. "VIII"\.. "IX"\.. "X"\.. "XI"\.. "XII"\.. ""].. ::msgcat::mcset cs MONTHS_FULL [list \.. "leden"\.. "\u00fanor"\.. "b\u0159ezen"\.. "duben"\.. "kv\u011bten"\.. "\u010derven"\.. "\u010dervenec"\.. "srpen"\.. "z\u00e1\u0159\u00ed"\.. "\u0159\u00edjen"\..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1208
                                                                                                                                                                                                            Entropy (8bit):4.315504392809956
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83wV0tBVYuorIsmZ5meAxyISjTHU92WFVwpwvbvT:43w+DiuorreAY0zw8rT
                                                                                                                                                                                                            MD5:27A6A8BE8903AEF9D0BE956906A89583
                                                                                                                                                                                                            SHA1:EE29FDF67CB3AE150DF6BBBE603C1C3F5DA28641
                                                                                                                                                                                                            SHA-256:0D422A991BCA13FE9033118691CFEDAB0F372222EBB0BC92BAF8E914EE816B84
                                                                                                                                                                                                            SHA-512:0E702A679AD94BF479226B7DE32077562F3F95210F6453AE564138386DBB179941BA5359AEE9AC532F4A6E5BE745D6962D6B638A21DD48B865716F2FD2A0CB01
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset da DAYS_OF_WEEK_ABBREV [list \.. "s\u00f8"\.. "ma"\.. "ti"\.. "on"\.. "to"\.. "fr"\.. "l\u00f8"].. ::msgcat::mcset da DAYS_OF_WEEK_FULL [list \.. "s\u00f8ndag"\.. "mandag"\.. "tirsdag"\.. "onsdag"\.. "torsdag"\.. "fredag"\.. "l\u00f8rdag"].. ::msgcat::mcset da MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "maj"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset da MONTHS_FULL [list \.. "januar"\.. "februar"\.. "marts"\.. "april"\.. "maj"\.. "juni"\.. "juli"\.. "august"\.. "september"\.. "oktober"\.. "november"\.. "december"\.. ""].. ::msgcat::mcset da B
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1276
                                                                                                                                                                                                            Entropy (8bit):4.349293509679722
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83cFNSsZKKgXum47fpK2OaSIui7dHqWZ0ZIBFJWJvvvWIn:43InZKKgXoOqx1W67W9XWIn
                                                                                                                                                                                                            MD5:EE3963A5F7E29C05C9617BE3FD897114
                                                                                                                                                                                                            SHA1:0F978CA174DF596817F872B5EF1B447B9DFE651C
                                                                                                                                                                                                            SHA-256:4C27733502066E8391654D1D372F92BF0484C5A3821E121AE8AA5B99378C99AE
                                                                                                                                                                                                            SHA-512:EA933709C68F8199858A1CC1FFDA67EE7458CC57A163E672535EB0B4C37BFDC200604C7506748DAC3158B6CA63C2F076A2C6252B2A596E59F83D3B1D4BC9C901
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset de DAYS_OF_WEEK_ABBREV [list \.. "So"\.. "Mo"\.. "Di"\.. "Mi"\.. "Do"\.. "Fr"\.. "Sa"].. ::msgcat::mcset de DAYS_OF_WEEK_FULL [list \.. "Sonntag"\.. "Montag"\.. "Dienstag"\.. "Mittwoch"\.. "Donnerstag"\.. "Freitag"\.. "Samstag"].. ::msgcat::mcset de MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "Mrz"\.. "Apr"\.. "Mai"\.. "Jun"\.. "Jul"\.. "Aug"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Dez"\.. ""].. ::msgcat::mcset de MONTHS_FULL [list \.. "Januar"\.. "Februar"\.. "M\u00e4rz"\.. "April"\.. "Mai"\.. "Juni"\.. "Juli"\.. "August"\.. "September"\.. "Oktober"\.. "November"\.. "Dezember"\.. ""].. ::msgcat::mcset de BCE "v.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):847
                                                                                                                                                                                                            Entropy (8bit):4.412930056658995
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR831sMm47fpK2++SIui7dHqWZ0ZItovGvzvW:431h+mx1Wm+QjW
                                                                                                                                                                                                            MD5:A6227CD4F7434952D093F1F3C64B4378
                                                                                                                                                                                                            SHA1:0DDB9A49CB83DDF2396B2ECA85093260710496C2
                                                                                                                                                                                                            SHA-256:1C02D14140196623297F858E2EEF00B4159E1C6FAFE044EC65A48C9C24D46540
                                                                                                                                                                                                            SHA-512:D63F34024356F5CE0335D14EA557F4BBF238CCA8265DD27C039C70F7F28FE737F368B030DEE10B2C536512D2815E1F5B19838D08745C6A76A39050D573597EB3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset de_AT MONTHS_ABBREV [list \.. "J\u00e4n"\.. "Feb"\.. "M\u00e4r"\.. "Apr"\.. "Mai"\.. "Jun"\.. "Jul"\.. "Aug"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Dez"\.. ""].. ::msgcat::mcset de_AT MONTHS_FULL [list \.. "J\u00e4nner"\.. "Februar"\.. "M\u00e4rz"\.. "April"\.. "Mai"\.. "Juni"\.. "Juli"\.. "August"\.. "September"\.. "Oktober"\.. "November"\.. "Dezember"\.. ""].. ::msgcat::mcset de_AT DATE_FORMAT "%Y-%m-%d".. ::msgcat::mcset de_AT TIME_FORMAT "%T".. ::msgcat::mcset de_AT TIME_FORMAT_12 "%T".. ::msgcat::mcset de_AT DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1276
                                                                                                                                                                                                            Entropy (8bit):4.389082225723362
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83B8VSysVB8VsZKKgJ5Mm47fpK26aSIui7dHqWZ0ZIlj5VevjevbDvW:43Bt1VBbZKKgJs6qx1Wc5VojobzW
                                                                                                                                                                                                            MD5:C351057D8E5328C0790901D1F4DBEC9F
                                                                                                                                                                                                            SHA1:F73DE8AEF7F8083B0726760AA003E81067A68588
                                                                                                                                                                                                            SHA-256:532845CD15EC821C1939D000C648694A64E8CA8F0C14BAD5D79682CF991481CE
                                                                                                                                                                                                            SHA-512:8152AD082D0A6A4EBE7E1CCA9D4A5F2E48ABE3F09F4385A517C523A67CA3B08E0F20C193D0F6850F37E55ED0CD6FBD201FE22CC824AF170976D04DB061212F2D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset de_BE DAYS_OF_WEEK_ABBREV [list \.. "Son"\.. "Mon"\.. "Die"\.. "Mit"\.. "Don"\.. "Fre"\.. "Sam"].. ::msgcat::mcset de_BE DAYS_OF_WEEK_FULL [list \.. "Sonntag"\.. "Montag"\.. "Dienstag"\.. "Mittwoch"\.. "Donnerstag"\.. "Freitag"\.. "Samstag"].. ::msgcat::mcset de_BE MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "M\u00e4r"\.. "Apr"\.. "Mai"\.. "Jun"\.. "Jul"\.. "Aug"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Dez"\.. ""].. ::msgcat::mcset de_BE MONTHS_FULL [list \.. "Januar"\.. "Februar"\.. "M\u00e4rz"\.. "April"\.. "Mai"\.. "Juni"\.. "Juli"\.. "August"\.. "September"\.. "Oktober"\.. "November"\.. "Dezember"\.. ""].. ::m
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2304
                                                                                                                                                                                                            Entropy (8bit):4.371322909589862
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR833v+ZYYWtv+nWfFyL1NYOg+EKVJQ19tWQYmYaYRn9sWuSAJIJ6eRa6WrmdlX:43/pZyLjY0uYR9QmdkjC9r
                                                                                                                                                                                                            MD5:7DD14B1F4FF532DCAF6D4C6F0DF82E9A
                                                                                                                                                                                                            SHA1:707875FEF4207EBB71D066FDC54C7F68560C6DAD
                                                                                                                                                                                                            SHA-256:8B23E0E2F0F319BB9A2DFDCCDC565FF79A62FA85094811189B6BC41594232B6B
                                                                                                                                                                                                            SHA-512:5ECA072DE5DD7890270AE268C7C8D40EE2DB6966643604D16E54194DB0AD74FDA8D04848331E61B387E8B494AF18252E38671D939069EC4C90C672A629563B88
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset el DAYS_OF_WEEK_ABBREV [list \.. "\u039a\u03c5\u03c1"\.. "\u0394\u03b5\u03c5"\.. "\u03a4\u03c1\u03b9"\.. "\u03a4\u03b5\u03c4"\.. "\u03a0\u03b5\u03bc"\.. "\u03a0\u03b1\u03c1"\.. "\u03a3\u03b1\u03b2"].. ::msgcat::mcset el DAYS_OF_WEEK_FULL [list \.. "\u039a\u03c5\u03c1\u03b9\u03b1\u03ba\u03ae"\.. "\u0394\u03b5\u03c5\u03c4\u03ad\u03c1\u03b1"\.. "\u03a4\u03c1\u03af\u03c4\u03b7"\.. "\u03a4\u03b5\u03c4\u03ac\u03c1\u03c4\u03b7"\.. "\u03a0\u03ad\u03bc\u03c0\u03c4\u03b7"\.. "\u03a0\u03b1\u03c1\u03b1\u03c3\u03ba\u03b5\u03c5\u03ae"\.. "\u03a3\u03ac\u03b2\u03b2\u03b1\u03c4\u03bf"].. ::msgcat::mcset el MONTHS_ABBREV [list \.. "\u0399\u03b1\u03bd"\.. "\u03a6\u03b5\u03b2"\.. "\u039c\u03b1\u03c1"\.. "\u0391\u03c0\u03c1"\.. "\u039c\u03b1\u03ca"\.. "\u0399\u03bf\u
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):307
                                                                                                                                                                                                            Entropy (8bit):4.896073290907262
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoCwmGjbmvFjoCws6W3v1oCws6W3v6p6HyFjoCwmT+3vjbe:4EnLB383QrmdSs6W3vss6W3v6QSoJ3ve
                                                                                                                                                                                                            MD5:5B31AD8AC0000B01C4BD04BF6FC4784C
                                                                                                                                                                                                            SHA1:F55145B473DDCAE38A0F7297D58B80B12B2A5271
                                                                                                                                                                                                            SHA-256:705C66C14B6DE682EC7408EABDBA0800C626629E64458971BC8A4CBD3D5DB111
                                                                                                                                                                                                            SHA-512:1CCE6BCAE5D1F7D80E10687F0BCA2AE1B2DD53F04A0F443DC9B552804D60E708E64326B62BA4E3787325D89837B4AC8CCCA9AF6F39CBD654BCC8A9C27EA63BB8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_AU DATE_FORMAT "%e/%m/%Y".. ::msgcat::mcset en_AU TIME_FORMAT "%H:%M:%S".. ::msgcat::mcset en_AU TIME_FORMAT_12 "%I:%M:%S %P %z".. ::msgcat::mcset en_AU DATE_TIME_FORMAT "%e/%m/%Y %H:%M:%S %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):312
                                                                                                                                                                                                            Entropy (8bit):4.870560620756039
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoCr3FuoCsX3vtfNrsoCsX3v6YNIdjoCs+3v3FnN9vn:4EnLB383H3Fb3vtNN3v6y43v3FnNNn
                                                                                                                                                                                                            MD5:DDA87ACED97F9F7771788A1A0A1E4433
                                                                                                                                                                                                            SHA1:E221653CD659C095098180344654770FF059331B
                                                                                                                                                                                                            SHA-256:BC87754A253C1036E423FA553DA182DBC56F62A13EDA811D8CD9E8AFA40404A6
                                                                                                                                                                                                            SHA-512:BB95D9241B05686CA15C413746DD06071635CB070F38847BE9702397A86C01A3D54DEBE1ACAA51834AB74DB8D0F75E353995183864E382721425756EE46B0B1E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_BE DATE_FORMAT "%d %b %Y".. ::msgcat::mcset en_BE TIME_FORMAT "%k:%M:%S".. ::msgcat::mcset en_BE TIME_FORMAT_12 "%k h %M min %S s %z".. ::msgcat::mcset en_BE DATE_TIME_FORMAT "%d %b %Y %k:%M:%S %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.915769170926952
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xosmGMoss6W3v6ay/5osmT+3vR6HyFvn:4EnLB383hr8s6W3v6ay/hJ3voSVn
                                                                                                                                                                                                            MD5:4CBF90CE15ECCB6B695AA78D7D659454
                                                                                                                                                                                                            SHA1:30C26ADB03978C5E7288B964A14B692813D6E0B8
                                                                                                                                                                                                            SHA-256:EC48F18995D46F82B1CC71EA285174505A50E3BA2017BCCE2D807149B7543FD0
                                                                                                                                                                                                            SHA-512:CC809EBD1B2B5D9E918C2E2CE4E7075DFB0744C583F17C1C234D8437EF0C34654D2F09FF77544AD3430CEC78ABC70AA5F85F71AD1489A687B8087FCDFE07B088
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_BW DATE_FORMAT "%d %B %Y".. ::msgcat::mcset en_BW TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset en_BW DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):295
                                                                                                                                                                                                            Entropy (8bit):4.87629705076992
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoAhgqyFjoAZF3vX5oAZF3v6cvBoAh9+3vnFDL8vn:4EnLB383FhgqWDZF3vVZF3v6cvdhI3vM
                                                                                                                                                                                                            MD5:BFC4A48F5B10D137A4D32B440C47D3C6
                                                                                                                                                                                                            SHA1:C90EF2A8291DE589BC12D0A5B8AF2F0B00FEB7CD
                                                                                                                                                                                                            SHA-256:3CF2D0937FD95264549CF5C768B898F01D4875A3EB4A85D457D758BC11DFEC6E
                                                                                                                                                                                                            SHA-512:A91B81A956A438CA7274491CA107A2647CBDFB8AEB5FD7A58238F315590C74F83F2EBA4AA5C4E9A4A54F1FC1636318E94E5E4BBEA467326E0EACED079741E640
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_CA DATE_FORMAT "%d/%m/%y".. ::msgcat::mcset en_CA TIME_FORMAT "%r".. ::msgcat::mcset en_CA TIME_FORMAT_12 "%I:%M:%S %p".. ::msgcat::mcset en_CA DATE_TIME_FORMAT "%a %d %b %Y %r %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):286
                                                                                                                                                                                                            Entropy (8bit):4.892405843607203
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoEbtvqyFjoELE3vLjoELE3v6mjoEbto+3vnFDoAkvn:4EnLB383BbtvqWHLE3vTLE3v6EbtF3vW
                                                                                                                                                                                                            MD5:52E55DE8C489265064A01CEEC823DCDD
                                                                                                                                                                                                            SHA1:16F314A56AE0EAC9DAD58ADDEA6B25813A5BAA05
                                                                                                                                                                                                            SHA-256:C2CE5B74F9E9C190B21C5DF4106303B7B794481228FB9A57065B9C822A1059C3
                                                                                                                                                                                                            SHA-512:6010F29BF75D0CB4EE4F10781423A8CC68D5018DE8C633CD1217A7FE1299A0532E8C0E5D120188B748171EB255C587BB0B64B7384A58F725F3B6A4B9EA04393E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_GB DATE_FORMAT "%d/%m/%y".. ::msgcat::mcset en_GB TIME_FORMAT "%T".. ::msgcat::mcset en_GB TIME_FORMAT_12 "%T".. ::msgcat::mcset en_GB DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):329
                                                                                                                                                                                                            Entropy (8bit):4.851471679101967
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoa+joaQ9PoaAx/G4soaYYW3v6ay/5oaAx/T+3v4x6HyFvn:4EnLB383BSiF4KxW3v6ay/B/3v4ISVn
                                                                                                                                                                                                            MD5:DE2A484508615D7C1377522AFF03E16C
                                                                                                                                                                                                            SHA1:C27C0D10E7667AD95FFF731B4E45B2C6E665CC36
                                                                                                                                                                                                            SHA-256:563450A38DB6C6A1911BC04F4F55B816910B3E768B1465A69F9B3BD27292DBEE
                                                                                                                                                                                                            SHA-512:A360B0FD7E36BCC0FB4603D622C36199E5D4C705396C6701F29730EB5CB33D81B208541CADFAED5303FC329C7C6A465D23CA9584F0DEC2DE128E258478DD6661
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_HK AM "AM".. ::msgcat::mcset en_HK PM "PM".. ::msgcat::mcset en_HK DATE_FORMAT "%B %e, %Y".. ::msgcat::mcset en_HK TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset en_HK DATE_TIME_FORMAT "%B %e, %Y %l:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):286
                                                                                                                                                                                                            Entropy (8bit):4.833246107458447
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoK6qyFjoKi+3vLjoKi+3v6mjoKv+3vnFDoAkvn:4EnLB383CqW13vJ3v6b3v9dmn
                                                                                                                                                                                                            MD5:57F0BBE1316D14BC41D0858902A7980A
                                                                                                                                                                                                            SHA1:B68BF99A021B9F01FE69341DF06F5D1453156A97
                                                                                                                                                                                                            SHA-256:9E0DCEE86A03B7BDD831E0008868A9B874C506315BF01DF3982AD3813FD3BA8E
                                                                                                                                                                                                            SHA-512:864F32254AAD39859AFC47D0C90DC5F38CA86EF0BBC7DE61BE253756C22B7806E616B59802C4F4D7B2F5543BF7C070FFF6FAF253E0A337EC443337E63A2E5A57
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_IE DATE_FORMAT "%d/%m/%y".. ::msgcat::mcset en_IE TIME_FORMAT "%T".. ::msgcat::mcset en_IE TIME_FORMAT_12 "%T".. ::msgcat::mcset en_IE DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):318
                                                                                                                                                                                                            Entropy (8bit):4.80637980762728
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoKr3ujoKrGtoKr5vMoKrw3v1oKr5o+3voAsvn:4EnLB383T9xvT3vJF3vonn
                                                                                                                                                                                                            MD5:1A54E506E70B2125C6016B373D3DD074
                                                                                                                                                                                                            SHA1:15289902BAA93208D8FB224E119166D0E044E34E
                                                                                                                                                                                                            SHA-256:ADEA3A1AB8AA84237DDB2F276ABDB96DCB4C51932E920D1A5E336904E1138664
                                                                                                                                                                                                            SHA-512:0D663233E6C96515713B3B829B605E72D8CE581AEF1C02FF6CA96598C040DCA42A3AC765EE9B5002E8969A331EB19A9AF0F8215F7113D0AD2F2EB2C560239D53
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_IN AM "AM".. ::msgcat::mcset en_IN PM "PM".. ::msgcat::mcset en_IN DATE_FORMAT "%d %B %Y".. ::msgcat::mcset en_IN TIME_FORMAT "%H:%M:%S".. ::msgcat::mcset en_IN DATE_TIME_FORMAT "%d %B %Y %H:%M:%S %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):307
                                                                                                                                                                                                            Entropy (8bit):4.939458132662909
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoyejbmvFjo63v1o63v6p6HyFjoy7+3vjb0ysvn:4EnLB383temdj3vd3v6QS1S3ven
                                                                                                                                                                                                            MD5:7E81708F107658FFD31C3BFBF704A488
                                                                                                                                                                                                            SHA1:7941ED040707591B68581337F8D90FA03C5E1406
                                                                                                                                                                                                            SHA-256:EC305B7CB393421E6826D8F4FEA749D3902EBA53BFA488F2B463412F4070B9ED
                                                                                                                                                                                                            SHA-512:8F038FF960F81D96FF9E3454D8ABDA7FFDA5B99DA304ACECC42E74DDBED839388246F66B58928DA902D3B475FBA46602B34F6829A87ECB1124FFC47C036B4DBE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_NZ DATE_FORMAT "%e/%m/%Y".. ::msgcat::mcset en_NZ TIME_FORMAT "%H:%M:%S".. ::msgcat::mcset en_NZ TIME_FORMAT_12 "%I:%M:%S %P %z".. ::msgcat::mcset en_NZ DATE_TIME_FORMAT "%e/%m/%Y %H:%M:%S %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):329
                                                                                                                                                                                                            Entropy (8bit):4.824360175945298
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoojoOo2e4soe3v6ay/5o27+3v4x6HyFvn:4EnLB38304u3v6ay/k3v4ISVn
                                                                                                                                                                                                            MD5:E2E3BD806C20D7FB88109B7F3B84C072
                                                                                                                                                                                                            SHA1:2D7AD6BECA9C4D611BAE9747AD55A3E9385C2B42
                                                                                                                                                                                                            SHA-256:3A9C22B07906544C04F7A29B800FCE87C09D7FDF5C251236925115CF251A3890
                                                                                                                                                                                                            SHA-512:B14756B59BCABF8B29B41AC688E4F3A011735AF190B88F88B7B5FDDD3DA77F63FFC0F7875B3B453729CD3BC65E79F75F6E632CA68952EF473F78337D89E80BF2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_PH AM "AM".. ::msgcat::mcset en_PH PM "PM".. ::msgcat::mcset en_PH DATE_FORMAT "%B %e, %Y".. ::msgcat::mcset en_PH TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset en_PH DATE_TIME_FORMAT "%B %e, %Y %l:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.911413468674953
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoQW53FuoQGuX3v6ZwoQWa+3v3F0fxvn:4EnLB383V83FOJ3v62c3v3FEn
                                                                                                                                                                                                            MD5:F70245D73BE985091459ADF74B089EBC
                                                                                                                                                                                                            SHA1:21D52C336C08526D9DCF1AEC1F0701CB8B073D7A
                                                                                                                                                                                                            SHA-256:D565679AE9AACBFE3B5273FE29BD46F46FFBB63C837D7925C11356D267F5FF82
                                                                                                                                                                                                            SHA-512:171C70EB10D5E6421A55CE9B1AE99763E23FB6A6F563F69FE099D07C07FCA0CF8D3F6F00C5BB38BFF59A5F4C311506C4A9593F86C12B3B9E1861E72656B3800B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_SG DATE_FORMAT "%d %b %Y".. ::msgcat::mcset en_SG TIME_FORMAT_12 "%P %I:%M:%S".. ::msgcat::mcset en_SG DATE_TIME_FORMAT "%d %b %Y %P %I:%M:%S %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):251
                                                                                                                                                                                                            Entropy (8bit):4.937431055623088
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoOr0lIZoOK3v6poOs+3v0l6Uvn:4EnLB383z+3v6R3vl2n
                                                                                                                                                                                                            MD5:FCA7B13CA6C9527D396A95BEA94CC92D
                                                                                                                                                                                                            SHA1:E6F338A08F72DA11B97F70518D1565E6EF9AD798
                                                                                                                                                                                                            SHA-256:67C253E2A187AA814809418E5B7A21F3A1F9FB5073458A59D80290F58C6C1EB4
                                                                                                                                                                                                            SHA-512:37B8B4EA24B1C77AF0252A17660650CB2D4F8BB55C75817D6A94E1B81A3DDEF9913D12D3BF80C7BFE524CD0AD84E353E73238056759E6545BFE69EF5F806B8B7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_ZA DATE_FORMAT "%Y/%m/%d".. ::msgcat::mcset en_ZA TIME_FORMAT_12 "%I:%M:%S".. ::msgcat::mcset en_ZA DATE_TIME_FORMAT "%Y/%m/%d %I:%M:%S %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.934659260313229
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoEmGMoEs6W3v6ay/5oEmT+3vR6HyFvn:4EnLB383Zr0s6W3v6ay/ZJ3voSVn
                                                                                                                                                                                                            MD5:A302091F490344B7A79C9463480AD7CF
                                                                                                                                                                                                            SHA1:E3992D665077177BAD5A4771F1BAF52C2AD1829C
                                                                                                                                                                                                            SHA-256:6F4754CE29DFA4F0E7957923249151CE8277395D1AF9F102D61B185F85899E4E
                                                                                                                                                                                                            SHA-512:FEBDB0BD6D0FD4C592DB781836F93F0C579399D324112F8829B769303CC6EEA487AAB14EBD60ED1B4F3B3DABF501601C9F65656327FF54853BF2CD9EC6A2F00F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset en_ZW DATE_FORMAT "%d %B %Y".. ::msgcat::mcset en_ZW TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset en_ZW DATE_TIME_FORMAT "%d %B %Y %l:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1285
                                                                                                                                                                                                            Entropy (8bit):4.3537859241297845
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83dRb4vyomrIsmZ55vrAO0LH+50ydAcveva:43PT5rWvrAR60yW6oa
                                                                                                                                                                                                            MD5:D87605E6282713EED41D56D53B7A04FD
                                                                                                                                                                                                            SHA1:41AAD4BD3B72CCBB6A762FEED3C24931642DD867
                                                                                                                                                                                                            SHA-256:98D52CAB5CA65789D1DC37949B65BAF0272AB87BCCBB4D4982C3AF380D5406AB
                                                                                                                                                                                                            SHA-512:4A4F51B2FD0248B52530B5D9FE6BFCFE455147CBE2C1F073804A53666945405F89CBBAD219FFF6904C1F92885F7C53B9D9A969732D662CEA8EC1717B3303B294
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset eo DAYS_OF_WEEK_ABBREV [list \.. "di"\.. "lu"\.. "ma"\.. "me"\.. "\u0135a"\.. "ve"\.. "sa"].. ::msgcat::mcset eo DAYS_OF_WEEK_FULL [list \.. "diman\u0109o"\.. "lundo"\.. "mardo"\.. "merkredo"\.. "\u0135a\u016ddo"\.. "vendredo"\.. "sabato"].. ::msgcat::mcset eo MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "maj"\.. "jun"\.. "jul"\.. "a\u016dg"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset eo MONTHS_FULL [list \.. "januaro"\.. "februaro"\.. "marto"\.. "aprilo"\.. "majo"\.. "junio"\.. "julio"\.. "a\u016dgusto"\.. "septembro"\.. "oktobro"\.. "novembro"\.. "decembro"\.. ""].. ::m
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1232
                                                                                                                                                                                                            Entropy (8bit):4.2910064237800025
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83hEVIhlp4herIsYoorrClH+Fo9ARhprBvtFvr6:43OVY7+ercrmsYsr1thr6
                                                                                                                                                                                                            MD5:91DE6EE8E1A251EF73CC74BFB0216CAC
                                                                                                                                                                                                            SHA1:1FB01E3CF2CAFA95CC451BC34AB89DC542BBD7DD
                                                                                                                                                                                                            SHA-256:E9A6FE8CCE7C808487DA505176984D02F7D644425934CEDB10B521FE1E796202
                                                                                                                                                                                                            SHA-512:46CFD80E68461F165EE6A93AB6B433E4D4DA6A9A76CB7F3EF5766AC67567A7AFFB7B4E950A5AFA7C69C91F72AC82D2A448D32E39BBFC0BF26D2257460471EEC1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es DAYS_OF_WEEK_ABBREV [list \.. "dom"\.. "lun"\.. "mar"\.. "mi\u00e9"\.. "jue"\.. "vie"\.. "s\u00e1b"].. ::msgcat::mcset es DAYS_OF_WEEK_FULL [list \.. "domingo"\.. "lunes"\.. "martes"\.. "mi\u00e9rcoles"\.. "jueves"\.. "viernes"\.. "s\u00e1bado"].. ::msgcat::mcset es MONTHS_ABBREV [list \.. "ene"\.. "feb"\.. "mar"\.. "abr"\.. "may"\.. "jun"\.. "jul"\.. "ago"\.. "sep"\.. "oct"\.. "nov"\.. "dic"\.. ""].. ::msgcat::mcset es MONTHS_FULL [list \.. "enero"\.. "febrero"\.. "marzo"\.. "abril"\.. "mayo"\.. "junio"\.. "julio"\.. "agosto"\.. "septiembre"\.. "octubre"\.. "noviembre"\.. "diciembre"\.. ""].. ::msgc
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):248
                                                                                                                                                                                                            Entropy (8bit):4.878377455979812
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xo8GzvFjot/W3v1o8T+3v9ysvn:4EnLB3833GzdV3vLK3vnn
                                                                                                                                                                                                            MD5:313966A7E4F50BB77996FDE45E342CA9
                                                                                                                                                                                                            SHA1:021DF7211DAE9A635D52F7005672C157DBBAE182
                                                                                                                                                                                                            SHA-256:B97DCEA4FEC3E14632B1511D8C4F9E5A157D97B4EBBC7C6EE100C3558CB2947F
                                                                                                                                                                                                            SHA-512:79DCC76263310523BAF1100C70918FCE6BECB47BE360E4A26F11C61F27E14FC28B588A9253AA0C1F08F45AE8A03312A30FBDCF4FDFFDC5BF9D086C4B539DE022
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_AR DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_AR TIME_FORMAT "%H:%M:%S".. ::msgcat::mcset es_AR DATE_TIME_FORMAT "%d/%m/%Y %H:%M:%S %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.924579610789789
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoYePWWjoU3v6ry/5oY7+3vPUe6HyFvn:4EnLB383nedh3v6ry/nS3vs3SVn
                                                                                                                                                                                                            MD5:EF58B1097A3C6F2133BD7AA8CCC1AD1B
                                                                                                                                                                                                            SHA1:BD479E4635F3CD70A6A90E07B7E92757BC9E2687
                                                                                                                                                                                                            SHA-256:B47F55539DB6F64304DEA080D6F9A39165F1B9D4704DCBA4C182DBD3AA31A11B
                                                                                                                                                                                                            SHA-512:F9EB1489E5002200D255A45DC57132DEFD2A2C6DE5BC049D0D9720575E4FDD1B6A212D9E15974C6A2E0D0886069EA0DD967AD7C20845EC38EB74CBED0C3E5BE1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_BO DATE_FORMAT "%d-%m-%Y".. ::msgcat::mcset es_BO TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_BO DATE_TIME_FORMAT "%d-%m-%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.9352990174129925
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xodvPWWjok3v6ry/5odo+3vPUe6HyFvn:4EnLB383OdV3v6ry/i3vs3SVn
                                                                                                                                                                                                            MD5:42BCE0EE3A3F9E9782E5DE72C989903A
                                                                                                                                                                                                            SHA1:0960646417A61E8C31D408AE00B36A1284D0300E
                                                                                                                                                                                                            SHA-256:9D1A2A6EBA673C6F6D964DBCDDF228CB64978F282E70E494B60D74E16A1DB9CB
                                                                                                                                                                                                            SHA-512:C53DDCC17F261CFFAA2205879A131CFD23A7BCF4D3787090A0EA8D18530C4805903ED6CF31B53A34C70510A314EBBB68676E9F128289B42C5EFBC701405D5645
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_CL DATE_FORMAT "%d-%m-%Y".. ::msgcat::mcset es_CL TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_CL DATE_TIME_FORMAT "%d-%m-%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.908553844782894
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xo4FjbmvFjo4F+3v6ry/5o4++3vjb0f6HyFvn:4EnLB3831mdD+3v6ry/P3vbSVn
                                                                                                                                                                                                            MD5:6A8F31AE734DCEE4845454408CDB3BC5
                                                                                                                                                                                                            SHA1:A3B9A0124D3CFA9E0E5957612897B23193AD5D59
                                                                                                                                                                                                            SHA-256:5FAC53ACFB305C055AFD0BA824742A78CB506046B26DAC21C73F0BB60C2B889A
                                                                                                                                                                                                            SHA-512:188A65CFE2FBD04D83F363AEA166F224137C8A7009A9EBEB24B2A9AC89D9484D3A7109A4CE08F5C0A28911D81571230CC37554F4F19956AE163F9304911EE53C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_CO DATE_FORMAT "%e/%m/%Y".. ::msgcat::mcset es_CO TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_CO DATE_TIME_FORMAT "%e/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.919346233482604
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xo76GzvFjoTW3v6ry/5o76T+3v9f6HyFvn:4EnLB383K6Gzdj3v6ry/K6K3vMSVn
                                                                                                                                                                                                            MD5:2EDDA3F61BA4D049E6C871D88322CF72
                                                                                                                                                                                                            SHA1:40AFB64AF810596FCBDBD742ACAFE25CE56F3949
                                                                                                                                                                                                            SHA-256:A33DC22330D087B8567670B4915C334FF1741EE03F05D616CC801ECFDA1D9E64
                                                                                                                                                                                                            SHA-512:B6A6059B44F064C5CB59A3DAFAA7BE9064EE3E38F5FA6391017D931EF3A2B471DC4D556B7BEC6852FD1F6260EF17F476754D6BEA89E035748E9304977513CFB5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_CR DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_CR TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_CR DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.913083040975068
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xomerQZ2jou3v6ry/5om7+3vrQZg6HyFvn:4EnLB383sk4/3v6ry/s3vkrSVn
                                                                                                                                                                                                            MD5:76CFD4F568EA799F9A4082865633FF97
                                                                                                                                                                                                            SHA1:B09846BBF7A78243A5075F2DC9241791DCBA434B
                                                                                                                                                                                                            SHA-256:8DC2F857E91912ED46A94EB6B37DD6170EA7BCDDCD41CB85C0926A74EE12FCC1
                                                                                                                                                                                                            SHA-512:58B20A8A5D1F8C19AC36E61965106266B7E6F7E95DDD6AD9C4BB9FD7FFC561CB0E2103639D901A6A78CE2DD154CBF7F3AE0F71B4DC1CCB11DC6BB40D9C6E2157
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_DO DATE_FORMAT "%m/%d/%Y".. ::msgcat::mcset es_DO TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_DO DATE_TIME_FORMAT "%m/%d/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.915857529388286
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xozgzvFjoro+3v6ry/5oz9+3v9f6HyFvn:4EnLB383OgzdkF3v6ry/OI3vMSVn
                                                                                                                                                                                                            MD5:94B713B1560FE7711EA746F1CEBD37CD
                                                                                                                                                                                                            SHA1:E7047E8F04D731D38FA328FBC0E1856C4A8BB23D
                                                                                                                                                                                                            SHA-256:52AB5A6C9DD4F130A75C049B3AF8F54B84071FC190374BCCF5FA0E1F3B91EB21
                                                                                                                                                                                                            SHA-512:EE807D4D74A609F642CC3C6FC3D736708F67A6931DEB95288AB5822DA256BE4C908A346036195CF4266408458906D28BB5C715EEAFCACFC4FE45D4E6D8E435FE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_EC DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_EC TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_EC DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.9102355704853435
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xohvjbmvFjoI3v6ry/5oho+3vjb0f6HyFvn:4EnLB383KmdJ3v6ry/W3vbSVn
                                                                                                                                                                                                            MD5:761D0A468DF2EE75BC2CAB09D5FF38CD
                                                                                                                                                                                                            SHA1:D627BE45FE71CCB3CA53153393C075FF5136C2F3
                                                                                                                                                                                                            SHA-256:19B4D3025156C060A16328370A3FDB9F141298DECFC8F97BE606F6438FECE2EE
                                                                                                                                                                                                            SHA-512:6CF7C9004A8A3B70495862B7D21921B1A6263C2153FEBC5C4997366498ABBFE70263B436C2B4998550780A4C3A58DCF0AAE7420FF9D414323D731FA44BD83104
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_GT DATE_FORMAT "%e/%m/%Y".. ::msgcat::mcset es_GT TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_GT DATE_TIME_FORMAT "%e/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.947925914291734
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoIvriSFjoP3v6ry/5oIo+3vrig6HyFvn:4EnLB383V+2m3v6ry/v3v+lSVn
                                                                                                                                                                                                            MD5:33CEE7F947A484B076F5FA7871A30FEB
                                                                                                                                                                                                            SHA1:F77F8D1F42008770A6FF1F5097C863ECF482BEBE
                                                                                                                                                                                                            SHA-256:07873D4D59BB41000706A844859C73D26B1FF794058AA83CFFCA804981A24038
                                                                                                                                                                                                            SHA-512:EBF6873F9CB554489EFCD352943100C00171E49D27153769D1C4DB25E2D1F44F2D34869B596C267C9BB59ED0444468D9982137CFB1C6035FB15A855BB867133B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_HN DATE_FORMAT "%m-%d-%Y".. ::msgcat::mcset es_HN TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_HN DATE_TIME_FORMAT "%m-%d-%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.9102355704853435
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoPjbmvFjoH+3v6ry/5oI+3vjb0f6HyFvn:4EnLB383UmdD3v6ry/k3vbSVn
                                                                                                                                                                                                            MD5:678D7A6DC32355246BF3AC485A24AF4D
                                                                                                                                                                                                            SHA1:B6C273D3BE5FB9F5A221B0333870CCE41CEDFDE4
                                                                                                                                                                                                            SHA-256:A0F57137D2C0ABDC933E03CFB188F5632176C195CEADB9DC80D469C8DC6CEDC6
                                                                                                                                                                                                            SHA-512:571404CCB0591C681C975E3F7A6C6972FAF2362F1D48BFC95E69A9EAE2DB3F40BF4B666C41950C4924E3FD820C61ED91204F92283B8554F1BD35B64D53BD4125
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_MX DATE_FORMAT "%e/%m/%Y".. ::msgcat::mcset es_MX TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_MX DATE_TIME_FORMAT "%e/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.918215906418583
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoe/GriSFjo3W3v6ry/5oe/T+3vrig6HyFvn:4EnLB383Re+2eW3v6ry/RS3v+lSVn
                                                                                                                                                                                                            MD5:471C41907CE5DB1F30C647A789870F78
                                                                                                                                                                                                            SHA1:C575A639609620AF7C56430991D0E4C2B50BDEC5
                                                                                                                                                                                                            SHA-256:6250663DA1378E54BEDCEF206583D212BC0D61D04D070495238D33715BB20CAE
                                                                                                                                                                                                            SHA-512:CAE32DF8F583542CAFE3292501725D85B697A5C1F9A0A7993490E8A69B6CE5CE3DE3AA2733B14D989A8D13B5E31B437DB42E9AB9D1851FE72313592C752B5061
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_NI DATE_FORMAT "%m-%d-%Y".. ::msgcat::mcset es_NI TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_NI DATE_TIME_FORMAT "%m-%d-%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.906719336603863
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoX5rQZ2joHE3v6ry/5oXa+3vrQZg6HyFvn:4EnLB383ak4F3v6ry/G3vkrSVn
                                                                                                                                                                                                            MD5:571F6716293442672521F70854A5AD05
                                                                                                                                                                                                            SHA1:525EBDEA6F85FC769B6C0C0B179BD98381647123
                                                                                                                                                                                                            SHA-256:EBB661C1C09E7D4F6FBCC4B2DAD0F41442B1FFDD27F003ABDC0375DD316E57D7
                                                                                                                                                                                                            SHA-512:C6176EE48515BDFC09B8347DAC5FD2C0165AA765916457DC7B057E526785AC912481CB72F118D2943372213B23CE3C39739263C2B3DA4DBFEB24C522ACC0439D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_PA DATE_FORMAT "%m/%d/%Y".. ::msgcat::mcset es_PA TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_PA DATE_TIME_FORMAT "%m/%d/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.90959433688075
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoIgzvFjoQ9X3v6ry/5oI9+3v9f6HyFvn:4EnLB383+zdB3v6ry/y3vMSVn
                                                                                                                                                                                                            MD5:5A5997D834DDD3E2E8FF8C6956AD54AC
                                                                                                                                                                                                            SHA1:AB4110E37B3665D738A8F2B3E64CBA9E99127301
                                                                                                                                                                                                            SHA-256:90C130B66958CF63CB3DDD2C633E58444357DBAB44C56831DD794CBD2EB1AED0
                                                                                                                                                                                                            SHA-512:1FEB8E77EA7B886E4A06279AC8A4B6200DBB86DCD28989651B92A0C9147A7BCFBB871DF8F904A1CF8F869BFFBD21325505AC44A4DBEBE1EFC87D43174597F1F3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_PE DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_PE TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_PE DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.905689521403511
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xo06GriSFjoeW3v6ry/5o06T+3vrig6HyFvn:4EnLB383gG+263v6ry/gK3v+lSVn
                                                                                                                                                                                                            MD5:CE811BB8D12C7E6D53338759CCFB0A22
                                                                                                                                                                                                            SHA1:0AED290AA479DE6887CCB58D3F0A0F379EF8D558
                                                                                                                                                                                                            SHA-256:F790E8E48DC079DCD7DEB58170561006A31294F7E4ACBF9CF2ABFA3DB9E3FA9E
                                                                                                                                                                                                            SHA-512:0C73654CC3D33F76D9BF545BD6C5E42CBDD10B6D9750BFD6536806010F3B6A3C3647FB9D5E7E75A39823FDB857E13D07B7F987809C94B9F980E6D3A6D3108E85
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_PR DATE_FORMAT "%m-%d-%Y".. ::msgcat::mcset es_PR TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_PR DATE_TIME_FORMAT "%m-%d-%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.917539255090736
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xo/5zvFjovE3v6ry/5o/a+3v9f6HyFvn:4EnLB383Czdt3v6ry/+3vMSVn
                                                                                                                                                                                                            MD5:9CD6FAC4121E3D287C87157142E32845
                                                                                                                                                                                                            SHA1:3081FE2197017EC8E052756A407880C1C4ED026A
                                                                                                                                                                                                            SHA-256:70263F7EB22822DFEE8849B7AC4418ED9331275A71E77236B59226396505CDFF
                                                                                                                                                                                                            SHA-512:25DC054085C4078734988EEDD87E31ABE93DA8B43512E924DE4BCDE9F8EC670436B72FAD1855484F9AC71DD0BEDD9ED30304D02219C4FFC4B0516D8889BDF9F9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_PY DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_PY TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_PY DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.929035824905457
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xofriSFjo3+3v6ry/5oY+3vrig6HyFvn:4EnLB383Y+22+3v6ry/Q3v+lSVn
                                                                                                                                                                                                            MD5:AF300EA6E733DC6820768EA16194B472
                                                                                                                                                                                                            SHA1:7766A6EB3D07BCC759CF6718EF3D6EC3FCE13565
                                                                                                                                                                                                            SHA-256:26A38B3745C95673D21BABB987F1D41EE08DDA945C670F5432BA0CE6F893C0E9
                                                                                                                                                                                                            SHA-512:C38D67C912584BE539D71881C6517AC186CBB336A160602DA716CE2708B2D38CE8FA7DD23EDB98890ABB7119B924B6C7816C18EC18F20C49D6284DF2386E32EE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_SV DATE_FORMAT "%m-%d-%Y".. ::msgcat::mcset es_SV TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_SV DATE_TIME_FORMAT "%m-%d-%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.923802447598272
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xooygzvFjooq9X3v6ry/5ooy9+3v9f6HyFvn:4EnLB3835rzdbsX3v6ry/5J3vMSVn
                                                                                                                                                                                                            MD5:2DC550FEC3F477B1159B824479BCE707
                                                                                                                                                                                                            SHA1:4D0B20CF3E50B64D74655A405A7750E0B0BB4375
                                                                                                                                                                                                            SHA-256:1291B58810739EA0651493DD7887F5EE3E14BDB806E06DD4BB8AE2520C742EDA
                                                                                                                                                                                                            SHA-512:B12B927ACA6274904928A6A6CAEC8339A794C74A1F1804FF93AABC132AF9AD8AC5117F20067A60EFEBC9887150D7ACA5BE9643FF61509666011FD203211C25B9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_UY DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_UY TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_UY DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.928484426267027
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoXrzvFjoXK3v6ry/5oXs+3v9f6HyFvn:4EnLB3838zdv3v6ry/c3vMSVn
                                                                                                                                                                                                            MD5:184D6C4B9F0AA874DEB959F63F7CC01B
                                                                                                                                                                                                            SHA1:5FB370B498289590C977F6B489FF646F0FB27425
                                                                                                                                                                                                            SHA-256:91191517403C712299919F9C797F952502E33CB6961D1DBEE3A7C9E8D2B170B9
                                                                                                                                                                                                            SHA-512:881CCAB0950AE993744ECCA141120C005F53D684167A3E5CBDDF950D110D630FB2B4F6AE6E3D0E06D5110AE25EA00A4F4DAFB03AD3B227DC8C63464D434431DA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset es_VE DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset es_VE TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset es_VE DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1258
                                                                                                                                                                                                            Entropy (8bit):4.391217201307309
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83P1Y2+1YoQVTsC/m48qpRTVTR7I/68qqq4Z0yoN7emG5wsvtqmsv5t:43P1p+1jQ9sq8y9v8Yko7emG5wKtqmKX
                                                                                                                                                                                                            MD5:C8C5EF2FA6DD8DBD5BBD2699BE1A0BF6
                                                                                                                                                                                                            SHA1:F5E26B40786B8987C98F9CBDEF5522043574A9ED
                                                                                                                                                                                                            SHA-256:4BEE224C21B0483CFF39BE145C671AA20CB7872C8727FD918C0E8ECA2BBEB172
                                                                                                                                                                                                            SHA-512:757FA85C137A11C1A3F4A8392C7A4E4030A67D0E593FA25A98BEC07DB295399AB2C0D9EBE61E07420B14387A29C060DC3AF812A1E7B85110DBB13C3C3DCB3600
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset et DAYS_OF_WEEK_ABBREV [list \.. "P"\.. "E"\.. "T"\.. "K"\.. "N"\.. "R"\.. "L"].. ::msgcat::mcset et DAYS_OF_WEEK_FULL [list \.. "p\u00fchap\u00e4ev"\.. "esmasp\u00e4ev"\.. "teisip\u00e4ev"\.. "kolmap\u00e4ev"\.. "neljap\u00e4ev"\.. "reede"\.. "laup\u00e4ev"].. ::msgcat::mcset et MONTHS_ABBREV [list \.. "Jaan"\.. "Veebr"\.. "M\u00e4rts"\.. "Apr"\.. "Mai"\.. "Juuni"\.. "Juuli"\.. "Aug"\.. "Sept"\.. "Okt"\.. "Nov"\.. "Dets"\.. ""].. ::msgcat::mcset et MONTHS_FULL [list \.. "Jaanuar"\.. "Veebruar"\.. "M\u00e4rts"\.. "Aprill"\.. "Mai"\.. "Juuni"\.. "Juuli"\.. "August"\.. "September"\.. "Oktoober"\.. "November"\.. "De
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1032
                                                                                                                                                                                                            Entropy (8bit):4.002617252503668
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83DEXk8TT7vXk8TTMtzCIsOo/ssP6tvf1I49sHT:434bTbbTc+RjKi4mz
                                                                                                                                                                                                            MD5:ED9805AF5BFB54EB28C6CB3975F86F5B
                                                                                                                                                                                                            SHA1:2BD91BD850028712F35A2DDB2555036FBF6E8114
                                                                                                                                                                                                            SHA-256:6889B57D29B670C6CFB7B5A3F2F1749D12C802E8E9629014D06CE23C034C7EF1
                                                                                                                                                                                                            SHA-512:16F31DE5D2B0D3ED2D975C7891C73C48F073CDAC28F17572FC9424C2D384DDFE9E5E235F17C788F42840CB2D819D2D9499B909AB80FEF1B09F2AE1627CF1DADC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset eu DAYS_OF_WEEK_ABBREV [list \.. "igandea"\.. "astelehena"\.. "asteartea"\.. "asteazkena"\.. "osteguna"\.. "ostirala"\.. "larunbata"].. ::msgcat::mcset eu DAYS_OF_WEEK_FULL [list \.. "igandea"\.. "astelehena"\.. "asteartea"\.. "asteazkena"\.. "osteguna"\.. "ostirala"\.. "larunbata"].. ::msgcat::mcset eu MONTHS_ABBREV [list \.. "urt"\.. "ots"\.. "mar"\.. "api"\.. "mai"\.. "eka"\.. "uzt"\.. "abu"\.. "ira"\.. "urr"\.. "aza"\.. "abe"\.. ""].. ::msgcat::mcset eu MONTHS_FULL [list \.. "urtarrila"\.. "otsaila"\.. "martxoa"\.. "apirila"\.. "maiatza"\.. "ekaina"\.. "uztaila"\.. "abuztua"\.. "iraila"\.. "urria"\.. "azaroa"\..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):294
                                                                                                                                                                                                            Entropy (8bit):4.915392589807169
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoszFnJF+l6VvBoszw3vLjoszw3v6mjosz++3v/RHvn:4EnLB383FL+l6VQ3vO3v6G3vZPn
                                                                                                                                                                                                            MD5:4C91AA000D4316585893025CBB96E910
                                                                                                                                                                                                            SHA1:3D4E73839A1A8CB9DEC1E59D9D2813257D9480F0
                                                                                                                                                                                                            SHA-256:D45CC432E5743E6CEC34E9A1E0F91A9D5C315CDA409E0826B51AD9D908479EB6
                                                                                                                                                                                                            SHA-512:0731F2EEB22ADC7EF8AF215B9EB4C5A66B33BC90E4F80CF7AA482AD002CB30543547230124A0507EC79EDDD6903A042EDA5D7C8AFD77F7FC994EFC6853FABB05
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset eu_ES DATE_FORMAT "%a, %Yeko %bren %da".. ::msgcat::mcset eu_ES TIME_FORMAT "%T".. ::msgcat::mcset eu_ES TIME_FORMAT_12 "%T".. ::msgcat::mcset eu_ES DATE_TIME_FORMAT "%y-%m-%d %T %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1711
                                                                                                                                                                                                            Entropy (8bit):4.21837106187395
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83CnMqnbxbGwgjSyiY/Xw2mS1yM/8ye48YyfNqTb2gyj/8yHkQp:43Yzyhgvs9yi4P
                                                                                                                                                                                                            MD5:7AB25F4E7E457469DC61A33176B3AA72
                                                                                                                                                                                                            SHA1:EEA98283D250A99E33DD4D5D9B1B76A029716CE6
                                                                                                                                                                                                            SHA-256:86898728B275288693B200568DC927C3FF5B9050690876C4441A8339DAE06386
                                                                                                                                                                                                            SHA-512:7524437F91E91751BEB7A378D7674C49E5D84B716FE962F4C23580C46A671F3F33638FCD37A8F90C86E24DA8F54448E06AC9C3AEFFB5613E94A04E512C1AD68D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fa DAYS_OF_WEEK_ABBREV [list \.. "\u06cc\u2214"\.. "\u062f\u2214"\.. "\u0633\u2214"\.. "\u0686\u2214"\.. "\u067e\u2214"\.. "\u062c\u2214"\.. "\u0634\u2214"].. ::msgcat::mcset fa DAYS_OF_WEEK_FULL [list \.. "\u06cc\u06cc\u200c\u0634\u0646\u0628\u0647"\.. "\u062f\u0648\u0634\u0646\u0628\u0647"\.. "\u0633\u0647\u200c\u0634\u0646\u0628\u0647"\.. "\u0686\u0647\u0627\u0631\u0634\u0646\u0628\u0647"\.. "\u067e\u0646\u062c\u200c\u0634\u0646\u0628\u0647"\.. "\u062c\u0645\u0639\u0647"\.. "\u0634\u0646\u0628\u0647"].. ::msgcat::mcset fa MONTHS_ABBREV [list \.. "\u0698\u0627\u0646"\.. "\u0641\u0648\u0631"\.. "\u0645\u0627\u0631"\.. "\u0622\u0648\u0631"\.. "\u0645\u0640\u0647"\.. "\u0698\u0648\u0646"\.. "\u0698\u0648\u06cc"\.. "\u0627\u0648\u062a
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2009
                                                                                                                                                                                                            Entropy (8bit):4.491667766230948
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83KnMqnbxbGUgjDiY/Xw2mS1yM/8ye48tfNqTb2gyj/8yHkQLoRv9v/vNv0P:43wihgvsai4Rmv53JU
                                                                                                                                                                                                            MD5:C59EE7CA80AD9F612A21C8B6674A820E
                                                                                                                                                                                                            SHA1:AEFD631EFC1892063244FA622DE1A091C461E370
                                                                                                                                                                                                            SHA-256:6B56545C1AE1DE53BC2389BB7AE59F115BADE24F907E384E079491DC77D6541D
                                                                                                                                                                                                            SHA-512:42F52091480599D317FB80DF8E52A6C6F88614C6172BF4033974DD136FB30E6F47D38982C8A7BC14CF3165C3EBAE3680F94DF3A0ED079AB68165286251CD0BD7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fa_IN DAYS_OF_WEEK_ABBREV [list \.. "\u06cc\u2214"\.. "\u062f\u2214"\.. "\u0633\u2214"\.. "\u0686\u2214"\.. "\u067e\u2214"\.. "\u062c\u2214"\.. "\u0634\u2214"].. ::msgcat::mcset fa_IN DAYS_OF_WEEK_FULL [list \.. "\u06cc\u06cc\u200c\u0634\u0646\u0628\u0647"\.. "\u062f\u0648\u0634\u0646\u0628\u0647"\.. "\u0633\u0647\u200c\u0634\u0646\u0628\u0647"\.. "\u0686\u0647\u0627\u0631\u0634\u0646\u0628\u0647"\.. "\u067e\u0646\u062c\u200c\u0634\u0646\u0628\u0647"\.. "\u062c\u0645\u0639\u0647"\.. "\u0634\u0646\u0628\u0647"].. ::msgcat::mcset fa_IN MONTHS_ABBREV [list \.. "\u0698\u0627\u0646"\.. "\u0641\u0648\u0631"\.. "\u0645\u0627\u0631"\.. "\u0622\u0648\u0631"\.. "\u0645\u0640\u0647"\.. "\u0698\u0648\u0646"\.. "\u0698\u0648\u06cc"\.. "\u0627\u0
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):426
                                                                                                                                                                                                            Entropy (8bit):5.12739029869254
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:4EnLB383D2WGz7A/3vy3v6TANCmK3vz7AAbn:4aR83DoPivkvFk5vPN
                                                                                                                                                                                                            MD5:9778A7C3ABD37ECBEC0BB9715E52FAF8
                                                                                                                                                                                                            SHA1:D8063CA7779674EB1D9FE3E4B4774DB20B93038B
                                                                                                                                                                                                            SHA-256:3D9779C27E8960143D00961F6E82124120FD47B7F3CB82DB3DF21CDD9090C707
                                                                                                                                                                                                            SHA-512:B90B4A96CE5E8B9BF512B98C406603C60EA00F6740D04CD1FC30810C7155A37851AE5E28716F959137806F1A9E3152D2A0D79B8EA7E681A0737A28593657DE66
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fa_IR AM "\u0635\u0628\u062d".. ::msgcat::mcset fa_IR PM "\u0639\u0635\u0631".. ::msgcat::mcset fa_IR DATE_FORMAT "%d\u2044%m\u2044%Y".. ::msgcat::mcset fa_IR TIME_FORMAT "%S:%M:%H".. ::msgcat::mcset fa_IR TIME_FORMAT_12 "%S:%M:%l %P".. ::msgcat::mcset fa_IR DATE_TIME_FORMAT "%d\u2044%m\u2044%Y %S:%M:%H %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1195
                                                                                                                                                                                                            Entropy (8bit):4.32217771842326
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83KTvIhmuw4tW/UWJTttWKeqA+3ewvtyv3e6:43YvIwuw4t05ttnlzt0p
                                                                                                                                                                                                            MD5:CC06F0ABD8F985654DAD8256598EBCB7
                                                                                                                                                                                                            SHA1:71C880F9F395ACD32AF7F538033211F392F83645
                                                                                                                                                                                                            SHA-256:9929A6B7139BD7E0F29487F7888A83E4C4F5E9CE0352738CFCA94EE2DDF3BD6B
                                                                                                                                                                                                            SHA-512:E1292665270B6FBF7738CC3864B55194E7B827C6AD9492FB2E54DC1B626159B243052CE502335B9D92E2B8F58A4DD1FA0E628CB6A9D1D3A652FE2B93A3FB711A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fi DAYS_OF_WEEK_ABBREV [list \.. "su"\.. "ma"\.. "ti"\.. "ke"\.. "to"\.. "pe"\.. "la"].. ::msgcat::mcset fi DAYS_OF_WEEK_FULL [list \.. "sunnuntai"\.. "maanantai"\.. "tiistai"\.. "keskiviikko"\.. "torstai"\.. "perjantai"\.. "lauantai"].. ::msgcat::mcset fi MONTHS_ABBREV [list \.. "tammi"\.. "helmi"\.. "maalis"\.. "huhti"\.. "touko"\.. "kes\u00e4"\.. "hein\u00e4"\.. "elo"\.. "syys"\.. "loka"\.. "marras"\.. "joulu"\.. ""].. ::msgcat::mcset fi MONTHS_FULL [list \.. "tammikuu"\.. "helmikuu"\.. "maaliskuu"\.. "huhtikuu"\.. "toukokuu"\.. "kes\u00e4kuu"\.. "hein\u00e4kuu"\.. "elokuu"\.. "syyskuu"\.. "lokakuu"\.. "marraskuu"\..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1033
                                                                                                                                                                                                            Entropy (8bit):4.15884265510429
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR834YPxTSBFSa+E6rIsmYmyAxyIQbXHU92W1T:43a6rIyAE0B
                                                                                                                                                                                                            MD5:5D224E66FD9521CA4327D4F164CD6585
                                                                                                                                                                                                            SHA1:FC8F4C1D9A69931679028DE02155D96A18F6542E
                                                                                                                                                                                                            SHA-256:2EC9B03469FA38B260915C93318F446EA5E12B9090BD441936B57552EBA1E3C9
                                                                                                                                                                                                            SHA-512:0E0F97D99F0274A8A92AA7DC992B252A0BB696D69A8835602D8F4C03A6A15780F45971F00863436949CD81AD7DF6EE6BC463CE5B9FECF5E39508BA4D4E83C693
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fo DAYS_OF_WEEK_ABBREV [list \.. "sun"\.. "m\u00e1n"\.. "t\u00fds"\.. "mik"\.. "h\u00f3s"\.. "fr\u00ed"\.. "ley"].. ::msgcat::mcset fo DAYS_OF_WEEK_FULL [list \.. "sunnudagur"\.. "m\u00e1nadagur"\.. "t\u00fdsdagur"\.. "mikudagur"\.. "h\u00f3sdagur"\.. "fr\u00edggjadagur"\.. "leygardagur"].. ::msgcat::mcset fo MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "mai"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "des"\.. ""].. ::msgcat::mcset fo MONTHS_FULL [list \.. "januar"\.. "februar"\.. "mars"\.. "apr\u00edl"\.. "mai"\.. "juni"\.. "juli"\.. "august"\.. "september"\.. "oktober"\.. "november"\..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):286
                                                                                                                                                                                                            Entropy (8bit):4.864028070948858
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoZA4WjoZd3vLjoZd3v6mjoZd+3vnFDoAkvn:4EnLB3831P23vS3v6u3v9dmn
                                                                                                                                                                                                            MD5:92E2B6483B2374817548F4EAA1731820
                                                                                                                                                                                                            SHA1:071E1E9368CCB4EC864E78622B2113F460920203
                                                                                                                                                                                                            SHA-256:C3DCCF5E5904C24D4AD9AAA36160A78F5397A7452510C0C0E61DE4DE863305CB
                                                                                                                                                                                                            SHA-512:E79D4D38A22298252FA46D15C383CFB2A1E49E8196C265A58F9BA4982DFD9CE29E87C0B85BE3F39617359451831B792FCD3092A52EDF8FFD999AFE5CFE1D170D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fo_FO DATE_FORMAT "%d/%m-%Y".. ::msgcat::mcset fo_FO TIME_FORMAT "%T".. ::msgcat::mcset fo_FO TIME_FORMAT_12 "%T".. ::msgcat::mcset fo_FO DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1257
                                                                                                                                                                                                            Entropy (8bit):4.383721663740675
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR835LzAX2t6KOkPwzZIGzRmzQf1waGqHvivh:43mlwIFZtA/qPkh
                                                                                                                                                                                                            MD5:4D63B4A7CF13A28A6F6784B5597EEF43
                                                                                                                                                                                                            SHA1:FE1B35A93CB72666D7D6BC37D9BE081B05A00CD9
                                                                                                                                                                                                            SHA-256:96B1E1E12CD13A56722EBF27D362C70B467342FA1282A40B89FB16B5105A0480
                                                                                                                                                                                                            SHA-512:5647CAE859B62C7CE1CEE6426A076361D2A29EFE6B6F311DDC0E7D006194BA68D575852FEC5FDE2AB43DF8AE440C57013D32A3951095CB856327070FD9BD1C76
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fr DAYS_OF_WEEK_ABBREV [list \.. "dim."\.. "lun."\.. "mar."\.. "mer."\.. "jeu."\.. "ven."\.. "sam."].. ::msgcat::mcset fr DAYS_OF_WEEK_FULL [list \.. "dimanche"\.. "lundi"\.. "mardi"\.. "mercredi"\.. "jeudi"\.. "vendredi"\.. "samedi"].. ::msgcat::mcset fr MONTHS_ABBREV [list \.. "janv."\.. "f\u00e9vr."\.. "mars"\.. "avr."\.. "mai"\.. "juin"\.. "juil."\.. "ao\u00fbt"\.. "sept."\.. "oct."\.. "nov."\.. "d\u00e9c."\.. ""].. ::msgcat::mcset fr MONTHS_FULL [list \.. "janvier"\.. "f\u00e9vrier"\.. "mars"\.. "avril"\.. "mai"\.. "juin"\.. "juillet"\.. "ao\u00fbt"\.. "septembre"\.. "octobre"\.. "novembre"\.. "d\u00e9cembre
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):286
                                                                                                                                                                                                            Entropy (8bit):4.910112619660625
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoXqyFjoIX3vLjoIX3v6mjog+3vnFDoAkvn:4EnLB383AqWv3vL3v6d3v9dmn
                                                                                                                                                                                                            MD5:07EEADB8C2F2425FF9A27E46A81827A2
                                                                                                                                                                                                            SHA1:AA18A651C64098C7885F1F869B9F221453F42987
                                                                                                                                                                                                            SHA-256:AAD828BCBB512FBD9902DCDD3812247A74913CC574DEB07DA95A7BBE74B1FE48
                                                                                                                                                                                                            SHA-512:1FA60B1A69B2F5FD2C009EC18695A937C4484D7C418F7E8398D95723B857698143E0584A546F9032B75894730CBBEF78453061AC13D90199FF702E148D983C28
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fr_BE DATE_FORMAT "%d/%m/%y".. ::msgcat::mcset fr_BE TIME_FORMAT "%T".. ::msgcat::mcset fr_BE TIME_FORMAT_12 "%T".. ::msgcat::mcset fr_BE DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):286
                                                                                                                                                                                                            Entropy (8bit):4.890376345610709
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xooIso13vLjo13v6mjo1+3vnFDoAkvn:4EnLB383vIF3vU3v6A3v9dmn
                                                                                                                                                                                                            MD5:2F70BDDE7685E2892C5F79C632FC2F0F
                                                                                                                                                                                                            SHA1:FD1A6F6042E59D1563ABB5858C348C1D785C435E
                                                                                                                                                                                                            SHA-256:0624DF9A56723DDB89E59736C20A5837DEA2206A789EBE7EEF19AD287590CA45
                                                                                                                                                                                                            SHA-512:50FC0C91AB2C75FFC4F100C0D42DFC4B2101DB9713FD77E6FF5BF3F25A0AF4A535A4709CF4586809CEEE76C25B66ABC0DD4FD61524510C57AA0E63EA8F46E8D5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fr_CA DATE_FORMAT "%Y-%m-%d".. ::msgcat::mcset fr_CA TIME_FORMAT "%T".. ::msgcat::mcset fr_CA TIME_FORMAT_12 "%T".. ::msgcat::mcset fr_CA DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):288
                                                                                                                                                                                                            Entropy (8bit):4.913241133684606
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoFt28oF+3vLjoF+3v6mjo++3vnFDoAkvn:4EnLB383yte+3vs+3v6/3v9dmn
                                                                                                                                                                                                            MD5:83FC7EBA68C3727F7C13C8EEAF79823F
                                                                                                                                                                                                            SHA1:81C27F9B97F5F5190F7189230535EC09CD228158
                                                                                                                                                                                                            SHA-256:290CA6EB74BAEAC4E2420D0755D148849F89EE87E37860F25CBB7B8AFA3EDCBC
                                                                                                                                                                                                            SHA-512:35DA46558A246D7B3FAB02208001CE986E2E6DD88D6318AF743F4E81CA6920471D1425BB009A7476A79E7F61E1353C027B765331CD8EFA07A9E884DCB73F2195
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset fr_CH DATE_FORMAT "%d. %m. %y".. ::msgcat::mcset fr_CH TIME_FORMAT "%T".. ::msgcat::mcset fr_CH TIME_FORMAT_12 "%T".. ::msgcat::mcset fr_CH DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1188
                                                                                                                                                                                                            Entropy (8bit):4.314271783103334
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR835k0CM/hlrXa754pD73/tKSx54pbIK5f2CA:43W05rXUa173/VadDA
                                                                                                                                                                                                            MD5:67D137E5D853DB61A4B4264871E793F7
                                                                                                                                                                                                            SHA1:4280E7F662DE792175AF8B4C93874F035F716F0F
                                                                                                                                                                                                            SHA-256:880806867ACABD9B39E3029A5ADD26B690CC5709082D43B0959EBA725EA07AB5
                                                                                                                                                                                                            SHA-512:C27B745143539D3E6D94BB754DCA35065CDE9B1AA6EE038D47F658175CFACC20236124D38BE5BBB03CAF8F613BD748C43CB8DFCC9234E915D18B5A477BAEF94E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ga DAYS_OF_WEEK_ABBREV [list \.. "Domh"\.. "Luan"\.. "M\u00e1irt"\.. "C\u00e9ad"\.. "D\u00e9ar"\.. "Aoine"\.. "Sath"].. ::msgcat::mcset ga DAYS_OF_WEEK_FULL [list \.. "D\u00e9 Domhnaigh"\.. "D\u00e9 Luain"\.. "D\u00e9 M\u00e1irt"\.. "D\u00e9 C\u00e9adaoin"\.. "D\u00e9ardaoin"\.. "D\u00e9 hAoine"\.. "D\u00e9 Sathairn"].. ::msgcat::mcset ga MONTHS_ABBREV [list \.. "Ean"\.. "Feabh"\.. "M\u00e1rta"\.. "Aib"\.. "Beal"\.. "Meith"\.. "I\u00fail"\.. "L\u00fan"\.. "MF\u00f3mh"\.. "DF\u00f3mh"\.. "Samh"\.. "Noll"\.. ""].. ::msgcat::mcset ga MONTHS_FULL [list \.. "Ean\u00e1ir"\.. "Feabhra"\.. "M\u00e1rta"\.. "Aibre\u00e1n"\.. "M\u00ed na Bealtaine"\.. "Meith"\..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):265
                                                                                                                                                                                                            Entropy (8bit):4.818053174805798
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoChFfluoChF+3v6xyFjoCh++3vflm68vn:4EnLB383xPflwe3v6gZl3vflm6+n
                                                                                                                                                                                                            MD5:A02F11BE0DF920E63E7A3ACCE746E32D
                                                                                                                                                                                                            SHA1:4A8B1EF1A6F8A5FD022042D6E009A01E4B0FEBD3
                                                                                                                                                                                                            SHA-256:F5B859D8DD2A2B5F756E39B0DFEB26B95878D2F54BA3CE46C56F0F26CF2B554B
                                                                                                                                                                                                            SHA-512:5F9AF8C89F491CB4C158ED73EA4CF32E6A83CF44A94DA6FE1A962C58199BF2348530F3DEFA0C6F433BA3ADEF81AE9B3884F30CD7A841B159D52F9F21008B4F92
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ms_MY DATE_FORMAT "%A %d %b %Y".. ::msgcat::mcset ms_MY TIME_FORMAT_12 "%I:%M:%S %z".. ::msgcat::mcset ms_MY DATE_TIME_FORMAT "%A %d %b %Y %I:%M:%S %z %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):717
                                                                                                                                                                                                            Entropy (8bit):4.55153350337982
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:4EnLB383VYmxWHWog4QUbxMmAMMiGZu+3v6ay/GK3vZsSVn:4aR83VYsxonQ2MmVVGRvjCGsvGSV
                                                                                                                                                                                                            MD5:D8BBEC2F8935054E6081BB5E4AE8F7E3
                                                                                                                                                                                                            SHA1:33FE6D51A284B8760BC6F442329B10374F506BDA
                                                                                                                                                                                                            SHA-256:7DBC4E82D82FDE8CDF522FA10E082289D46B0C1A4A7D7A5FA83FF116677F052B
                                                                                                                                                                                                            SHA-512:BF39C75DD6B3625897D7D44AC253AF5656CA21D0B394F78611584E2606CBC419C4A02353542D23393BEBCCF0CB4D861CDECD61AD89339F78C0260E966B495777
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset mt DAYS_OF_WEEK_ABBREV [list \.. "\u0126ad"\.. "Tne"\.. "Tli"\.. "Erb"\.. "\u0126am"\.. "\u0120im"].. ::msgcat::mcset mt MONTHS_ABBREV [list \.. "Jan"\.. "Fra"\.. "Mar"\.. "Apr"\.. "Mej"\.. "\u0120un"\.. "Lul"\.. "Awi"\.. "Set"\.. "Ott"\.. "Nov"].. ::msgcat::mcset mt BCE "QK".. ::msgcat::mcset mt CE "".. ::msgcat::mcset mt DATE_FORMAT "%A, %e ta %B, %Y".. ::msgcat::mcset mt TIME_FORMAT_12 "%l:%M:%S %P".. ::msgcat::mcset mt DATE_TIME_FORMAT "%A, %e ta %B, %Y %l:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1209
                                                                                                                                                                                                            Entropy (8bit):4.313626715960843
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83B0tSYuZrIsmYmPAxyIQ4HU92W16EL3Tvav31:43qhuZrIPAt04yTcF
                                                                                                                                                                                                            MD5:42D02C3CAF28BE4994F27CEF5A183AB7
                                                                                                                                                                                                            SHA1:DC411E8AC12C3D588AB2F3A3C95A75D8689AD402
                                                                                                                                                                                                            SHA-256:534C5DACEF12F818FAF4ED806997A559F95D591F1B6236B0C30B07A107DD13F3
                                                                                                                                                                                                            SHA-512:0BE27572106324FE2B6CDFF4513500DE7582AD1ABEF451FFC62B2050D3875A149DDDB66451E1B3F5BA9216268E9998D2A1C1E8343BBB9EF97947DA054B82818E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset nb DAYS_OF_WEEK_ABBREV [list \.. "s\u00f8"\.. "ma"\.. "ti"\.. "on"\.. "to"\.. "fr"\.. "l\u00f8"].. ::msgcat::mcset nb DAYS_OF_WEEK_FULL [list \.. "s\u00f8ndag"\.. "mandag"\.. "tirsdag"\.. "onsdag"\.. "torsdag"\.. "fredag"\.. "l\u00f8rdag"].. ::msgcat::mcset nb MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "mai"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "des"\.. ""].. ::msgcat::mcset nb MONTHS_FULL [list \.. "januar"\.. "februar"\.. "mars"\.. "april"\.. "mai"\.. "juni"\.. "juli"\.. "august"\.. "september"\.. "oktober"\.. "november"\.. "desember"\.. ""].. ::msgcat::mcset nb BC
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1129
                                                                                                                                                                                                            Entropy (8bit):4.235969198645435
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR837Ed+RxRMZZsmUmnZAEEHM92WFU5vtrvs:43AAHRMZZPnZALsCtt7s
                                                                                                                                                                                                            MD5:B9B949794203D204628D4DBEA29587AE
                                                                                                                                                                                                            SHA1:1642D8040144469B5C359E80693E68036F87B849
                                                                                                                                                                                                            SHA-256:9E2FE3851CF13EC79A9B10A09B01CEB0A26044AE0DC90A4E00BE57745E854C79
                                                                                                                                                                                                            SHA-512:0CCCCF6D61423CEE0389C3BA1A8E94F2B092C53465D1937F5595AF91E46DD38B318D6C7EE3D88B89F32BFB952C0D55E0E67B46D7DF306ECA6690E283ADEB2CB9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset nl DAYS_OF_WEEK_ABBREV [list \.. "zo"\.. "ma"\.. "di"\.. "wo"\.. "do"\.. "vr"\.. "za"].. ::msgcat::mcset nl DAYS_OF_WEEK_FULL [list \.. "zondag"\.. "maandag"\.. "dinsdag"\.. "woensdag"\.. "donderdag"\.. "vrijdag"\.. "zaterdag"].. ::msgcat::mcset nl MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mrt"\.. "apr"\.. "mei"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset nl MONTHS_FULL [list \.. "januari"\.. "februari"\.. "maart"\.. "april"\.. "mei"\.. "juni"\.. "juli"\.. "augustus"\.. "september"\.. "oktober"\.. "november"\.. "december"\.. ""].. ::msgcat::mcset nl DATE_FORM
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):286
                                                                                                                                                                                                            Entropy (8bit):4.865165930946383
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xo4gPPdjog9X3vLjog9X3v6mjo49+3vnFDoAkvn:4EnLB3835gHdPF3vjF3v64I3v9dmn
                                                                                                                                                                                                            MD5:3261F397ED0291368FF1881E7BA08ECE
                                                                                                                                                                                                            SHA1:7147ABB62034EB152B1FED9246A533535F07372C
                                                                                                                                                                                                            SHA-256:77A69DD60D171B321512B14794E75A66FF753410C007997B310790D86E09B057
                                                                                                                                                                                                            SHA-512:C1526F454FA594DAD056B056F76F01D8B2AB713D04EB2A3643416B8E741B248CC94E000BAEE5B0F60436B88B1216FB1DE7F7C3FA456D4A4FBDE24F97C3B739B8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset nl_BE DATE_FORMAT "%d-%m-%y".. ::msgcat::mcset nl_BE TIME_FORMAT "%T".. ::msgcat::mcset nl_BE TIME_FORMAT_12 "%T".. ::msgcat::mcset nl_BE DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1200
                                                                                                                                                                                                            Entropy (8bit):4.282788574144479
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83tCtrJwuQrIsmYmLAxyIQ4HU92W1W4/3Hv+v31:434suQrILAt0EafIF
                                                                                                                                                                                                            MD5:985E97517C2BF37719A618F575DF392C
                                                                                                                                                                                                            SHA1:65BC07FC3A955300ED09B7485F90AEC18CBAD43F
                                                                                                                                                                                                            SHA-256:06FA2D6D8C59D0B8EAC2EDE5AB0DDB8B6E095D1A023B1966FCE3B65916FA14FB
                                                                                                                                                                                                            SHA-512:75BC14DBAD147A98D32D2AF0BE0BE50F115BB9C3BBE283B53977B9F264A055734B30F6B1C4EEE9686F1874D178C535111731C92D495B7D370FB17213B65C9A40
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset nn DAYS_OF_WEEK_ABBREV [list \.. "su"\.. "m\u00e5"\.. "ty"\.. "on"\.. "to"\.. "fr"\.. "lau"].. ::msgcat::mcset nn DAYS_OF_WEEK_FULL [list \.. "sundag"\.. "m\u00e5ndag"\.. "tysdag"\.. "onsdag"\.. "torsdag"\.. "fredag"\.. "laurdag"].. ::msgcat::mcset nn MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "mai"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "des"\.. ""].. ::msgcat::mcset nn MONTHS_FULL [list \.. "januar"\.. "februar"\.. "mars"\.. "april"\.. "mai"\.. "juni"\.. "juli"\.. "august"\.. "september"\.. "oktober"\.. "november"\.. "desember"\.. ""].. ::msgcat::mcset nn BCE "f.Kr."
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1263
                                                                                                                                                                                                            Entropy (8bit):4.459506202908786
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83lUj0ORGgIzdW6RDYKG7FwRc0ypvOvX:43+HMg2W6RDYnFwRc0ydYX
                                                                                                                                                                                                            MD5:79AB7C13AA3833A1DAEADDB1144CCE55
                                                                                                                                                                                                            SHA1:C01ABC2F16549CAEC6B081448B2CBA88A680E250
                                                                                                                                                                                                            SHA-256:61462C325DB0065352D8155307F949869862A86CAC67AD7BB6703F57A7FA2FF3
                                                                                                                                                                                                            SHA-512:79EB696164FDDD9B121558C2780E54E295FF2DC4D8E87A0DE507B4F2925612721A98FF5010199CB68CF894ACA7A07884E9E02F3DC1E078D241431E3DC884C0A1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset pl DAYS_OF_WEEK_ABBREV [list \.. "N"\.. "Pn"\.. "Wt"\.. "\u015ar"\.. "Cz"\.. "Pt"\.. "So"].. ::msgcat::mcset pl DAYS_OF_WEEK_FULL [list \.. "niedziela"\.. "poniedzia\u0142ek"\.. "wtorek"\.. "\u015broda"\.. "czwartek"\.. "pi\u0105tek"\.. "sobota"].. ::msgcat::mcset pl MONTHS_ABBREV [list \.. "sty"\.. "lut"\.. "mar"\.. "kwi"\.. "maj"\.. "cze"\.. "lip"\.. "sie"\.. "wrz"\.. "pa\u017a"\.. "lis"\.. "gru"\.. ""].. ::msgcat::mcset pl MONTHS_FULL [list \.. "stycze\u0144"\.. "luty"\.. "marzec"\.. "kwiecie\u0144"\.. "maj"\.. "czerwiec"\.. "lipiec"\.. "sierpie\u0144"\.. "wrzesie\u0144"\.. "pa\u017adziernik"\.. "listopad"\..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1177
                                                                                                                                                                                                            Entropy (8bit):4.394980756969744
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83CYkjBc1yHYJt//0/I31YMY47flV7YaqgCyt9Fo8g6Gtvt76svi:43C5LHcNnxJ9Ltg6Gpt76Ki
                                                                                                                                                                                                            MD5:8F53B3571DD29E12BD33349CFA32F28F
                                                                                                                                                                                                            SHA1:C125E059B8BFE5FECD482D1A1DA50B8678872BF6
                                                                                                                                                                                                            SHA-256:6F6EEEDDCF232BDCB952592A144810CED44A1CBB4BCC2C062D5F98D441505380
                                                                                                                                                                                                            SHA-512:5CD7E7097B720E5399795126A71348816CBA697FD8F14160779E982ADAB00D5994978E2F9445785B0DE62F6F14232278AD1A65BC53730CA58D676B057F0BC406
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset pt DAYS_OF_WEEK_ABBREV [list \.. "Dom"\.. "Seg"\.. "Ter"\.. "Qua"\.. "Qui"\.. "Sex"\.. "S\u00e1b"].. ::msgcat::mcset pt DAYS_OF_WEEK_FULL [list \.. "Domingo"\.. "Segunda-feira"\.. "Ter\u00e7a-feira"\.. "Quarta-feira"\.. "Quinta-feira"\.. "Sexta-feira"\.. "S\u00e1bado"].. ::msgcat::mcset pt MONTHS_ABBREV [list \.. "Jan"\.. "Fev"\.. "Mar"\.. "Abr"\.. "Mai"\.. "Jun"\.. "Jul"\.. "Ago"\.. "Set"\.. "Out"\.. "Nov"\.. "Dez"\.. ""].. ::msgcat::mcset pt MONTHS_FULL [list \.. "Janeiro"\.. "Fevereiro"\.. "Mar\u00e7o"\.. "Abril"\.. "Maio"\.. "Junho"\.. "Julho"\.. "Agosto"\.. "Setembro"\.. "Outubro"\.. "Novembro"\.. "Dezembro"
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):286
                                                                                                                                                                                                            Entropy (8bit):4.8608779725401785
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xofm6GPWWjofAW3vLjofAW3v6mjofm6T+3vnFDoAkvn:4EnLB383+NGdg93vk93v6fNK3v9dmn
                                                                                                                                                                                                            MD5:A2626EA95C2480FEA68906AE6A1F6993
                                                                                                                                                                                                            SHA1:A0592902337C00FC2E70B1DFB3A42453A86535BB
                                                                                                                                                                                                            SHA-256:320BE7D5B730091E6FA35F196314737261C8E154577DCF6AC8C2057D44394AD7
                                                                                                                                                                                                            SHA-512:9801A87D024565676D4F3EAF0702C213E59FC2B6719D8BE95C19C9ED53FC43487F65F5408378B401A2B4C2BD4E2E391C2D848CA87739A6082AB7766EC6B9EFE1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset pt_BR DATE_FORMAT "%d-%m-%Y".. ::msgcat::mcset pt_BR TIME_FORMAT "%T".. ::msgcat::mcset pt_BR TIME_FORMAT_12 "%T".. ::msgcat::mcset pt_BR DATE_TIME_FORMAT "%a %d %b %Y %T %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1224
                                                                                                                                                                                                            Entropy (8bit):4.350784108088039
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83coPUMSeZmkTMm41icpK+7ZVoImEcVUCWdvHvWIn:43lPHFmkm1iMVoxEc+CWZPWIn
                                                                                                                                                                                                            MD5:F6575EC17966320106FF7ABDFB3186E2
                                                                                                                                                                                                            SHA1:68C6B72D664FDA27450FCE8B5734AB627CE825D7
                                                                                                                                                                                                            SHA-256:25ED6AC7A353E23B954B98611AE3B7E56BDCF2B0CB0DB358253CFB8BEBBB831C
                                                                                                                                                                                                            SHA-512:E564543231922A17C898419545BFA65E5E31FE9F005FDD201B735CFDE08E96FB3B98349C2A7959E29CA8F7E6934B0C4C6DE6B5E67209D0DD9A7746DFEBF037B3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ro DAYS_OF_WEEK_ABBREV [list \.. "D"\.. "L"\.. "Ma"\.. "Mi"\.. "J"\.. "V"\.. "S"].. ::msgcat::mcset ro DAYS_OF_WEEK_FULL [list \.. "duminic\u0103"\.. "luni"\.. "mar\u0163i"\.. "miercuri"\.. "joi"\.. "vineri"\.. "s\u00eemb\u0103t\u0103"].. ::msgcat::mcset ro MONTHS_ABBREV [list \.. "Ian"\.. "Feb"\.. "Mar"\.. "Apr"\.. "Mai"\.. "Iun"\.. "Iul"\.. "Aug"\.. "Sep"\.. "Oct"\.. "Nov"\.. "Dec"\.. ""].. ::msgcat::mcset ro MONTHS_FULL [list \.. "ianuarie"\.. "februarie"\.. "martie"\.. "aprilie"\.. "mai"\.. "iunie"\.. "iulie"\.. "august"\.. "septembrie"\.. "octombrie"\.. "noiembrie"\.. "decembrie"\.. ""].. ::msgcat:
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2091
                                                                                                                                                                                                            Entropy (8bit):4.2886524607041006
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:43D+pQ7keidQfRQPgQHB81Z/sFIAZSQWQXQrQxJQjQRnQBFQiWftkWt:26pgkeoSnpjA4tMYiJcCMFmVRt
                                                                                                                                                                                                            MD5:9F1C8DD58550558977821FD500E7C0E0
                                                                                                                                                                                                            SHA1:EFDD809BC2872A5BE0E353D31BE6D7D72E4B829C
                                                                                                                                                                                                            SHA-256:BB35BB6F07BAEF72C329EC3E95D6527A2736070EE2FFE5DE227E1FF0332390F8
                                                                                                                                                                                                            SHA-512:AA3C5C40AE9D342F8287958355C3321CF60566AD3E84E3D18D782FC022A998DA275506A61010A65D2E7D7578F2919C47C63AB0BA63A38800AA48D4B88ACE54D3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ru DAYS_OF_WEEK_ABBREV [list \.. "\u0412\u0441"\.. "\u041f\u043d"\.. "\u0412\u0442"\.. "\u0421\u0440"\.. "\u0427\u0442"\.. "\u041f\u0442"\.. "\u0421\u0431"].. ::msgcat::mcset ru DAYS_OF_WEEK_FULL [list \.. "\u0432\u043e\u0441\u043a\u0440\u0435\u0441\u0435\u043d\u044c\u0435"\.. "\u043f\u043e\u043d\u0435\u0434\u0435\u043b\u044c\u043d\u0438\u043a"\.. "\u0432\u0442\u043e\u0440\u043d\u0438\u043a"\.. "\u0441\u0440\u0435\u0434\u0430"\.. "\u0447\u0435\u0442\u0432\u0435\u0440\u0433"\.. "\u043f\u044f\u0442\u043d\u0438\u0446\u0430"\.. "\u0441\u0443\u0431\u0431\u043e\u0442\u0430"].. ::msgcat::mcset ru MONTHS_ABBREV [list \.. "\u044f\u043d\u0432"\.. "\u0444\u0435\u0432"\.. "\u043c\u0430\u0440"\.. "\u0430\u043f\u0440"\.. "\u043c\u0430\u0439"\.. "\u0438\u044e\u
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):248
                                                                                                                                                                                                            Entropy (8bit):4.9420431225061
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoVAgWIZoVY9X3vtfNrsoVA9+3vW6Q9vn:4EnLB383SFWIyaX3vtNl/3vWHNn
                                                                                                                                                                                                            MD5:DC98D88964650E302BE97FDB3B33326E
                                                                                                                                                                                                            SHA1:1DDDCC4265D7B980B867FEE674BEF2FD87D823F7
                                                                                                                                                                                                            SHA-256:13E4E79A0ED82034BADE0CFF8DEF5DE1222F6968108AD710662BDB7DAF36D7E1
                                                                                                                                                                                                            SHA-512:F3B9D528C529DD520FEDA3C20ED354E521C5B3C29F3317E15B7939CE06A3D67554D34DD6E54FE038585E46C560C604A1FD7E7F84914086B5994D52CE2C9E99CE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ru_UA DATE_FORMAT "%d.%m.%Y".. ::msgcat::mcset ru_UA TIME_FORMAT "%k:%M:%S".. ::msgcat::mcset ru_UA DATE_TIME_FORMAT "%d.%m.%Y %k:%M:%S %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1212
                                                                                                                                                                                                            Entropy (8bit):4.359036493565628
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83/YIXo4YY0dD6kMm7fX2NaSIvZdHZgHZ/IxvaGWxvtl9svWTN:43rLTR44/yWltOWB
                                                                                                                                                                                                            MD5:E297221FA73BD78577B398BC7D061D21
                                                                                                                                                                                                            SHA1:F2A6B456272F913A9E97C495CEE73AC774C90FA1
                                                                                                                                                                                                            SHA-256:E65D6E5E837DF0A2DF0DB77BCE45334BBC27EFFF9023C37119E75D49932D9D6C
                                                                                                                                                                                                            SHA-512:AB9DDAE7CB21193C7753041F0B88CF2D40987E7E604B47816219458D217F084AA4EBF36719E22AAB3FD71A271D9F956ADC353182991903D7ADE8C8F00F6B2F9B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sh DAYS_OF_WEEK_ABBREV [list \.. "Ned"\.. "Pon"\.. "Uto"\.. "Sre"\.. "\u010cet"\.. "Pet"\.. "Sub"].. ::msgcat::mcset sh DAYS_OF_WEEK_FULL [list \.. "Nedelja"\.. "Ponedeljak"\.. "Utorak"\.. "Sreda"\.. "\u010cetvrtak"\.. "Petak"\.. "Subota"].. ::msgcat::mcset sh MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "Mar"\.. "Apr"\.. "Maj"\.. "Jun"\.. "Jul"\.. "Avg"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Dec"\.. ""].. ::msgcat::mcset sh MONTHS_FULL [list \.. "Januar"\.. "Februar"\.. "Mart"\.. "April"\.. "Maj"\.. "Juni"\.. "Juli"\.. "Avgust"\.. "Septembar"\.. "Oktobar"\.. "Novembar"\.. "Decembar"\.. ""].. ::msgcat::mcset sh BC
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1255
                                                                                                                                                                                                            Entropy (8bit):4.4043119723436135
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83c46o40u3rIsmJIcm93ApLDVb2IcU95WFGEXF3eUCvtz/v3e6:43c3ow3rF93Ap7tEXFREtznp
                                                                                                                                                                                                            MD5:24DA40901D907D35195CC1B3A675EBC7
                                                                                                                                                                                                            SHA1:8AF31248F06FADA5CFB0D83A940CFF5CE70E2577
                                                                                                                                                                                                            SHA-256:976813F6C53C9BEBBF976B0F560FD7FC5E4EC4C574D7E1CD31F9A4056765CB7A
                                                                                                                                                                                                            SHA-512:A9BC6AAFE9AEEDFD1E483E54A2D27871A09ADD6807D8F90410CD2BB82A91BA9DF435652EC9A7C3AD0A080D7F153CA848BB47DAD3936BA30E4AEFF3C474C433CC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sk DAYS_OF_WEEK_ABBREV [list \.. "Ne"\.. "Po"\.. "Ut"\.. "St"\.. "\u0160t"\.. "Pa"\.. "So"].. ::msgcat::mcset sk DAYS_OF_WEEK_FULL [list \.. "Nede\u013ee"\.. "Pondelok"\.. "Utorok"\.. "Streda"\.. "\u0160tvrtok"\.. "Piatok"\.. "Sobota"].. ::msgcat::mcset sk MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "m\u00e1j"\.. "j\u00fan"\.. "j\u00fal"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset sk MONTHS_FULL [list \.. "janu\u00e1r"\.. "febru\u00e1r"\.. "marec"\.. "apr\u00edl"\.. "m\u00e1j"\.. "j\u00fan"\.. "j\u00fal"\.. "august"\.. "september"\.. "okt\u00f3ber"\.. "november"\.. "decem
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1216
                                                                                                                                                                                                            Entropy (8bit):4.333705818952628
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83MIXpC9opYuGS/BrIsmZ5hv1yAxyIVjd392WFThENvt0vJoO:43fXYujZrqyApYJtyR
                                                                                                                                                                                                            MD5:CB76F54CBE0D1AAE8BA956B4C51CBD2A
                                                                                                                                                                                                            SHA1:C1F78375EDB0BD2504553E33B2024C0C63FDB1B2
                                                                                                                                                                                                            SHA-256:11A6264676DBED87E4F718075127E32E107854F35F141642454F484984084486
                                                                                                                                                                                                            SHA-512:69964348FF08DE6EEB5E3DD61057FF0DF5441105EB7BEE7FB7E9AC5E26DCC164E3C7C011CA5CD7BC5B97A7872532331C97CCBC80563F6C5A3548014BFA8BEF16
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sl DAYS_OF_WEEK_ABBREV [list \.. "Ned"\.. "Pon"\.. "Tor"\.. "Sre"\.. "\u010cet"\.. "Pet"\.. "Sob"].. ::msgcat::mcset sl DAYS_OF_WEEK_FULL [list \.. "Nedelja"\.. "Ponedeljek"\.. "Torek"\.. "Sreda"\.. "\u010cetrtek"\.. "Petek"\.. "Sobota"].. ::msgcat::mcset sl MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "maj"\.. "jun"\.. "jul"\.. "avg"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset sl MONTHS_FULL [list \.. "januar"\.. "februar"\.. "marec"\.. "april"\.. "maj"\.. "junij"\.. "julij"\.. "avgust"\.. "september"\.. "oktober"\.. "november"\.. "december"\.. ""].. ::msgcat::mcset sl B
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1321
                                                                                                                                                                                                            Entropy (8bit):4.408176575111904
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83F7ONQEwXwjjTlVoSEh76W/X+WZQJ4hv+H6v2V:43NwjPEwl4VQ8q
                                                                                                                                                                                                            MD5:E606F620F03EC0FBDBE6551601299C5F
                                                                                                                                                                                                            SHA1:0B50AB679E8D90D8E7319BCADAC426E004594D3B
                                                                                                                                                                                                            SHA-256:1F4EFD78F6B45B65F73F09B2F52FC13C2A7C4138DCB7664804878D197B6EBDF9
                                                                                                                                                                                                            SHA-512:08AF2B51EB7111E334ADDA3A03F9A8816C104E9742B523EC363FB5131A3DF73D298A8DDCD573D23C23C65CCFD2B8898DF75AE3D4F04BF80744044FB6BAB5EC0A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sq DAYS_OF_WEEK_ABBREV [list \.. "Die"\.. "H\u00ebn"\.. "Mar"\.. "M\u00ebr"\.. "Enj"\.. "Pre"\.. "Sht"].. ::msgcat::mcset sq DAYS_OF_WEEK_FULL [list \.. "e diel"\.. "e h\u00ebn\u00eb"\.. "e mart\u00eb"\.. "e m\u00ebrkur\u00eb"\.. "e enjte"\.. "e premte"\.. "e shtun\u00eb"].. ::msgcat::mcset sq MONTHS_ABBREV [list \.. "Jan"\.. "Shk"\.. "Mar"\.. "Pri"\.. "Maj"\.. "Qer"\.. "Kor"\.. "Gsh"\.. "Sht"\.. "Tet"\.. "N\u00ebn"\.. "Dhj"\.. ""].. ::msgcat::mcset sq MONTHS_FULL [list \.. "janar"\.. "shkurt"\.. "mars"\.. "prill"\.. "maj"\.. "qershor"\.. "korrik"\.. "gusht"\.. "shtator"\.. "tetor"\.. "n\u00ebntor"\.. "dhjetor"\.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2087
                                                                                                                                                                                                            Entropy (8bit):4.307749748884122
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:43ilQTSBQrQP9QenzMKSFD9NI/QiNQEQrQL1KKYjU5rtAx:2I5EyLMKSFZNIYMzYMKKiqW
                                                                                                                                                                                                            MD5:BF363AB60B57F6D8FDCDBFD230A28DDF
                                                                                                                                                                                                            SHA1:6375CBA0A2197DA7E65BEE45C42F02C4F0B9142D
                                                                                                                                                                                                            SHA-256:FA00A7B22C9941F6C2B893F22B703DCB159CA2F2E4005FD6A74A632AEB786BFA
                                                                                                                                                                                                            SHA-512:91AD8085EF321A5A0E4D2ED204940CB66E8E230BBEDE59A8A07D1CEED9155FCC6B075A1FCC44AE834C1FEEEB3A59256C4310684C5AC453D4C50DFABD88469814
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sr DAYS_OF_WEEK_ABBREV [list \.. "\u041d\u0435\u0434"\.. "\u041f\u043e\u043d"\.. "\u0423\u0442\u043e"\.. "\u0421\u0440\u0435"\.. "\u0427\u0435\u0442"\.. "\u041f\u0435\u0442"\.. "\u0421\u0443\u0431"].. ::msgcat::mcset sr DAYS_OF_WEEK_FULL [list \.. "\u041d\u0435\u0434\u0435\u0459\u0430"\.. "\u041f\u043e\u043d\u0435\u0434\u0435\u0459\u0430\u043a"\.. "\u0423\u0442\u043e\u0440\u0430\u043a"\.. "\u0421\u0440\u0435\u0434\u0430"\.. "\u0427\u0435\u0442\u0432\u0440\u0442\u0430\u043a"\.. "\u041f\u0435\u0442\u0430\u043a"\.. "\u0421\u0443\u0431\u043e\u0442\u0430"].. ::msgcat::mcset sr MONTHS_ABBREV [list \.. "\u0408\u0430\u043d"\.. "\u0424\u0435\u0431"\.. "\u041c\u0430\u0440"\.. "\u0410\u043f\u0440"\.. "\u041c\u0430\u0458"\.. "\u0408\u0443\u043d"\.. "\
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1219
                                                                                                                                                                                                            Entropy (8bit):4.3542418837714285
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83qoLt6yLQoAusrIsmZ5m4AcjTHX92WFfjr4MvBvX:43ZLxQNusrr4Aw3Jkq1X
                                                                                                                                                                                                            MD5:3B5C3FFA0829768470BDA1B46D882060
                                                                                                                                                                                                            SHA1:C96799036EC5CCDE799A6B50CD7748908935A2F3
                                                                                                                                                                                                            SHA-256:483916B51BD7E071E88F9EC36AAF3E08FEA823991532F832DE491C6C40B55A9F
                                                                                                                                                                                                            SHA-512:684FA249123878AA7F856DF0FD3B0D9F041113CFEA8EEFA47D0E1948DA23694330BF0D62BA896A3891CD559C16CAE9330BF31508F530AC003D2929D5FD9246D8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sv DAYS_OF_WEEK_ABBREV [list \.. "s\u00f6"\.. "m\u00e5"\.. "ti"\.. "on"\.. "to"\.. "fr"\.. "l\u00f6"].. ::msgcat::mcset sv DAYS_OF_WEEK_FULL [list \.. "s\u00f6ndag"\.. "m\u00e5ndag"\.. "tisdag"\.. "onsdag"\.. "torsdag"\.. "fredag"\.. "l\u00f6rdag"].. ::msgcat::mcset sv MONTHS_ABBREV [list \.. "jan"\.. "feb"\.. "mar"\.. "apr"\.. "maj"\.. "jun"\.. "jul"\.. "aug"\.. "sep"\.. "okt"\.. "nov"\.. "dec"\.. ""].. ::msgcat::mcset sv MONTHS_FULL [list \.. "januari"\.. "februari"\.. "mars"\.. "april"\.. "maj"\.. "juni"\.. "juli"\.. "augusti"\.. "september"\.. "oktober"\.. "november"\.. "december"\.. ""].. ::msgcat:
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1040
                                                                                                                                                                                                            Entropy (8bit):4.108744949579904
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:4EnLB383A4mScvhkzoR4mtuWckRkoay3UVxMmALfG7IdzVJ633xRCPLMYMvYo76u:4aR83/Shkz1uckO76kMmEf62qOTdMvvn
                                                                                                                                                                                                            MD5:5774860C8AEECBD48F1502E616158CAB
                                                                                                                                                                                                            SHA1:DE7059713EA7913A0C79F5386833CE2BCAD2CFD7
                                                                                                                                                                                                            SHA-256:1DA068C9AA02EF14A2440758C6040D632D96044A20EC501DBB9E40D8592E0E7F
                                                                                                                                                                                                            SHA-512:91E69222DDF55E9E0E389DB77D7A0F2E082351DC3FB34A1A2C1E350E4187E8BB940F6C2EDE1B8651159C2787AA0BE4D7268F33F7A82CAED03514FCE462530408
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset sw DAYS_OF_WEEK_ABBREV [list \.. "Jpi"\.. "Jtt"\.. "Jnn"\.. "Jtn"\.. "Alh"\.. "Iju"\.. "Jmo"].. ::msgcat::mcset sw DAYS_OF_WEEK_FULL [list \.. "Jumapili"\.. "Jumatatu"\.. "Jumanne"\.. "Jumatano"\.. "Alhamisi"\.. "Ijumaa"\.. "Jumamosi"].. ::msgcat::mcset sw MONTHS_ABBREV [list \.. "Jan"\.. "Feb"\.. "Mar"\.. "Apr"\.. "Mei"\.. "Jun"\.. "Jul"\.. "Ago"\.. "Sep"\.. "Okt"\.. "Nov"\.. "Des"\.. ""].. ::msgcat::mcset sw MONTHS_FULL [list \.. "Januari"\.. "Februari"\.. "Machi"\.. "Aprili"\.. "Mei"\.. "Juni"\.. "Julai"\.. "Agosti"\.. "Septemba"\.. "Oktoba"\.. "Novemba"\.. "Desemba"\.. ""].. ::msgcat::mcset sw BCE "
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1874
                                                                                                                                                                                                            Entropy (8bit):4.080580566597515
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83AI0xnJdnQhmHlHYPKtul+eOPfIxyH5ztUSLu8tptLtrl+eOPfIxyH5ztUSU:43N0dQmHlHYPKtu1HxMtr1Hx/
                                                                                                                                                                                                            MD5:85288236C3997302EA26D7403BBA2C15
                                                                                                                                                                                                            SHA1:05AB389CC4DCF17B37BFF6ED1ECD58D6E9850A01
                                                                                                                                                                                                            SHA-256:AEFDC4255890D5B3FFE5CEE1B457B7D711283C2287ABA644155C10956012F6C1
                                                                                                                                                                                                            SHA-512:8E389D46606176EE14B8356153095B49C9426B80139B672A620F488891F091D1A272D4FB116775900E4AB4EC84DDDEBD8D6AF81AC672F14F148F2BFC638D2B10
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ta DAYS_OF_WEEK_FULL [list \.. "\u0b9e\u0bbe\u0baf\u0bbf\u0bb1\u0bc1"\.. "\u0ba4\u0bbf\u0b99\u0bcd\u0b95\u0bb3\u0bcd"\.. "\u0b9a\u0bc6\u0bb5\u0bcd\u0bb5\u0bbe\u0baf\u0bcd"\.. "\u0baa\u0bc1\u0ba4\u0ba9\u0bcd"\.. "\u0bb5\u0bbf\u0baf\u0bbe\u0bb4\u0ba9\u0bcd"\.. "\u0bb5\u0bc6\u0bb3\u0bcd\u0bb3\u0bbf"\.. "\u0b9a\u0ba9\u0bbf"].. ::msgcat::mcset ta MONTHS_ABBREV [list \.. "\u0b9c\u0ba9\u0bb5\u0bb0\u0bbf"\.. "\u0baa\u0bc6\u0baa\u0bcd\u0bb0\u0bb5\u0bb0\u0bbf"\.. "\u0bae\u0bbe\u0bb0\u0bcd\u0b9a\u0bcd"\.. "\u0b8f\u0baa\u0bcd\u0bb0\u0bb2\u0bcd"\.. "\u0bae\u0bc7"\.. "\u0b9c\u0bc2\u0ba9\u0bcd"\.. "\u0b9c\u0bc2\u0bb2\u0bc8"\.. "\u0b86\u0b95\u0bb8\u0bcd\u0b9f\u0bcd"\.. "\u0b9a\u0bc6\u0baa\u0bcd\u0b9f\u0bae\u0bcd\u0baa\u0bb0\u0bcd"\.. "\u0b85\u0b95\u0bcd\u0b9f\u0bcb\u0baa\u0bb0\u0bcd"\.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):257
                                                                                                                                                                                                            Entropy (8bit):4.863003494480733
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xosDv+IZosK3v6ry/5osDo+3v+6f6HyFvn:4EnLB383ZDvl5K3v6ry/ZDF3vmSVn
                                                                                                                                                                                                            MD5:CF078352DA0507C767F04E31D6C14296
                                                                                                                                                                                                            SHA1:0A9B1255BD85B60D3620AE61370F54748AB7A182
                                                                                                                                                                                                            SHA-256:4978A193076DE56944236F7F1DCECACFF739536DFB3DBEFC1F7FE2B97A8AEAF4
                                                                                                                                                                                                            SHA-512:6FFC85B2A8DECB373EC76B1CD1A9459A30E443319F2C8DB9BBE6E115F5EFEEBAC314D4E8BE996EA55EE46466C6F6057A73078F5FDCF1C4CBAF1A270E45BC10C0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset ta_IN DATE_FORMAT "%d %M %Y".. ::msgcat::mcset ta_IN TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset ta_IN DATE_TIME_FORMAT "%d %M %Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2149
                                                                                                                                                                                                            Entropy (8bit):4.097884113767283
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:43a8mxI9k3JR0UjjFbPcniLHVktjjFbPcniLHVM:2a8v9k3JdbPcIidbPcIG
                                                                                                                                                                                                            MD5:61E4CB2AAD66285E9113071057F39C35
                                                                                                                                                                                                            SHA1:A2BD21090859669C4B6A875E077825381B7E2702
                                                                                                                                                                                                            SHA-256:9E96C7123100234A7018533764502985A208F2EB3314F5B6332D46016725A63F
                                                                                                                                                                                                            SHA-512:589A2D65508B07B5FDEDA883F71A4B496B25458CA1ECE7C4D4F5DAE82EB683DA82C8E21E57D63A235AB600174C9D362A746B2E27BAA6E3ADE1B7BD9D6000BE27
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset te DAYS_OF_WEEK_ABBREV [list \.. "\u0c06\u0c26\u0c3f"\.. "\u0c38\u0c4b\u0c2e"\.. "\u0c2e\u0c02\u0c17\u0c33"\.. "\u0c2c\u0c41\u0c27"\.. "\u0c17\u0c41\u0c30\u0c41"\.. "\u0c36\u0c41\u0c15\u0c4d\u0c30"\.. "\u0c36\u0c28\u0c3f"].. ::msgcat::mcset te DAYS_OF_WEEK_FULL [list \.. "\u0c06\u0c26\u0c3f\u0c35\u0c3e\u0c30\u0c02"\.. "\u0c38\u0c4b\u0c2e\u0c35\u0c3e\u0c30\u0c02"\.. "\u0c2e\u0c02\u0c17\u0c33\u0c35\u0c3e\u0c30\u0c02"\.. "\u0c2c\u0c41\u0c27\u0c35\u0c3e\u0c30\u0c02"\.. "\u0c17\u0c41\u0c30\u0c41\u0c35\u0c3e\u0c30\u0c02"\.. "\u0c36\u0c41\u0c15\u0c4d\u0c30\u0c35\u0c3e\u0c30\u0c02"\.. "\u0c36\u0c28\u0c3f\u0c35\u0c3e\u0c30\u0c02"].. ::msgcat::mcset te MONTHS_ABBREV [list \.. "\u0c1c\u0c28\u0c35\u0c30\u0c3f"\.. "\u0c2b\u0c3f\u0c2c\u0c4d\u0c30\u0c35\u0c30\u0c3f"\.. "\u0c2e\u0c3
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):419
                                                                                                                                                                                                            Entropy (8bit):5.058324650031252
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:4EnLB383LjZWsn0sHjoD0savzda3v6ry/ZF3vMSVn:4aR833Z1nnHjoDnavzd8vSCZNvMSV
                                                                                                                                                                                                            MD5:BCA040A356E7E8CC597EFB9B9065F8E1
                                                                                                                                                                                                            SHA1:ADAF7EC8C2035BC06E168D3F1BD7F39277E9273F
                                                                                                                                                                                                            SHA-256:B110FEEDDA21ECCEFA624BEF8E1476E9F221FB253880AC370967AE4D0237CA7A
                                                                                                                                                                                                            SHA-512:D408ECE8CF89FB23B45420D3CBA7655EEE713498210889A84EE25D3417360705546D97028EAAAA47764B6E9B0A3699669B98C0A53861A38E0DFCB9F3B8A47BEC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset te_IN AM "\u0c2a\u0c42\u0c30\u0c4d\u0c35\u0c3e\u0c39\u0c4d\u0c28".. ::msgcat::mcset te_IN PM "\u0c05\u0c2a\u0c30\u0c3e\u0c39\u0c4d\u0c28".. ::msgcat::mcset te_IN DATE_FORMAT "%d/%m/%Y".. ::msgcat::mcset te_IN TIME_FORMAT_12 "%I:%M:%S %P".. ::msgcat::mcset te_IN DATE_TIME_FORMAT "%d/%m/%Y %I:%M:%S %P %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2359
                                                                                                                                                                                                            Entropy (8bit):4.382796122808316
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:439X4QKPQJecQwFA0P9JmDsxQ7KHfWkD2CQM0DnWxFDzCYmdrtVP:29ohCi1028QmHfIC4jW3DmHB
                                                                                                                                                                                                            MD5:7F61E1EA256D78948189EF07119663CD
                                                                                                                                                                                                            SHA1:6867E9780049FACE9984B7788B6F362B8D1AD718
                                                                                                                                                                                                            SHA-256:48BEAF693BF5B6EED15234DB0D375B97E6D576A749E9048420C153E6CAFC0259
                                                                                                                                                                                                            SHA-512:F3E24E0B41A7D722AC2FA0E429A2DCB1CCB5BAECC9912ADF6AF79C51366EA1AC9F931F0F44F068F3CEE6873516E6223CC5E7616CF523B1DFB9E528DE4D58454A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset th DAYS_OF_WEEK_ABBREV [list \.. "\u0e2d\u0e32."\.. "\u0e08."\.. "\u0e2d."\.. "\u0e1e."\.. "\u0e1e\u0e24."\.. "\u0e28."\.. "\u0e2a."].. ::msgcat::mcset th DAYS_OF_WEEK_FULL [list \.. "\u0e27\u0e31\u0e19\u0e2d\u0e32\u0e17\u0e34\u0e15\u0e22\u0e4c"\.. "\u0e27\u0e31\u0e19\u0e08\u0e31\u0e19\u0e17\u0e23\u0e4c"\.. "\u0e27\u0e31\u0e19\u0e2d\u0e31\u0e07\u0e04\u0e32\u0e23"\.. "\u0e27\u0e31\u0e19\u0e1e\u0e38\u0e18"\.. "\u0e27\u0e31\u0e19\u0e1e\u0e24\u0e2b\u0e31\u0e2a\u0e1a\u0e14\u0e35"\.. "\u0e27\u0e31\u0e19\u0e28\u0e38\u0e01\u0e23\u0e4c"\.. "\u0e27\u0e31\u0e19\u0e40\u0e2a\u0e32\u0e23\u0e4c"].. ::msgcat::mcset th MONTHS_ABBREV [list \.. "\u0e21.\u0e04."\.. "\u0e01.\u0e1e."\.. "\u0e21\u0e35.\u0e04."\.. "\u0e40\u0e21.\u0e22."\.. "\u0e1e.\u0e04."\.. "\u0e21\u0
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1183
                                                                                                                                                                                                            Entropy (8bit):4.390397293529625
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR83ZVUflVdq4qTr6dyX59508THHCh5LbQgWiNv9KvWIn:43PXTtbTngLhWiJGWIn
                                                                                                                                                                                                            MD5:017F0F989BD5DBBF25E7C797CE09C45C
                                                                                                                                                                                                            SHA1:162922DBD55A31A74410375A36EE7BC50E092BDD
                                                                                                                                                                                                            SHA-256:4B85B345D6C43F7257C6849A60A492397FD5FD9D82DF3A2252189D7A1ECCBB64
                                                                                                                                                                                                            SHA-512:73B6CF395753D863330687404E8A584CB08B81A8CC456DCE7BB49C4EA15EA19E45E3CC1E1367E10915DE14AC6258383289BCFEF55AD2768A50889DF390D37EF9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset tr DAYS_OF_WEEK_ABBREV [list \.. "Paz"\.. "Pzt"\.. "Sal"\.. "\u00c7ar"\.. "Per"\.. "Cum"\.. "Cmt"].. ::msgcat::mcset tr DAYS_OF_WEEK_FULL [list \.. "Pazar"\.. "Pazartesi"\.. "Sal\u0131"\.. "\u00c7ar\u015famba"\.. "Per\u015fembe"\.. "Cuma"\.. "Cumartesi"].. ::msgcat::mcset tr MONTHS_ABBREV [list \.. "Oca"\.. "\u015eub"\.. "Mar"\.. "Nis"\.. "May"\.. "Haz"\.. "Tem"\.. "A\u011fu"\.. "Eyl"\.. "Eki"\.. "Kas"\.. "Ara"\.. ""].. ::msgcat::mcset tr MONTHS_FULL [list \.. "Ocak"\.. "\u015eubat"\.. "Mart"\.. "Nisan"\.. "May\u0131s"\.. "Haziran"\.. "Temmuz"\.. "A\u011fustos"\.. "Eyl\u00fcl"\.. "Ekim"\.. "Kas\u0131m"\.. "Aral\u
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2165
                                                                                                                                                                                                            Entropy (8bit):4.289021158621493
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:436yILgoQjQPxUIkgPDRQnQ0vVQbC1iQwweIgWQDIoZI7QDI3QbI87IVQnIzQ7mh:2AzUe3EhV8CYgrbH7z3fLVTzgn5jyX7p
                                                                                                                                                                                                            MD5:323BD95809A44B0BADC71AD36E5F095B
                                                                                                                                                                                                            SHA1:44F6016873CA955D27545C56CCD24BDB06A83C43
                                                                                                                                                                                                            SHA-256:7093DA7E39CEB6D3F51EB6CF1CCA2D7F3680ED7B8FE4A5F0CECEEF6BEB21AC77
                                                                                                                                                                                                            SHA-512:DB16E0E2D17CE47673DE781A7171944C14CC550FB8EB0920C05B979E4D067E36DF0B59B8BFA81F82D8FCE1FFDDAAD2755E68BFE5BC0DBB11E8716A4D18BA5F7E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset uk DAYS_OF_WEEK_ABBREV [list \.. "\u043d\u0434"\.. "\u043f\u043d"\.. "\u0432\u0442"\.. "\u0441\u0440"\.. "\u0447\u0442"\.. "\u043f\u0442"\.. "\u0441\u0431"].. ::msgcat::mcset uk DAYS_OF_WEEK_FULL [list \.. "\u043d\u0435\u0434\u0456\u043b\u044f"\.. "\u043f\u043e\u043d\u0435\u0434\u0456\u043b\u043e\u043a"\.. "\u0432\u0456\u0432\u0442\u043e\u0440\u043e\u043a"\.. "\u0441\u0435\u0440\u0435\u0434\u0430"\.. "\u0447\u0435\u0442\u0432\u0435\u0440"\.. "\u043f'\u044f\u0442\u043d\u0438\u0446\u044f"\.. "\u0441\u0443\u0431\u043e\u0442\u0430"].. ::msgcat::mcset uk MONTHS_ABBREV [list \.. "\u0441\u0456\u0447"\.. "\u043b\u044e\u0442"\.. "\u0431\u0435\u0440"\.. "\u043a\u0432\u0456\u0442"\.. "\u0442\u0440\u0430\u0432"\.. "\u0447\u0435\u0440\u0432"\.. "\u043b
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1471
                                                                                                                                                                                                            Entropy (8bit):4.44729506678271
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4aR836DNjYTP55YAUy2tJ9kyzW68IFYHMBSW1K1pvhv1O:43dbYJyC8ySgI1dV1O
                                                                                                                                                                                                            MD5:C127F54C462917D3B3EEF5F29F612138
                                                                                                                                                                                                            SHA1:B1D9A67F856D93F98524C6372B352EA0DE1B9CD3
                                                                                                                                                                                                            SHA-256:E9B7AECD456F1D2288604C982B5DED0DCF71DCA968C0B0EAFF4CA16CC3B73EC2
                                                                                                                                                                                                            SHA-512:0B0F132F10580751258D37E070338C3B39DF57FDECDB9D0AFA67E90D6766DDCB4D711876E551ED759D177F1B8F4E9E1DD8F7899F7CB57F8039F55EC4C2984E87
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset vi DAYS_OF_WEEK_ABBREV [list \.. "Th 2"\.. "Th 3"\.. "Th 4"\.. "Th 5"\.. "Th 6"\.. "Th 7"\.. "CN"].. ::msgcat::mcset vi DAYS_OF_WEEK_FULL [list \.. "Th\u01b0\u0301 hai"\.. "Th\u01b0\u0301 ba"\.. "Th\u01b0\u0301 t\u01b0"\.. "Th\u01b0\u0301 n\u0103m"\.. "Th\u01b0\u0301 s\u00e1u"\.. "Th\u01b0\u0301 ba\u0309y"\.. "Chu\u0309 nh\u00e2\u0323t"].. ::msgcat::mcset vi MONTHS_ABBREV [list \.. "Thg 1"\.. "Thg 2"\.. "Thg 3"\.. "Thg 4"\.. "Thg 5"\.. "Thg 6"\.. "Thg 7"\.. "Thg 8"\.. "Thg 9"\.. "Thg 10"\.. "Thg 11"\.. "Thg 12"\.. ""].. ::msgcat::mcset vi MONTHS_FULL [list \.. "Th\u00e1ng m\u00f4\u0323t"\.. "Th\u00e1ng hai"\.. "Th\u00e1ng ba"\.. "Th\u00e1ng t\u01b0"\.. "Th\u00e
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with very long lines (1598), with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3385
                                                                                                                                                                                                            Entropy (8bit):4.5164095151631125
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:43qrY2BBT7uxDqwPqDa8c3FLbYmhyvMDKbW0YGLuoEyke2gdr:2yPTKdo
                                                                                                                                                                                                            MD5:2F356DE14D48B1091DEAA32D20C38D96
                                                                                                                                                                                                            SHA1:4AB78D47A73290000955A7C1DFDF7106093F69FD
                                                                                                                                                                                                            SHA-256:EB247F5184A59414D3DF7E3ECA51F5998C248CFB27D2C02E62A7A30AB35197A7
                                                                                                                                                                                                            SHA-512:602410830018B455C68AE2EBDD83BA561CF59DA5898E00C80CE7EF619912E591EB38B4C8FE8D9B1F024E7105B0C4D2D326FC855F31E79C1B954429B947DFFBB1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset zh DAYS_OF_WEEK_ABBREV [list \.. "\u661f\u671f\u65e5"\.. "\u661f\u671f\u4e00"\.. "\u661f\u671f\u4e8c"\.. "\u661f\u671f\u4e09"\.. "\u661f\u671f\u56db"\.. "\u661f\u671f\u4e94"\.. "\u661f\u671f\u516d"].. ::msgcat::mcset zh DAYS_OF_WEEK_FULL [list \.. "\u661f\u671f\u65e5"\.. "\u661f\u671f\u4e00"\.. "\u661f\u671f\u4e8c"\.. "\u661f\u671f\u4e09"\.. "\u661f\u671f\u56db"\.. "\u661f\u671f\u4e94"\.. "\u661f\u671f\u516d"].. ::msgcat::mcset zh MONTHS_ABBREV [list \.. "\u4e00\u6708"\.. "\u4e8c\u6708"\.. "\u4e09\u6708"\.. "\u56db\u6708"\.. "\u4e94\u6708"\.. "\u516d\u6708"\.. "\u4e03\u6708"\.. "\u516b\u6708"\.. "\u4e5d\u6708"\.. "\u5341\u6708"\.. "\u5341\u4e00\u6708"\.. "\u5341\u4e8c\u6708"\.. ""].. ::msgcat::m
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):319
                                                                                                                                                                                                            Entropy (8bit):5.167825099880243
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoX5YBoHJ+3vtfNrsoHJ+3v6MYBoXa+3vYq9vn:4EnLB383U5YMJ+3vtN3J+3v6LcL3vYqN
                                                                                                                                                                                                            MD5:9FCDC2E80E13984D434E3CC91E1ED14C
                                                                                                                                                                                                            SHA1:710D9EE2A71021F4AB609886138EED43C1380ACD
                                                                                                                                                                                                            SHA-256:4C8A855700FEFE8EE21B08030FF4159D8011AE50353F063229C42DE6292475CF
                                                                                                                                                                                                            SHA-512:D899A1F58DF1051BB2C2C4AC859C52A2D19B1593C37022A29439B37A8057ADC3941F3564E2E1D9CEB72AE123A4E12E24C3736343AA3A5EC8749AB5AEBBF65085
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset zh_CN DATE_FORMAT "%Y-%m-%e".. ::msgcat::mcset zh_CN TIME_FORMAT "%k:%M:%S".. ::msgcat::mcset zh_CN TIME_FORMAT_12 "%P%I\u65f6%M\u5206%S\u79d2".. ::msgcat::mcset zh_CN DATE_TIME_FORMAT "%Y-%m-%e %k:%M:%S %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):780
                                                                                                                                                                                                            Entropy (8bit):4.716025632367214
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:4EnLB383HmSBBHZovDh4ToC4qU3WwVW3v6P3v3WwSn:4aR83Hxo14u3Ww+viv3WwS
                                                                                                                                                                                                            MD5:CFDA7B6463305FA15DBBA72D725A1876
                                                                                                                                                                                                            SHA1:2BF885073FBAF4A38B7AFDA76CA391F195A5A362
                                                                                                                                                                                                            SHA-256:7E1C5BD9EC1A17BB851B0DCABD0DFA9FF9D64B89603D9D3FBEAAC609172346AE
                                                                                                                                                                                                            SHA-512:55F974C706933ECE0575A33C381D9B370B8A408C5C5514C805EC04C8B0CA5BAFAA47267DA98E1805B478A9589FFB7549D79002B2A7AF387049011D78DD7605B6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset zh_HK DAYS_OF_WEEK_ABBREV [list \.. "\u65e5"\.. "\u4e00"\.. "\u4e8c"\.. "\u4e09"\.. "\u56db"\.. "\u4e94"\.. "\u516d"].. ::msgcat::mcset zh_HK MONTHS_ABBREV [list \.. "1\u6708"\.. "2\u6708"\.. "3\u6708"\.. "4\u6708"\.. "5\u6708"\.. "6\u6708"\.. "7\u6708"\.. "8\u6708"\.. "9\u6708"\.. "10\u6708"\.. "11\u6708"\.. "12\u6708"\.. ""].. ::msgcat::mcset zh_HK DATE_FORMAT "%Y\u5e74%m\u6708%e\u65e5".. ::msgcat::mcset zh_HK TIME_FORMAT_12 "%P%I:%M:%S".. ::msgcat::mcset zh_HK DATE_TIME_FORMAT "%Y\u5e74%m\u6708%e\u65e5 %P%I:%M:%S %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):347
                                                                                                                                                                                                            Entropy (8bit):5.062880051437783
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoOpEoPpFocMohX3v6Zwoh+3v6fxvn:4EnLB383J53v6O3vCn
                                                                                                                                                                                                            MD5:3218F8E6BEDD534277DE0849C423158E
                                                                                                                                                                                                            SHA1:10C006446A10406A5644C4033665E877EBF72AF7
                                                                                                                                                                                                            SHA-256:500546B3211D454659D845B4AB9AEF226125100DF40407C49530DE17CDD4363F
                                                                                                                                                                                                            SHA-512:3142893DA85BA8F83A5B6851B313B5F5FF80D2B989C1AE015665EE70373249B44EFB4FF7C621F1D8F37AC6019EF5E8D6D21C76C48998C3D9072F9C5060AA8813
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset zh_SG AM "\u4e0a\u5348".. ::msgcat::mcset zh_SG PM "\u4e2d\u5348".. ::msgcat::mcset zh_SG DATE_FORMAT "%d %B %Y".. ::msgcat::mcset zh_SG TIME_FORMAT_12 "%P %I:%M:%S".. ::msgcat::mcset zh_SG DATE_TIME_FORMAT "%d %B %Y %P %I:%M:%S %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):354
                                                                                                                                                                                                            Entropy (8bit):5.124064818715749
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSyEtJLl73oo6d3/xoAykaRULH/XRxy/5oAyjZRULHi5oAyU/G0OMoAyxW3v6ZQ:4EnLB38315xDOiKRRW3v6F3v8A2n
                                                                                                                                                                                                            MD5:9010E34791B5DDB7F1E0AD4DA6BD4623
                                                                                                                                                                                                            SHA1:418F7374BABEF27FEC8E00D3A32F535084593AB9
                                                                                                                                                                                                            SHA-256:DBA0584B8E1925B439F06E0BF0965E97AFB7EB39E70E0E4C9B70769EBC5F996C
                                                                                                                                                                                                            SHA-512:D3AB698B725E84DAB06E472C41FF2EB55D63885D22B4598C596800BAC83A02A44CB524524F267D090952AF7E0031F47720786ACF9E354EF672CF9EEFB7DB3BD4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/loadICU.tcl -- do not edit..namespace eval ::tcl::clock {.. ::msgcat::mcset zh_TW BCE "\u6c11\u570b\u524d".. ::msgcat::mcset zh_TW CE "\u6c11\u570b".. ::msgcat::mcset zh_TW DATE_FORMAT "%Y/%m/%e".. ::msgcat::mcset zh_TW TIME_FORMAT_12 "%P %I:%M:%S".. ::msgcat::mcset zh_TW DATE_TIME_FORMAT "%Y/%m/%e %P %I:%M:%S %z"..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Tcl script, ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):33777
                                                                                                                                                                                                            Entropy (8bit):4.60013086740989
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:4D0xrpIuhenN4kA0G6sRcl5AdtsPLKiF64aJQ2L:HpnhsS9C5Adqua5aJvL
                                                                                                                                                                                                            MD5:4ECD97188BFED58A15FE22EC566FA6A3
                                                                                                                                                                                                            SHA1:6E4E91096298F1A0AE6CD4241F167C8B4F661EE5
                                                                                                                                                                                                            SHA-256:67A157F1873D606B53DC4D894BD8E71F6B1A0DD66177B9513BD039B348B40349
                                                                                                                                                                                                            SHA-512:1D5067BBB13DAB001168EEB41EBFA2D13BACB0F43A8067CC93923E8F4D062AA387DA23D7D98D6A2AE77D7C849A6026F2343102CBE03690C2CEA0890222339475
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# optparse.tcl --..#..# (private) Option parsing package..# Primarily used internally by the safe:: code...#..#.WARNING: This code will go away in a future release..#.of Tcl. It is NOT supported and you should not rely..#.on it. If your code does rely on this package you..#.may directly incorporate this code into your application.....package require Tcl 8.5-..# When this version number changes, update the pkgIndex.tcl file..# and the install directory in the Makefiles...package provide opt 0.4.8....namespace eval ::tcl {.... # Exported APIs.. namespace export OptKeyRegister OptKeyDelete OptKeyError OptKeyParse \.. OptProc OptProcArgGiven OptParse \... Lempty Lget \.. Lassign Lvarpop Lvarpop1 Lvarset Lvarincr \.. SetMax SetMin......################# Example of use / 'user documentation' ###################.... proc OptCreateTestProc {} {.....# Defines ::tcl::OptParseTest as a test proc with parsed arguments...# (can't be d
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):620
                                                                                                                                                                                                            Entropy (8bit):4.702477618616754
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:jHxIRu9zhjJS42wbGlTULuUAZb3KykszLYIGbyAkXaqrQ+pBb6:biRUJS42wbGlTUcZ+yk2LY0XaqrB4
                                                                                                                                                                                                            MD5:07532085501876DCC6882567E014944C
                                                                                                                                                                                                            SHA1:6BC7A122429373EB8F039B413AD81C408A96CB80
                                                                                                                                                                                                            SHA-256:6A4ABD2C519A745325C26FB23BE7BBF95252D653A24806EB37FD4AA6A6479AFE
                                                                                                                                                                                                            SHA-512:0D604E862F3A1A19833EAD99AAF15A9F142178029AB64C71D193CEE4901A0196C1EEDDC2BCE715B7FA958AC45C194E63C77A71E4BE4F9AEDFD5B44CF2A726E76
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Tcl package index file, version 1.1..# This file is generated by the "pkg_mkIndex -direct" command..# and sourced either when an application starts up or..# by a "package unknown" script. It invokes the..# "package ifneeded" command to set up package-related..# information so that packages will be loaded automatically..# in response to "package require" commands. When this..# script is sourced, the variable $dir must contain the..# full path name of this file's directory.....if {![package vsatisfies [package provide Tcl] 8.5-]} {return}..package ifneeded opt 0.4.8 [list source [file join $dir optparse.tcl]]..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):23995
                                                                                                                                                                                                            Entropy (8bit):4.884828325514459
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:8xgjLNILEHsdAW2UfnImRqXqux6XmihmCchzPLrXJjJh6PLfzdklG:8xgjLNImsdnvIm86uGLhLchzDzJ9h6Dn
                                                                                                                                                                                                            MD5:DDB0AB9842B64114138A8C83C4322027
                                                                                                                                                                                                            SHA1:ECCACDC2CCD86A452B21F3CF0933FD41125DE790
                                                                                                                                                                                                            SHA-256:F46AB61CDEBE3AA45FA7E61A48930D64A0D0E7E94D04D6BF244F48C36CAFE948
                                                                                                                                                                                                            SHA-512:C0CF718258B4D59675C088551060B34CE2BC8638958722583AC2313DC354223BFEF793B02F1316E522A14C7BA9BED219531D505DE94DC3C417FC99D216A01463
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# package.tcl --..#..# utility procs formerly in init.tcl which can be loaded on demand..# for package management...#..# Copyright (c) 1991-1993 The Regents of the University of California...# Copyright (c) 1994-1998 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....namespace eval tcl::Pkg {}....# ::tcl::Pkg::CompareExtension --..#..# Used internally by pkg_mkIndex to compare the extension of a file to a given..# extension. On Windows, it uses a case-insensitive comparison because the..# file system can be file insensitive...#..# Arguments:..# fileName.name of a file whose extension is compared..# ext..(optional) The extension to compare against; you must..#..provide the starting dot...#..Defaults to [info sharedlibextension]..#..# Results:..# Returns 1 if the extension matches, 0 otherwise....proc tcl::Pkg::CompareExtension {fileName {ext {}}} {.. global tcl_platfor
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):844
                                                                                                                                                                                                            Entropy (8bit):4.883013702569192
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:TF7S2n2wn2SNHaeYF9xcwrmXhbs1GUiSYX3EtSK78ex4VIpynEw88/McUBbPgnz:TF7Hn2wnlk2KwyZSM4SkV/3UB7Cz
                                                                                                                                                                                                            MD5:577787C2F4F5956BA70F83012B980AE5
                                                                                                                                                                                                            SHA1:040B2469F796F3FDFCD1E1DD2EB1C5B799EDEF62
                                                                                                                                                                                                            SHA-256:E269029C8263E3CBC1920C3604ECDCF15EDCCB208A0D68F9EB42B73954D620C0
                                                                                                                                                                                                            SHA-512:C2940F6F3D77412EFC537B8AB67352F519DFFA95739FCC17BF1817335AFD9E5BFE91ABE98CBA99E278CB4923D4E6D431ED9D72282745203C0F7D73193F550238
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# parray:..# Print the contents of a global array on stdout...#..# Copyright (c) 1991-1993 The Regents of the University of California...# Copyright (c) 1994 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....proc parray {a {pattern *}} {.. upvar 1 $a array.. if {![array exists array]} {...return -code error "\"$a\" isn't an array".. }.. set maxl 0.. set names [lsort [array names array $pattern]].. foreach name $names {...if {[string length $name] > $maxl} {... set maxl [string length $name]...}.. }.. set maxl [expr {$maxl + [string length $a] + 2}].. foreach name $names {...set nameString [format %s(%s) $a $name]...puts stdout [format "%-*s = %s" $maxl $nameString $array($name)].. }..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Tcl script, ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):42223
                                                                                                                                                                                                            Entropy (8bit):4.822635446297551
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:H/Jo8y7AyARYhZfc3njlVdRIp4xOtoYx4WneNiBq5vIhfwEaqadlUCJ2Pbb1P6:H/c7AmhZmnjvdRIG924WneNiBq5+fwEc
                                                                                                                                                                                                            MD5:B8C1561D471CFBF4111C706411D59883
                                                                                                                                                                                                            SHA1:71483EAEEF377EE9AF90BEC44F70C7B12C5BC720
                                                                                                                                                                                                            SHA-256:C21DCE3AB31893118BBED01E559070F1D3541877FEE331BD45F5BF4300ED9654
                                                                                                                                                                                                            SHA-512:465065A938C71AF4588B3331B51A62DD57F57492EB1CB6C0F52B9FD0A2FE7A54B1E995AA56E4A41D7A99EAFF665C1E23E3B240FB3F9840AB242C21B1DBFFFF45
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# safe.tcl --..#..# This file provide a safe loading/sourcing mechanism for safe interpreters...# It implements a virtual path mechanism to hide the real pathnames from the..# child. It runs in a parent interpreter and sets up data structure and..# aliases that will be invoked when used from a child interpreter...#..# See the safe.n man page for details...#..# Copyright (c) 1996-1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES.....#..# The implementation is based on namespaces. These naming conventions are..# followed:..# Private procs starts with uppercase...# Public procs are exported and starts with lowercase..#....# Needed utilities package..package require opt 0.4.8....# Create the safe namespace..namespace eval ::safe {.. # Exported API:.. namespace export interpCreate interpInit interpConfigure interpDelete \...interpAddToAccessPath interpFindInAccessPath setL
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):5617
                                                                                                                                                                                                            Entropy (8bit):4.747404679682368
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:eOaVhNUMUuUQU2UsUIUbUEUEeUkgU6UWSO0DT5RTdcvsilrvs+jscMK57ehXowrz:ejVHRRLP3LWDXewTbSO0DT5RTdcvsilg
                                                                                                                                                                                                            MD5:C62FB22F4C9A3EFF286C18421397AAF4
                                                                                                                                                                                                            SHA1:4A49B8768CFF68F2EFFAF21264343B7C632A51B2
                                                                                                                                                                                                            SHA-256:DDF7E42DEF37888AD0A564AA4F8CA95F4EEC942CEBEBFCA851D35515104D5C89
                                                                                                                                                                                                            SHA-512:558D401CB6AF8CE3641AF55CAEBC9C5005AB843EE84F60C6D55AFBBC7F7129DA9C58C2F55C887C3159107546FA6BC13FFC4CCA63EA8841D7160B8AA99161A185
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Tcl autoload index file, version 2.0..# -*- tcl -*-..# This file is generated by the "auto_mkindex" command..# and sourced to set up indexing information for one or..# more commands. Typically each line is a command that..# sets an element in the auto_index array, where the..# element name is the name of a command and the value is..# a script that loads the command.....set auto_index(auto_reset) [list source [file join $dir auto.tcl]]..set auto_index(tcl_findLibrary) [list source [file join $dir auto.tcl]]..set auto_index(auto_mkindex) [list source [file join $dir auto.tcl]]..set auto_index(auto_mkindex_old) [list source [file join $dir auto.tcl]]..set auto_index(::auto_mkindex_parser::init) [list source [file join $dir auto.tcl]]..set auto_index(::auto_mkindex_parser::cleanup) [list source [file join $dir auto.tcl]]..set auto_index(::auto_mkindex_parser::mkindex) [list source [file join $dir auto.tcl]]..set auto_index(::auto_mkindex_parser::hook) [list source [file join $dir auto.t
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):12204
                                                                                                                                                                                                            Entropy (8bit):4.763796758810551
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:55CjnlRfMKqaOH5bE2KjNkkpgpCmqkkuowUh9PTYMsvSO+xy8h/vuKisM68E:5q3MKYH5bE1jNkkpgomq/uCPTYMC+k83
                                                                                                                                                                                                            MD5:215262A286E7F0A14F22DB1AA7875F05
                                                                                                                                                                                                            SHA1:66B942BA6D3120EF8D5840FCDEB06242A47491FF
                                                                                                                                                                                                            SHA-256:4B7ED9FD2363D6876092DB3F720CBDDF97E72B86B519403539BA96E1C815ED8F
                                                                                                                                                                                                            SHA-512:6ECD745D7DA9D826240C0AB59023C703C94B158AE48C1410FAA961A8EDB512976A4F15AE8DEF099B58719ADF0D2A9C37E6F29F54D39C1AB7EE81FA333A60F39B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# -*- tcl -*-..#..# Searching for Tcl Modules. Defines a procedure, declares it as the primary..# command for finding packages, however also uses the former 'package unknown'..# command as a fallback...#..# Locates all possible packages in a directory via a less restricted glob. The..# targeted directory is derived from the name of the requested package, i.e...# the TM scan will look only at directories which can contain the requested..# package. It will register all packages it found in the directory so that..# future requests have a higher chance of being fulfilled by the ifneeded..# database without having to come to us again...#..# We do not remember where we have been and simply rescan targeted directories..# when invoked again. The reasoning is this:..#..# - The only way we get back to the same directory is if someone is trying to..# [package require] something that wasn't there on the first scan...#..# Either..# 1) It is there now: If we rescan, you get it; if not you don
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):147
                                                                                                                                                                                                            Entropy (8bit):4.995501022397479
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/2DcsBdNMXGm2OHnFvpsYoHsdSalHFLwy:SlSWB9eg/2DBpDm2OHnFvmYoH1alHOy
                                                                                                                                                                                                            MD5:FF8B5540631A6EE93507338C4E7AA49D
                                                                                                                                                                                                            SHA1:817B261A1B6B92AA498EC286349964EA10FB5A84
                                                                                                                                                                                                            SHA-256:7213997BB9CF9D384A7002B8C8EFEF25C01ABA6083D9835A16D583D5DCEE40A0
                                                                                                                                                                                                            SHA-512:8D78AC4868ED0013EDA536C0E82E0E91398772AA18C637AEFE22F24B142FCDA55A4CB853B2282951E907C9E2F62BD3F831A5CF995F52898F5225D16889943A9C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Abidjan) {.. {-9223372036854775808 -968 0 LMT}.. {-1830383032 0 0 GMT}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):183
                                                                                                                                                                                                            Entropy (8bit):4.832432925672155
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2Dc9XfBQDcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2DUGDBS
                                                                                                                                                                                                            MD5:52FDFD3DB98475FBBB620D0D5565C5CC
                                                                                                                                                                                                            SHA1:C7750452859663605272553DBEE0B6C134E1517C
                                                                                                                                                                                                            SHA-256:6040827AFED8CEF45F252FBD7E3E862C0B5E9D06C1C98C58BAD61DFE67BD57CC
                                                                                                                                                                                                            SHA-512:2FF9D96D81279148A86BE208FEEACCBCB8B4224D093D6C092ECD1C4EA2186589CCF947027D3A726600C703611B4CFEE029AA14ED3E8593C477B427C4F342CF27
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Accra) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):189
                                                                                                                                                                                                            Entropy (8bit):4.817170256300069
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/2DczqIVDcVVMMyn:SlSWB9vsM3y7VTHAIgNTxcAN/2DnaDkO
                                                                                                                                                                                                            MD5:30CDD4D37E9DD60FBF6D754C9343F364
                                                                                                                                                                                                            SHA1:56F896C21068764B7B8F884F374B18913CA3D9CA
                                                                                                                                                                                                            SHA-256:E11FD8AD8572B684333810CFDC23B92E1ACF619875866985E288D92F8277D07F
                                                                                                                                                                                                            SHA-512:78FC8043CCE25713404E70996229E5EA8238BF5C0F59029064EDA5494E2D4F54398931F3D855E30C82B2C53B789C40EE4CBF09D0F98C2BA6734595D4AA75017A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Addis_Ababa) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1080
                                                                                                                                                                                                            Entropy (8bit):4.187497782275587
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB862D7nmdHh5Cv6/lHY8SOSuvvzXipFSgSO5vW5aKmvbsF6VWsXN87QBWcAFy:5veSvKlHYXNujXipFSjKRKXiWsXCGWJy
                                                                                                                                                                                                            MD5:E8D3DF11CE0E7575485573FA07D955D5
                                                                                                                                                                                                            SHA1:3B2C00C85B6C0BFAA1C676C970D6DF1B4BDC3D4A
                                                                                                                                                                                                            SHA-256:E6874647561CE1C5FD1F650C9B167F77AC5B24FD2026046399A9043CF998E5C4
                                                                                                                                                                                                            SHA-512:E2968BE847622CF243C0E498436FD21BDC2E1DF0FD8D694F2C70569D17CE896CDE4968BB8ABDEF9F687439E4EA2D955AE87D6C15E81F881EE1413416A90765D4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Algiers) {.. {-9223372036854775808 732 0 LMT}.. {-2486592732 561 0 PMT}.. {-1855958961 0 0 WET}.. {-1689814800 3600 1 WEST}.. {-1680397200 0 0 WET}.. {-1665363600 3600 1 WEST}.. {-1648342800 0 0 WET}.. {-1635123600 3600 1 WEST}.. {-1616893200 0 0 WET}.. {-1604278800 3600 1 WEST}.. {-1585443600 0 0 WET}.. {-1574038800 3600 1 WEST}.. {-1552266000 0 0 WET}.. {-1539997200 3600 1 WEST}.. {-1531443600 0 0 WET}.. {-956365200 3600 1 WEST}.. {-950486400 0 0 WET}.. {-942012000 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796262400 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-766630800 3600 0 CET}.. {-733280400 0 0 WET}.. {-439430400 3600 0 CET}.. {-212029200 0 0 WET}.. {41468400 3600 1 WEST}.. {54774000 0 0 WET}.. {231724800 3600 1 WEST}.. {246240000 3600 0 CET}.. {259545600 7200 1 CEST}.. {275274000 3600 0 CET}.. {309740400 0 0 WET}.. {
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):184
                                                                                                                                                                                                            Entropy (8bit):4.801054282631739
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/2DcjEUEH+DcVVMMyn:SlSWB9vsM3y7VTHAIgNTxcAN/2DGs+DR
                                                                                                                                                                                                            MD5:A543BDEB3771017421FB75231F0004F2
                                                                                                                                                                                                            SHA1:D682C58C27562FF3ABAB8EDE8EB6EA754DA7C02E
                                                                                                                                                                                                            SHA-256:064EB7F9A1FA05A317C6BDCA6B102BC1560D980758F9E4DDB010C9E7DC068ECB
                                                                                                                                                                                                            SHA-512:44848D60EDC79AF784A819714C0D9F62DCCB6329B47F25D74AB8C174BF9EC3F783C66FEB27F588A93FABA9BECAF076F453D6D797CE4F28461F7AE69440EA54C7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Asmara) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):184
                                                                                                                                                                                                            Entropy (8bit):4.806258322241929
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/2DcjAWDcVVMMyn:SlSWB9vsM3y7VTHAIgNTxcAN/2D8DkOn
                                                                                                                                                                                                            MD5:1B5E386E7A2F10D9385DE4C5683EBB85
                                                                                                                                                                                                            SHA1:FECBA599C37493D2E0AEE8E21BAB40BF8E8DC82A
                                                                                                                                                                                                            SHA-256:76939852A98EA7BF156D0AC18B434CC610DAF5232322C0FBB066CD52C5B72AF7
                                                                                                                                                                                                            SHA-512:B36FABFCDB2187A3A4A211C8E033D96C91E3C4D47907D284E10786555562C82231566033EAB4753EF1E48DF1233CFC8C6C0FB3CA50748BE0B2554A972A88FBA0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Asmera) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):184
                                                                                                                                                                                                            Entropy (8bit):4.883634030944169
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2DcxAQDcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2DwNDBS
                                                                                                                                                                                                            MD5:6B9BB5B37C41AA727E31BF03483DC1CA
                                                                                                                                                                                                            SHA1:CB3BBA37B063EA4A54CD15C6E30C14D8CA30D3C0
                                                                                                                                                                                                            SHA-256:F6D1BA22115A6565B6D6ABEB578F001DDB41E673C422C8EA70D0DF77B24115F6
                                                                                                                                                                                                            SHA-512:23DB3E298FDEB165FD85D99E03C00835B584984B814AF7F54A9CDD4A9F93E16B0C58342D319129F46CF8EC36F93DE5EA51B492CA4CABDAB75D84709BC6C26119
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Bamako) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):178
                                                                                                                                                                                                            Entropy (8bit):4.882974805254803
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsGe/vXHAIgNGESuvHRL/2Dcx2m/2DcGeyn:SlSWB9vsM3y7VXHAIgNTTN/2Dw/2D4yn
                                                                                                                                                                                                            MD5:92FF9E5835C0C80F358BFE69120660A0
                                                                                                                                                                                                            SHA1:724758B43BD79DD8A29B02BE6910D492924F8280
                                                                                                                                                                                                            SHA-256:5047A507D22B68C9349EB6A48C41C80DB4C69F98F99C6574059DEA87178E36C0
                                                                                                                                                                                                            SHA-512:6FCB709DB4AC19191FECE1E8BAC55E77F265B5AF89F7A3565F06BFAF0BEE12E3EAF2F52CA09C68D75C358C25A31867505CE8AD75D7386DCD15F4BE1CE61272CD
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Bangui) $TZData(:Africa/Lagos)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):184
                                                                                                                                                                                                            Entropy (8bit):4.888193386512119
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2Dcx79FHp4DcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2Dw7J4c
                                                                                                                                                                                                            MD5:46E5703CF284E44E15E5872DF075FCBC
                                                                                                                                                                                                            SHA1:EA4BFA6D568DFA877F72302ADA21ECC2840D9FD5
                                                                                                                                                                                                            SHA-256:77E610A02CCECE3045B09D07A9BE6100F5AA9C3C2AEB543535C9AE941194F4E4
                                                                                                                                                                                                            SHA-512:1454467FE63E97DFA4DE66E359F68B2D80C92CDE59FC15A4BE513629FFD154D2281EADF3FC78F7AFDDF5A5896195F3A69E66697A659BBB1A0EAFD3E1DA6565EC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Banjul) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):176
                                                                                                                                                                                                            Entropy (8bit):4.847843768169462
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/2Dc5iDMXGm2OHGVkeoHsdSawwF6hSVPVFwy:SlSWB9eg/2D4uDm2OHCkeoH1awwFMmMy
                                                                                                                                                                                                            MD5:7E710C939B9CC0C1AC1ECF4239B543C5
                                                                                                                                                                                                            SHA1:429CC87086FB22727815ED05AC6472333FF06013
                                                                                                                                                                                                            SHA-256:2A870E534DE67713C27F2F3B9BF26FA7498C240CF633988CE76DBDAC5B69214D
                                                                                                                                                                                                            SHA-512:70D9365C31C43A95211FC20E9290B24D356FFEFA935B8829CE32831026A196DECDD12226097F6DA3B4B919E137AA0181714680CDBB72B00C130A87E3A4735004
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Bissau) {.. {-9223372036854775808 -3740 0 LMT}.. {-1830380400 -3600 0 -01}.. {157770000 0 0 GMT}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):183
                                                                                                                                                                                                            Entropy (8bit):4.904342145830274
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsfKG5XHAIgNGEjKORL/2Dc8ycXp75h4DcfKB:SlSWB9vsM3y7fnHAIgNTjdN/2DAmp1hs
                                                                                                                                                                                                            MD5:7AD3749D7047855CB9B9EC9696015402
                                                                                                                                                                                                            SHA1:F792359AD9EEC2ABD98DAFA6661C1E57BAB89EBE
                                                                                                                                                                                                            SHA-256:8F700409B8EEE33ACE5F050414971FFEE0270949842E58E9299BB5CD6CCF34DE
                                                                                                                                                                                                            SHA-512:681C1B318746C587DEBA6E109D1D5A99D1F3E28FE46C24F36B69D533D884FDDC6EA35BB31A475575D683B73BF129FED761523EC9285F2FF1E4CACA2C54C046C5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Blantyre) $TZData(:Africa/Maputo)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):183
                                                                                                                                                                                                            Entropy (8bit):4.901235831565769
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsGe/vXHAIgNGESuvHRL/2DciE0TMJZp4DcGeyn:SlSWB9vsM3y7VXHAIgNTTN/2D4qGp4D1
                                                                                                                                                                                                            MD5:7028268EE88250AC40547A3FDBBFC67C
                                                                                                                                                                                                            SHA1:5006D499CD1D1CB93EB3DA0EC279F76B7123DAA6
                                                                                                                                                                                                            SHA-256:596DB2D64CDD6250642CB65514D5BCB52F3E3EA83F50D8915D9D4FDEA008F440
                                                                                                                                                                                                            SHA-512:D623C69FE8A6050E77FB819C2F5FAEE35D5034182B1D30A409C17208155501656133E774E402875537335F8201E4734A0B5D327712CBF623AC330F1014D9025B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Brazzaville) $TZData(:Africa/Lagos)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):184
                                                                                                                                                                                                            Entropy (8bit):4.947752840781864
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsfKG5XHAIgNGEjKORL/2DclbDcfKB:SlSWB9vsM3y7fnHAIgNTjdN/2DkbDEi
                                                                                                                                                                                                            MD5:0EBC2D8F0BD1A32C21070F9397EAC9E2
                                                                                                                                                                                                            SHA1:95AAA97427265635784E8AC624CA863DB9F1475D
                                                                                                                                                                                                            SHA-256:9A15867255B43A954CA60DA11660F157553AAB6A15C50ACD49D182276E0CF4CC
                                                                                                                                                                                                            SHA-512:4CD2E14F84C58E955742637A51D99DB9493972671A2B5D801EBD9D901D4903654E374C59BF010C70071D33FA17788358F78004201A787CCA2AD714D670393488
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Bujumbura) $TZData(:Africa/Maputo)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3852
                                                                                                                                                                                                            Entropy (8bit):3.7766651198444507
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:58ybRwEa40MF4pt0/jaGYbaJF0a3T07ITB85oWXmSGmuyTVuV0apRQnL0KD3rZza:fLg1GbJFp3gHRQVy7DPUUQkiHMo
                                                                                                                                                                                                            MD5:9DCDB3DD41DA13D81EB8E1CAF56964DA
                                                                                                                                                                                                            SHA1:F95EE7B1EF464F2640EC4AE29F3C18B5BF2B2905
                                                                                                                                                                                                            SHA-256:8698B0A53D858AEA7C495EDF759EF0E6C63F7E07A256599393DEC7B7A7413734
                                                                                                                                                                                                            SHA-512:BA5898ABEE541BC72C9DEDD77BABB18024C7AEA0274FA3F809748FCBFF770BFAD902BF70680DDE989F7D3592E5398C100D0E0EA388D4200911ED7DE089535D6D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Cairo) {.. {-9223372036854775808 7509 0 LMT}.. {-2185409109 7200 0 EET}.. {-929844000 10800 1 EEST}.. {-923108400 7200 0 EET}.. {-906170400 10800 1 EEST}.. {-892868400 7200 0 EET}.. {-875844000 10800 1 EEST}.. {-857790000 7200 0 EET}.. {-844308000 10800 1 EEST}.. {-825822000 7200 0 EET}.. {-812685600 10800 1 EEST}.. {-794199600 7200 0 EET}.. {-779853600 10800 1 EEST}.. {-762663600 7200 0 EET}.. {-399088800 10800 1 EEST}.. {-386650800 7200 0 EET}.. {-368330400 10800 1 EEST}.. {-355114800 7200 0 EET}.. {-336790800 10800 1 EEST}.. {-323654400 7200 0 EET}.. {-305168400 10800 1 EEST}.. {-292032000 7200 0 EET}.. {-273632400 10800 1 EEST}.. {-260496000 7200 0 EET}.. {-242096400 10800 1 EEST}.. {-228960000 7200 0 EET}.. {-210560400 10800 1 EEST}.. {-197424000 7200 0 EET}.. {-178938000 10800 1 EEST}.. {-165801600 7200 0 EET}.. {-147402000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):5532
                                                                                                                                                                                                            Entropy (8bit):3.535398586134154
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:zE+CJZtmaG6/eszBrlxs5MRhk9xPmwv7KbGKCDp0d:7MZSszBrlKcJC9k
                                                                                                                                                                                                            MD5:18183122D242E0B69A80BC02BC0328DF
                                                                                                                                                                                                            SHA1:C9976ABC0663EB29A2FEAAFDF6746C05A264B67C
                                                                                                                                                                                                            SHA-256:8776EEDFDFEE09C4C833593127CEFAC9C33E2487AB9BF4BF8C73E5E11B4E5613
                                                                                                                                                                                                            SHA-512:9611A6EF9C5B55FAB752C1EC7E464B8AF60AE32383CE9BA72F35168ABB68A45DB0654A9099CBDC123F5F6E2B6DB7C8FBF56A8DDB813824187AD1090971F12219
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Casablanca) {.. {-9223372036854775808 -1820 0 LMT}.. {-1773012580 0 0 +00}.. {-956361600 3600 1 +00}.. {-950490000 0 0 +00}.. {-942019200 3600 1 +00}.. {-761187600 0 0 +00}.. {-617241600 3600 1 +00}.. {-605149200 0 0 +00}.. {-81432000 3600 1 +00}.. {-71110800 0 0 +00}.. {141264000 3600 1 +00}.. {147222000 0 0 +00}.. {199756800 3600 1 +00}.. {207702000 0 0 +00}.. {231292800 3600 1 +00}.. {244249200 0 0 +00}.. {265507200 3600 1 +00}.. {271033200 0 0 +00}.. {448243200 3600 0 +01}.. {504918000 0 0 +00}.. {1212278400 3600 1 +00}.. {1220223600 0 0 +00}.. {1243814400 3600 1 +00}.. {1250809200 0 0 +00}.. {1272758400 3600 1 +00}.. {1281222000 0 0 +00}.. {1301788800 3600 1 +00}.. {1312066800 0 0 +00}.. {1335664800 3600 1 +00}.. {1342749600 0 0 +00}.. {1345428000 3600 1 +00}.. {1348970400 0 0 +00}.. {1367114400 3600 1 +00}.. {13731
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7536
                                                                                                                                                                                                            Entropy (8bit):3.8315604186920704
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:TzLdXKy9f4elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhltlUxo:TdayR41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                            MD5:30155093248C4F7E45EF7C0132D2B2AB
                                                                                                                                                                                                            SHA1:FAD100CC49F0CB0910BDE39B43295A47512E1BE6
                                                                                                                                                                                                            SHA-256:8827F7311EDE69A9679BDF2B7418DBF350A2FC8F973E8B1E1E4390D4D5C6D2E8
                                                                                                                                                                                                            SHA-512:469A24AF0C2A4A40CB2488C3E21BB9BBDE057F876EACA08A31FC6F22845063D917A0A4AE96680401E45792DE534EE3A305F137A93C4DF879B4602510D881270E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Ceuta) {.. {-9223372036854775808 -1276 0 LMT}.. {-2177452800 0 0 WET}.. {-1630112400 3600 1 WEST}.. {-1616810400 0 0 WET}.. {-1451692800 0 0 WET}.. {-1442451600 3600 1 WEST}.. {-1427673600 0 0 WET}.. {-1379293200 3600 1 WEST}.. {-1364774400 0 0 WET}.. {-1348448400 3600 1 WEST}.. {-1333324800 0 0 WET}.. {-1316390400 3600 1 WEST}.. {-1301270400 0 0 WET}.. {-1293840000 0 0 WET}.. {-94694400 0 0 WET}.. {-81432000 3600 1 WEST}.. {-71110800 0 0 WET}.. {141264000 3600 1 WEST}.. {147222000 0 0 WET}.. {199756800 3600 1 WEST}.. {207702000 0 0 WET}.. {231292800 3600 1 WEST}.. {244249200 0 0 WET}.. {265507200 3600 1 WEST}.. {271033200 0 0 WET}.. {448243200 3600 0 CET}.. {504918000 3600 0 CET}.. {512528400 7200 1 CEST}.. {528253200 3600 0 CET}.. {543978000 7200 1 CEST}.. {559702800 3600 0 CET}.. {575427600 7200 1 CEST}.. {591152400 3600
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):185
                                                                                                                                                                                                            Entropy (8bit):4.88110192592456
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2DcmMM1+DcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2DCM1+c
                                                                                                                                                                                                            MD5:8CDD2EEB7E0EC816F3EC051350FEBF13
                                                                                                                                                                                                            SHA1:37F3A149B4A01DFA2EAB42A28C810BE66AAB7C52
                                                                                                                                                                                                            SHA-256:3176C99FC45337CBCE0CD516DE4B02B8BAA47D00E84F698122A2ADD57797984E
                                                                                                                                                                                                            SHA-512:5A90B6DB45EDAD7734D596FB81FD1959A433F57E71D2212E1DCBD6A12F3FD1FE747FA363C4C787A4D3023F542553C1E2C9CF4F61E28F1BB13042E4AFE3D0FF31
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Conakry) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):183
                                                                                                                                                                                                            Entropy (8bit):4.856992353568779
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2DcXXMFBx/2DcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2DKXEBn
                                                                                                                                                                                                            MD5:946D3B52F915445DBB8EE8BF67F4EFAB
                                                                                                                                                                                                            SHA1:18345968B95E886CA72634D49F2B38F9B29BA629
                                                                                                                                                                                                            SHA-256:D50F9732757B284BAC75526F2CFA585DF7F6974160827AFB0FF66124C7CFD361
                                                                                                                                                                                                            SHA-512:00B531D1352CF35045EE25C777C7FEA17294E9861E68CE2DE0D9884C05EBDEA84D5F4F0E8B5605721295E25C259979446B7DB76525A633C7D2FA35B38962CF43
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Dakar) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):191
                                                                                                                                                                                                            Entropy (8bit):4.8447607449193075
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/2Dc8bEH+DcVVMMyn:SlSWB9vsM3y7VTHAIgNTxcAN/2DJbVDR
                                                                                                                                                                                                            MD5:7A819572758BC60F4085DF28F1DD1C01
                                                                                                                                                                                                            SHA1:0A5BA34EBFBA5A8E8B896713BA527781FC90FF01
                                                                                                                                                                                                            SHA-256:AB69948637416219A3D458777990FA4568BEBC89388884BBF129C0E1370A560B
                                                                                                                                                                                                            SHA-512:C03E785D1E85292056BB0BDD8DF8326C5DFEB6070AB1C071E1032D14EA69C9DEBC57B2CC7852E35D31652187126CCF0009A6A5C32F9DBB75D56C705535DF05CC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Dar_es_Salaam) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):186
                                                                                                                                                                                                            Entropy (8bit):4.829357904445218
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/2DcRHKQ1BQDcVVMMyn:SlSWB9vsM3y7VTHAIgNTxcAN/2DOrkDR
                                                                                                                                                                                                            MD5:7981499F9430DC1636C9F834273E0B91
                                                                                                                                                                                                            SHA1:1D63F8578420D56E4A5D9D0881FBEC015421E416
                                                                                                                                                                                                            SHA-256:E7F7560CCD65D53C446ADAE7128A74D37E17DD0B907A2F2FD85322FB8707B497
                                                                                                                                                                                                            SHA-512:3C3F7D78E9A0DE6E2950E1C305EA2DBC986754AE9FB10AC410685F30C39EC235F6F221393099C012E62EE5A7B4F1BED67C96B7B81E90BBA064BA9FE685FE4050
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Djibouti) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):178
                                                                                                                                                                                                            Entropy (8bit):4.850101792457859
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsGe/vXHAIgNGESuvHRL/2DcnKe2DcGeyn:SlSWB9vsM3y7VXHAIgNTTN/2Dml2D4yn
                                                                                                                                                                                                            MD5:44881E75AC32FA95FF6143066EF01B90
                                                                                                                                                                                                            SHA1:A221619B4CDE8BE6A181E1F3869EAB665F2E98B8
                                                                                                                                                                                                            SHA-256:FCF2DAD148F4D2951320EA99730C56D5EB43D505F37416BE4BAD265CE2902706
                                                                                                                                                                                                            SHA-512:4FA67A5F84758366189F0FC4A7FA6C820BA083E1C56EA95D25D21A367F25F76261B7EB5631DFFEB20E095CFD64E770338773F76BD50D4CF6AE29AD3EDFCEC408
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Douala) $TZData(:Africa/Lagos)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):5235
                                                                                                                                                                                                            Entropy (8bit):3.541189246992611
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:+eCJZtmaG6/eszBrlxs5MRhk9xPmwv7KbGKCDp0d:+eqZSszBrlKcJC9k
                                                                                                                                                                                                            MD5:956F5B51FA8BA2E954A0E59AAC8F3276
                                                                                                                                                                                                            SHA1:AE35A8502E57EA6EE173E3B42509E4CAC73DA091
                                                                                                                                                                                                            SHA-256:5FB102A95B3C004AAB8371840B1A04AC352F48FF9E9EAFDEAAF21960B0F3CAA6
                                                                                                                                                                                                            SHA-512:19E7F2574E2B62DF68CC24737F6B94864B3D64B2472BC7D78E6AB5142A1DC1AB3B3700AB802129CB16AED4A4FED29E2B8A5593EE327ADF496255FE2FEF6A7023
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/El_Aaiun) {.. {-9223372036854775808 -3168 0 LMT}.. {-1136070432 -3600 0 -01}.. {198291600 0 0 +00}.. {199756800 3600 1 +00}.. {207702000 0 0 +00}.. {231292800 3600 1 +00}.. {244249200 0 0 +00}.. {265507200 3600 1 +00}.. {271033200 0 0 +00}.. {1212278400 3600 1 +00}.. {1220223600 0 0 +00}.. {1243814400 3600 1 +00}.. {1250809200 0 0 +00}.. {1272758400 3600 1 +00}.. {1281222000 0 0 +00}.. {1301788800 3600 1 +00}.. {1312066800 0 0 +00}.. {1335664800 3600 1 +00}.. {1342749600 0 0 +00}.. {1345428000 3600 1 +00}.. {1348970400 0 0 +00}.. {1367114400 3600 1 +00}.. {1373162400 0 0 +00}.. {1376100000 3600 1 +00}.. {1382839200 0 0 +00}.. {1396144800 3600 1 +00}.. {1403920800 0 0 +00}.. {1406944800 3600 1 +00}.. {1414288800 0 0 +00}.. {1427594400 3600 1 +00}.. {1434247200 0 0 +00}.. {1437271200 3600 1 +00}.. {1445738400 0 0 +00}.. {1
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):186
                                                                                                                                                                                                            Entropy (8bit):4.866631090752554
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2Dcu5sp4DcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2Dk4DBS
                                                                                                                                                                                                            MD5:6C115220CF951FC2EE3C299F86935B6D
                                                                                                                                                                                                            SHA1:A1CAB8C710BF20553AF45343118C1726CFE922B7
                                                                                                                                                                                                            SHA-256:BC53A4D489F48F14C594C4B0E52079B34E043A5751BBC7DF254A560352243575
                                                                                                                                                                                                            SHA-512:E87A4FD145B645DF034182CAD7F9D2BE5B2D9F3A17B6A9B6C84A0B3E846D92EC4C69DF2E85129B7A1AFBC0CCAAC8E3B1D47EB09F0900A82B908E9F6BF63B9736
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Freetown) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):183
                                                                                                                                                                                                            Entropy (8bit):4.899477454245453
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsfKG5XHAIgNGEjKORL/2DcHK0o/4DcfKB:SlSWB9vsM3y7fnHAIgNTjdN/2DAV+4Dt
                                                                                                                                                                                                            MD5:07222D8ED83CDC456B4D5D84C4BDE320
                                                                                                                                                                                                            SHA1:2C657F461FA3F48D56C791AFE4AB7D2EAF45AF60
                                                                                                                                                                                                            SHA-256:653AF88955C4418D973E2F8681A99552EB7BE95BCA64C736072F488462F7B373
                                                                                                                                                                                                            SHA-512:3016D0636F401BD88BCD460F6A61782E7E8A2C32CE4ECB904C711DF414038A5818F0CA3D7FC671C5ABCE70647FC674A2EF9081C5289EBFD184B44885902E007A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Gaborone) $TZData(:Africa/Maputo)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):181
                                                                                                                                                                                                            Entropy (8bit):4.884642061266759
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsfKG5XHAIgNGEjKORL/2Dc0B5h4DcfKB:SlSWB9vsM3y7fnHAIgNTjdN/2Dlfh4Dt
                                                                                                                                                                                                            MD5:8666DABE8D196ACD94A9691C592FAF4E
                                                                                                                                                                                                            SHA1:9F7EE009DCEAACA79C6EAA6FC73015D595467919
                                                                                                                                                                                                            SHA-256:06B82C524585192E0E8FC69DCC1CF86183A8C5EF404645DC413FCF3F8C16B0AB
                                                                                                                                                                                                            SHA-512:AAA32FD1B01BFECDD0D1C9C1DF1163374DAFE094C75720EA4095C34F7EAE7DCB594D1A7F6A2A90FB43FF01020F7AEB48E92496E0EE2D039AF23076CD369DD2A7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Harare) $TZData(:Africa/Maputo)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):309
                                                                                                                                                                                                            Entropy (8bit):4.695542624694403
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2DWbzDm2OHePoHvmmXsd//HF2d7d6VcF2d6KsYov:MB862DW7mdHePCvmmcZvF0cVcF/KsFv
                                                                                                                                                                                                            MD5:F0E153FC9B978E30742ABC025CA45E02
                                                                                                                                                                                                            SHA1:73D96F3188190DAC2453E6F18A1C683CECB9CDE3
                                                                                                                                                                                                            SHA-256:5EEF6475E1312051037FCAE3354E32DC0910BE7A5116B71F8CCBE1CCA08D3F1C
                                                                                                                                                                                                            SHA-512:E66F4B5FF18BAAD53AFB1ED36A0827115C793075A61F794F26F32BC9F6799DF816A1F817BEB0C0BC938F89E6F5BFBE1AB4F504F1AF518764103FB287746552C7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Johannesburg) {.. {-9223372036854775808 6720 0 LMT}.. {-2458173120 5400 0 SAST}.. {-2109288600 7200 0 SAST}.. {-860976000 10800 1 SAST}.. {-845254800 7200 0 SAST}.. {-829526400 10800 1 SAST}.. {-813805200 7200 0 SAST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1127
                                                                                                                                                                                                            Entropy (8bit):4.027824722230131
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5mesdOkMV0GbMSHMzNy8MXLwM0JXMfCsMzaMq0QM3W50dM44R8M1XMreM7p0z8M5:5YMV04MSHMzNxMbwM0JXMfCsMzaMq0QJ
                                                                                                                                                                                                            MD5:32EC0589260D9D4BCC85FE91E6F04D00
                                                                                                                                                                                                            SHA1:BAA269852C4AC6B89EA7941E7A75A007E0CF9EDF
                                                                                                                                                                                                            SHA-256:F2646E15488ABF2E960759CEFE5705416E71DA71BB8407B26196244FD1A3394F
                                                                                                                                                                                                            SHA-512:4F485453BE1D186ADBE0908852475C63C57BA498091C222EFFB9A5FEA2DB7F55E1BB2DBDBF6AC0F24CC67D47549FA3F5257655B5449B1BCF1FB5CDB27B03D501
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Juba) {.. {-9223372036854775808 7588 0 LMT}.. {-1230775588 7200 0 CAT}.. {10360800 10800 1 CAST}.. {24786000 7200 0 CAT}.. {41810400 10800 1 CAST}.. {56322000 7200 0 CAT}.. {73432800 10800 1 CAST}.. {87944400 7200 0 CAT}.. {104882400 10800 1 CAST}.. {119480400 7200 0 CAT}.. {136332000 10800 1 CAST}.. {151016400 7200 0 CAT}.. {167781600 10800 1 CAST}.. {182552400 7200 0 CAT}.. {199231200 10800 1 CAST}.. {214174800 7200 0 CAT}.. {230680800 10800 1 CAST}.. {245710800 7200 0 CAT}.. {262735200 10800 1 CAST}.. {277246800 7200 0 CAT}.. {294184800 10800 1 CAST}.. {308782800 7200 0 CAT}.. {325634400 10800 1 CAST}.. {340405200 7200 0 CAT}.. {357084000 10800 1 CAST}.. {371941200 7200 0 CAT}.. {388533600 10800 1 CAST}.. {403477200 7200 0 CAT}.. {419983200 10800 1 CAST}.. {435013200 7200 0 CAT}.. {452037600 10800 1 CAST}.. {466635600 7200
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):185
                                                                                                                                                                                                            Entropy (8bit):4.837466713772859
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/2DcJEl2DcVVMMyn:SlSWB9vsM3y7VTHAIgNTxcAN/2DIEl2V
                                                                                                                                                                                                            MD5:E929ED1BC316C71AABE7E625BD562FB1
                                                                                                                                                                                                            SHA1:C20C172518C02D93327F4BBBC5D410BFFEF5039D
                                                                                                                                                                                                            SHA-256:8EA3028CE2B025F0C457DC8F7601279CA5AF565A88B9FE80208F9F1030F2B0D0
                                                                                                                                                                                                            SHA-512:B2FBCF06EACCF18DE97AF1D6BC57D9638E0A36DBF17044FF97F6B9E5089CF9E13E1304F304495324C0ACC1128A7D2D494E7C1FDB95DB0855FCE54F7028096C50
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Kampala) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1131
                                                                                                                                                                                                            Entropy (8bit):4.0421745451318385
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5xe9dSXMV0GbMSHMzNy8MXLwM0JXMfCsMzaMq0QM3W50dM44R8M1XMreM7p0z8MM:5hMV04MSHMzNxMbwM0JXMfCsMzaMq0Qc
                                                                                                                                                                                                            MD5:2BD3850DDBE2F05BF6F24F3AEFF7516C
                                                                                                                                                                                                            SHA1:22B0DBB54E071F30D51A8654CF103F99537F74CD
                                                                                                                                                                                                            SHA-256:F475DB8A857A46B310B12C21D6A9BC6CA9FF2960DA429A9D57FA375F9439E13B
                                                                                                                                                                                                            SHA-512:1CF82FC07348C697F26625673DA7E3D734358B3FBE69D8E2132CAC0D9F00C7E8CDC353676CD9BAC4CBB9E26CF6638CEAE41DF559E7445D9C453409D7115FFC6C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Khartoum) {.. {-9223372036854775808 7808 0 LMT}.. {-1230775808 7200 0 CAT}.. {10360800 10800 1 CAST}.. {24786000 7200 0 CAT}.. {41810400 10800 1 CAST}.. {56322000 7200 0 CAT}.. {73432800 10800 1 CAST}.. {87944400 7200 0 CAT}.. {104882400 10800 1 CAST}.. {119480400 7200 0 CAT}.. {136332000 10800 1 CAST}.. {151016400 7200 0 CAT}.. {167781600 10800 1 CAST}.. {182552400 7200 0 CAT}.. {199231200 10800 1 CAST}.. {214174800 7200 0 CAT}.. {230680800 10800 1 CAST}.. {245710800 7200 0 CAT}.. {262735200 10800 1 CAST}.. {277246800 7200 0 CAT}.. {294184800 10800 1 CAST}.. {308782800 7200 0 CAT}.. {325634400 10800 1 CAST}.. {340405200 7200 0 CAT}.. {357084000 10800 1 CAST}.. {371941200 7200 0 CAT}.. {388533600 10800 1 CAST}.. {403477200 7200 0 CAT}.. {419983200 10800 1 CAST}.. {435013200 7200 0 CAT}.. {452037600 10800 1 CAST}.. {466635600 7
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):181
                                                                                                                                                                                                            Entropy (8bit):4.910322325134086
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsfKG5XHAIgNGEjKORL/2DcCJRx+DcfKB:SlSWB9vsM3y7fnHAIgNTjdN/2DRX+DEi
                                                                                                                                                                                                            MD5:3017253E1C6ACCA8D470A014E4BB321D
                                                                                                                                                                                                            SHA1:671B7AC04580B56E2C34F88D123E8296947DDD7E
                                                                                                                                                                                                            SHA-256:73FEB807006897B4B485CB82394867444E890265EFE960EC66D6C0E325DA9372
                                                                                                                                                                                                            SHA-512:2498C380D761A16C183D78BC1BB18B1D2A1BFCB9C703D86A3FC04CCCE43D88C8D4BC3C47CC31639B78A5FE9C8A7445E9DBB52062E2F3B737DA1E7D0FF70F140A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Kigali) $TZData(:Africa/Maputo)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):180
                                                                                                                                                                                                            Entropy (8bit):4.866127364448228
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsGe/vXHAIgNGESuvHRL/2DcqQFeDcGeyn:SlSWB9vsM3y7VXHAIgNTTN/2DdD4yn
                                                                                                                                                                                                            MD5:41209A335A99803239A854575190C5ED
                                                                                                                                                                                                            SHA1:E6EA627C25513B9DDE053F9A24D509AA317C30A1
                                                                                                                                                                                                            SHA-256:611375C4901AD6C4844C2BB7D02FB17F34996F49E642546A6784D6F0B28530CC
                                                                                                                                                                                                            SHA-512:DF2C0B131F35F54DF5EBF7F8459F98DBABEB6F081247BA95B5D7B41146E2A2EF9BC6B1D909DE57A1223D9C258AB197D9668ED2E111A365C86BABDAA7DF551FB6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Kinshasa) $TZData(:Africa/Lagos)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):235
                                                                                                                                                                                                            Entropy (8bit):4.7936510664790815
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2D4JDm2OHWQvvoHvBsp9boFvoHzIX7uRe6vF9:MB862DymdHWQCvqpmVCzIq
                                                                                                                                                                                                            MD5:EC08046589E85D999A597252FF5368B7
                                                                                                                                                                                                            SHA1:126E3DE158E1E7AF4737D0AB5B51C0F92F416DC7
                                                                                                                                                                                                            SHA-256:DCC9F52F539A67DFD7ABAFDE072ACDAE2B67754C559C8A5FE61979F5A286A066
                                                                                                                                                                                                            SHA-512:84B9AB18BC343C8B8934F5FDD2E2EB413925B04D6F5394AA8337B7B55E6487FB071A83A69BD4D0FA40F7F31EBC57B9908729674542CEA3083D700FCD02D77633
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Lagos) {.. {-9223372036854775808 815 0 LMT}.. {-2035584815 0 0 GMT}.. {-1940889600 815 0 LMT}.. {-1767226415 1800 0 +0030}.. {-1588465800 3600 0 WAT}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):182
                                                                                                                                                                                                            Entropy (8bit):4.865878143076229
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsGe/vXHAIgNGESuvHRL/2Dcr7bp4DcGeyn:SlSWB9vsM3y7VXHAIgNTTN/2Dgfp4D4y
                                                                                                                                                                                                            MD5:35D8A58EE21E603C6FC4FB896AE6B3D0
                                                                                                                                                                                                            SHA1:F1D0A939D761F3F0954F045814CF5339A5597036
                                                                                                                                                                                                            SHA-256:AB3E797548C7663CF9ABA7FE163635FF7CAB9E6CB61FA1644C0F7B4B5CCE8B99
                                                                                                                                                                                                            SHA-512:97717961987F6B6832C24A7833150CDFE7E82BBEB32DFDB84D2500442AAD9263F8BD4E879591E913D56E9A1991C389EF730211853647A889F358AE3FA37C0185
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Libreville) $TZData(:Africa/Lagos)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):182
                                                                                                                                                                                                            Entropy (8bit):4.862780607964543
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2Dcih4DcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2DNh4D4
                                                                                                                                                                                                            MD5:EA21ABBF8B11953916A1C509B8A1B427
                                                                                                                                                                                                            SHA1:35ADC230C57B001BE8A99A3D2E34B609A60A1162
                                                                                                                                                                                                            SHA-256:EACA9124F17E5B11F27D11FA6141D19EB3AC23E155E155B73467BDAA3BC99AA7
                                                                                                                                                                                                            SHA-512:A7972D4F1C5FB988CA04B39E2CDD580F51383BA9D7A66C478275C11A07B8D7A6EFF53A3E1929B0D89F10BCC39D22F285DB2601ED60DB4647C65465643F70C137
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Lome) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):178
                                                                                                                                                                                                            Entropy (8bit):4.856982839546061
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsGe/vXHAIgNGESuvHRL/2DccLtBQDcGeyn:SlSWB9vsM3y7VXHAIgNTTN/2DXQD4yn
                                                                                                                                                                                                            MD5:40CD47F6DCF51EBEFEF42489F1716257
                                                                                                                                                                                                            SHA1:DF245192A1899A72DE01A57F6969AC060E841734
                                                                                                                                                                                                            SHA-256:4C2FD1E44DFAAF0C0DD2EB56B84B538F1E2D84B301AB2CFB8EE7759783501444
                                                                                                                                                                                                            SHA-512:D39BEB0EEF344B1A44F7D6A806A1D5B956D7D402648EE0C67C4BA46493236840AF975D89A91B2D33B8AA7D6DC9A051E66718DCDBC1C83B0E964215C2E32ED923
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Luanda) $TZData(:Africa/Lagos)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):185
                                                                                                                                                                                                            Entropy (8bit):4.940313336280723
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsfKG5XHAIgNGEjKORL/2DcfpT0DcfKB:SlSWB9vsM3y7fnHAIgNTjdN/2D8pT0Dt
                                                                                                                                                                                                            MD5:71A5DE1276902DB1542840318F9B1AF3
                                                                                                                                                                                                            SHA1:AC3825BF343482E0E4D9D6FAA6FCA4D1A125433B
                                                                                                                                                                                                            SHA-256:24384EEC359FD24D181AAEF3C017E3C345490A8D352B29D19B1B143A29A811C2
                                                                                                                                                                                                            SHA-512:2984EB42A79B8B32BB93DFE71F1C4C0CABFDC9B0A199971347BB3473463FA07FDB5D20227D288BF8653B1BDE347E1297459BBB4C3C34AF7A5434FBF945683577
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Lubumbashi) $TZData(:Africa/Maputo)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):181
                                                                                                                                                                                                            Entropy (8bit):4.905174746463853
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsfKG5XHAIgNGEjKORL/2DcOf+DcfKB:SlSWB9vsM3y7fnHAIgNTjdN/2DkDEi
                                                                                                                                                                                                            MD5:1D7FDB388535CC59742CA0F1AEE27FBD
                                                                                                                                                                                                            SHA1:A99FF2CAC47FD333429C22B271E190D979EEC024
                                                                                                                                                                                                            SHA-256:B00801A7279741434D9C2D7EC7322DD93B85EA4F5C9976AB3A43F0AB142E1553
                                                                                                                                                                                                            SHA-512:0174D3C6F9116C36C62AD1EB58203EE7DFE8C37F618B8449D5E45AD6290CF8334F28798877D7A563A12EE533026244D6A49BCCF29B5D7FCB5BCC91481D0DDDE2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Maputo)]} {.. LoadTimeZoneFile Africa/Maputo..}..set TZData(:Africa/Lusaka) $TZData(:Africa/Maputo)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):178
                                                                                                                                                                                                            Entropy (8bit):4.857096806490649
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsGe/vXHAIgNGESuvHRL/2Dcn2DcGeyn:SlSWB9vsM3y7VXHAIgNTTN/2D42D4yn
                                                                                                                                                                                                            MD5:1CA9B3E7BCD5BC1CC881453D16B09389
                                                                                                                                                                                                            SHA1:1B1964B314E72847D71A42C147CF2BF331B44461
                                                                                                                                                                                                            SHA-256:35D56EFFE9E7E60F17B32BD30486E566B635F0AE7A8948D77395B8E6332E26F1
                                                                                                                                                                                                            SHA-512:9E08D57B7824F5B076D159D9A5106E51450DF24729C36F485B9B68E8F47E8DFC50F9BEC3F11E0AE6579A8E372A5C0F0DA18A2E797CF2115519D1B4E5B64413DD
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Malabo) $TZData(:Africa/Lagos)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):149
                                                                                                                                                                                                            Entropy (8bit):4.952872531197478
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/2DcfKiMXGm2OHoVoHvdSF2I:SlSWB9eg/2DEZDm2OHoVoHvdI
                                                                                                                                                                                                            MD5:CD429B6891CBF603A93F9A9733E2391B
                                                                                                                                                                                                            SHA1:C6833B83B6D1694AC632018A27915E6F97F708AE
                                                                                                                                                                                                            SHA-256:FE6B6A4BE1B61F7F909A3F6137530DFE6D1754499A4D9B0D1CE4952FFF0AE62D
                                                                                                                                                                                                            SHA-512:6E57B70B71515998AD617954F9DDAE19968B20946542201153DAB47FBE63790D42F41AE29148ECBCE6D12812879BCF0A4EC881507B62CDB2675AB20267220BF9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Maputo) {.. {-9223372036854775808 7820 0 LMT}.. {-2109291020 7200 0 CAT}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):199
                                                                                                                                                                                                            Entropy (8bit):4.964472328419063
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7HbsSHAIgNTzbrN/2DZQs+DWb4n:MByMaHw7NH/t2DZiDWU
                                                                                                                                                                                                            MD5:88C8FF2B480648EDADBD0FB93F754275
                                                                                                                                                                                                            SHA1:BED7A784C378909914CEB0D303DFE6D05FD576B7
                                                                                                                                                                                                            SHA-256:1D80FD86CB733D57D88ECD404E702F750B233ED0CCBFBFFFEED1AAD3B7F1CB04
                                                                                                                                                                                                            SHA-512:CB7F831CF099E85B948AE57FCE9D91C7EAAD39753AF82C56EC15B65830EB4115A71BBC83A71A2AC947CAB24DEDDB557E02FAA5A3264546AE6E60607DF6BD2FA3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Johannesburg)]} {.. LoadTimeZoneFile Africa/Johannesburg..}..set TZData(:Africa/Maseru) $TZData(:Africa/Johannesburg)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):200
                                                                                                                                                                                                            Entropy (8bit):4.957246428185456
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7HbsSHAIgNTzbrN/2DzjEHp4DWb4n:MByMaHw7NH/t2DzjEJ4DWU
                                                                                                                                                                                                            MD5:CA7255B86425BA706D214924856B6818
                                                                                                                                                                                                            SHA1:E9BE6CF871BB1786E842953D41392299952EC9AC
                                                                                                                                                                                                            SHA-256:547197C09C1987350AE5720A4EEC7E8D8F4B9F4A0559726E225E13C707F7C564
                                                                                                                                                                                                            SHA-512:23F9AD0F926A0945A17BBC3DCFF9A3D7EE68EC9423EA78985F5FFC60CC61641B57871F9AA703B5FB9BE842DCD4693D0641F9EDED702240873F58D24CD4D60C32
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Johannesburg)]} {.. LoadTimeZoneFile Africa/Johannesburg..}..set TZData(:Africa/Mbabane) $TZData(:Africa/Johannesburg)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):187
                                                                                                                                                                                                            Entropy (8bit):4.877126792757121
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/2DcBEBXCEeDcVVMMyn:SlSWB9vsM3y7VTHAIgNTxcAN/2DFSVDR
                                                                                                                                                                                                            MD5:5C2E2B5189E0E816D5BD7AFC8B49A35E
                                                                                                                                                                                                            SHA1:4E43A1ED51399528636D6442B1DDFFD820911407
                                                                                                                                                                                                            SHA-256:25E221BE49DEC5547A74AEB91B0041859C59BC866987272A447AB2343D1CC30C
                                                                                                                                                                                                            SHA-512:B74735CFAB692756BAADFB1A51A8CC0C986F981D8E7E7A8182370A9017E67439875F0115820A349AFB3BE2FA581A721440968EF817471DD2C5E1286E53B2FE99
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Africa/Mogadishu) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):208
                                                                                                                                                                                                            Entropy (8bit):4.8660011420394955
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2D3NPDm2OHrFGxYoHvlHIg5pTwdPsy:MB862D3NbmdHhmYCvdIg5GPsy
                                                                                                                                                                                                            MD5:1B3C94B5098E454981C73C1F2AF80164
                                                                                                                                                                                                            SHA1:1EBA9E2DBEA70BB1AE5EB13739518AB5A62D2130
                                                                                                                                                                                                            SHA-256:2BF0D90610211651127402680519B29AB50B15D344263D0C1A22EDEBE5E01E27
                                                                                                                                                                                                            SHA-512:DA4A0BCE7C6750BD7D3BA76B6301B9390723BE0C001C39BE453D80BD87020C2253A75629F68F83C19410D2A75FAF5223A435299CD4AA53DE545EC7C5B5AA54B7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Monrovia) {.. {-9223372036854775808 -2588 0 LMT}.. {-2776979812 -2588 0 MMT}.. {-1604359012 -2670 0 MMT}.. {63593070 0 0 GMT}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):277
                                                                                                                                                                                                            Entropy (8bit):4.655052651600954
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2Dk1Dm2OHsvT5oH99VCV22ufPnVCkVBKBQn9q:MB862DGmdHsvVCjkifvdH9q
                                                                                                                                                                                                            MD5:B640661FB37BB74FAB172DBDF1B433E1
                                                                                                                                                                                                            SHA1:0236A5B53443A4A18B8B9D6AA7732620BE9A6553
                                                                                                                                                                                                            SHA-256:BD8E9765174431C0D403249D3E881C949C83966E9F8162552DA88AE53132467B
                                                                                                                                                                                                            SHA-512:53DCC6DF7C3E0B00A6D98A8DCC4988C8CFD6B53CC89E6F8D32DA41CB532A62D9C6A823675C5039F5639CE0D423F6D571F46F5B93FFC7EFFB4EDFFBF89D46AA12
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Nairobi) {.. {-9223372036854775808 8836 0 LMT}.. {-1946168836 9000 0 +0230}.. {-1309746600 10800 0 EAT}.. {-1261969200 9000 0 +0230}.. {-1041388200 9900 0 +0245}.. {-865305900 10800 0 EAT}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):208
                                                                                                                                                                                                            Entropy (8bit):4.856754881865487
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2DjUfDm2OHNseoH1axCXFHzaSmkFWTvF9:MB862DjULmdHPC1XNzaS3yz
                                                                                                                                                                                                            MD5:EDB548348E590C8CFE04ED172D96B86C
                                                                                                                                                                                                            SHA1:AD3B631FB03819772164402E202AFA781687F597
                                                                                                                                                                                                            SHA-256:9ADA5F5AFB25E823E1F0E8AD2489AAA1C09F01356634A9403670D7AB21CA2E2C
                                                                                                                                                                                                            SHA-512:17E396A9BE497077B774AD1108CC8760ED35FC92F65FFF070F9ACD3C4FB67A335C1C57DF1CCB1570DE14B708EFCA0063990A969E30759C9A47731DA45ED25EFE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Ndjamena) {.. {-9223372036854775808 3612 0 LMT}.. {-1830387612 3600 0 WAT}.. {308703600 7200 1 WAST}.. {321314400 3600 0 WAT}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):178
                                                                                                                                                                                                            Entropy (8bit):4.871519187180041
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsGe/vXHAIgNGESuvHRL/2DcdhA9Ff2DcGeyn:SlSWB9vsM3y7VXHAIgNTTN/2Dsh2f2D1
                                                                                                                                                                                                            MD5:0134039CD1666E983A9B6E43ABD6AF59
                                                                                                                                                                                                            SHA1:A2A99345390F4D17C892CEADE58C604257686764
                                                                                                                                                                                                            SHA-256:B517120AD8DB3F21EAB4E44A78001EE856EB4EA35852C54CCA96D38887DEBCFA
                                                                                                                                                                                                            SHA-512:E5911ADD3D776D87ACFC986C4D2564E3ED9AB12C67F23391ED35FF2A31AD8314B873E31DB8DA4D5E0DAEA12BE34110A8F0C27C9C6126977BAD51C6AD5CDFA39B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Niamey) $TZData(:Africa/Lagos)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):188
                                                                                                                                                                                                            Entropy (8bit):4.909962899502589
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2DcboGb+DcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2Dqbb+c
                                                                                                                                                                                                            MD5:550E482599C2F4280F2C258019BB2547
                                                                                                                                                                                                            SHA1:A39045BEF313094CEDC100A7D695AE51BC9E498D
                                                                                                                                                                                                            SHA-256:64CAF2BF9D45095DF97F419714D5617CF6300ACDB544B621DCE1D594AA9B910C
                                                                                                                                                                                                            SHA-512:4FD29C5B4C0D2BDE69C437E9BF4F08A11E1DAAA689B69F28F3551F550BDCCDD055E4C1A241EDB2FA48B18825AFF792F4860F55983E106EA8224F1D87ED4F7546
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Nouakchott) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):189
                                                                                                                                                                                                            Entropy (8bit):4.920023025906233
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2DcXCZDcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2D1DBS
                                                                                                                                                                                                            MD5:6CFC4E938E50C9B591F8CC42A14FA82A
                                                                                                                                                                                                            SHA1:FCE14A5CA62C9005C76D27B849A238E76C834F8A
                                                                                                                                                                                                            SHA-256:03B9C1FE350B5E9F6F333F9519FA394DCC562308D9388A903AF3D3FECEBDC762
                                                                                                                                                                                                            SHA-512:98F22F1D23A9930276A2D306A1473E64DC43547A16CFD01226E4F030A26A3CC4FDED77F790583CC5C078FC6DFCCE81C16A50879AE46A0D3A6F1FA98373F413C7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Ouagadougou) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):182
                                                                                                                                                                                                            Entropy (8bit):4.893842293207225
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsGe/vXHAIgNGESuvHRL/2DcyTKM0DcGeyn:SlSWB9vsM3y7VXHAIgNTTN/2DQD4yn
                                                                                                                                                                                                            MD5:6D979FCD225D5431C7391AE568C6409F
                                                                                                                                                                                                            SHA1:6C9DCD222061CC00FD386773C6BB2861F3429A60
                                                                                                                                                                                                            SHA-256:8FB8692DB9281AE2B087D704168BFD47D3D0901781FEF65BFD62FCB213BA6B50
                                                                                                                                                                                                            SHA-512:32AFA6AF6BFC3D42CA636DD2B96906048EF1ADFBB135BB7E7B77C444FED99FDABB84FBBADF56EC63828FFA7B3371191FF1311822B1C75241EBD9CF602467088E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Lagos)]} {.. LoadTimeZoneFile Africa/Lagos..}..set TZData(:Africa/Porto-Novo) $TZData(:Africa/Lagos)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):234
                                                                                                                                                                                                            Entropy (8bit):4.818597723513168
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2DXDm2OHH5oHvzdoH1aNbbFHRMy:MB862DTmdHH5CvzdC16bZRMy
                                                                                                                                                                                                            MD5:28A5967C797F4B38FB63F823D6F07168
                                                                                                                                                                                                            SHA1:17872E91683B884191D2E4C777FB79DCE6D73EE7
                                                                                                                                                                                                            SHA-256:BA1D60DF2B41320F92A123A714E17E576C89383526B96E0541A464C3FBA415B7
                                                                                                                                                                                                            SHA-512:B335E3D3268631F3A71F4BAD59740F3A5222344E8223C201B8FE885BAA7F1A550FA7778E498D6DC2111F41053856F50B21413AECCE84B80833EC8176F2A1009C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Sao_Tome) {.. {-9223372036854775808 1616 0 LMT}.. {-2713912016 -2205 0 LMT}.. {-1830384000 0 0 GMT}.. {1514768400 3600 0 WAT}.. {1546304400 0 0 GMT}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):186
                                                                                                                                                                                                            Entropy (8bit):4.905303708777235
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2DcHdDcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2DwdDBS
                                                                                                                                                                                                            MD5:F2D7F7BC4EA3629EC7F0E45300A0CFD2
                                                                                                                                                                                                            SHA1:E7594D378C5DCFEB1E87E13AC79A026260D2E630
                                                                                                                                                                                                            SHA-256:9D8009ACAB019B32B1E87AB10E0AC3765ABCABE8066318DA8CA4905D41562F72
                                                                                                                                                                                                            SHA-512:795E58172907020C85CF0B10BBA35842D5F92872CCB3382DFDC787BAA504C79927FA23BC3104AD63541A95C44CA80977E8247846DE918A0B00963B970F4823D2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Africa/Timbuktu) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):954
                                                                                                                                                                                                            Entropy (8bit):4.151253074491018
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB862DrmdHrCDWR+f7Zn9ueRSmNvlTtuyI/ZBv8dq8Jw4VFZBZYEuAENSfp8kSYx:5veuDkWx3NdT18kbjjAkxTx
                                                                                                                                                                                                            MD5:2DF9B050D82B06EB89DA908C31C1F1C9
                                                                                                                                                                                                            SHA1:CB294E12560A98D5CEA3BA7004B5519B6C22BAAC
                                                                                                                                                                                                            SHA-256:B447B6B1C351E77F22A2D77C0437F2BBB7D8BDFDFDC3D6285E0D260519CC7110
                                                                                                                                                                                                            SHA-512:BBE281D551E9F8DA7B6BB08D809177615410A11E4B1184ABD220EA8B1F355B2BBC090C6BAAF7E07FD61286891388ECD4026D4433C4E4B6A8D201F8D95E174532
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Tripoli) {.. {-9223372036854775808 3164 0 LMT}.. {-1577926364 3600 0 CET}.. {-574902000 7200 1 CEST}.. {-512175600 7200 1 CEST}.. {-449888400 7200 1 CEST}.. {-347158800 7200 0 EET}.. {378684000 3600 0 CET}.. {386463600 7200 1 CEST}.. {402271200 3600 0 CET}.. {417999600 7200 1 CEST}.. {433807200 3600 0 CET}.. {449622000 7200 1 CEST}.. {465429600 3600 0 CET}.. {481590000 7200 1 CEST}.. {496965600 3600 0 CET}.. {512953200 7200 1 CEST}.. {528674400 3600 0 CET}.. {544230000 7200 1 CEST}.. {560037600 3600 0 CET}.. {575852400 7200 1 CEST}.. {591660000 3600 0 CET}.. {607388400 7200 1 CEST}.. {623196000 3600 0 CET}.. {641775600 7200 0 EET}.. {844034400 3600 0 CET}.. {860108400 7200 1 CEST}.. {875919600 7200 0 EET}.. {1352505600 3600 0 CET}.. {1364515200 7200 1 CEST}.. {1382662800 7200 0 EET}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1111
                                                                                                                                                                                                            Entropy (8bit):4.150944563639585
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB862DHmdHjCvbB/lxRjntMVyoKCyFWeey0XSe/OSyHaCgmvLOcSFQSFeSTC6ZPJ:5LemvbplxRhbv+yuh2tIee6kvcw9Cy
                                                                                                                                                                                                            MD5:0C99335A41D33AA8BC1EDA0CB4CDCBF5
                                                                                                                                                                                                            SHA1:5CABC28D318FA5B8307429EA571FFF91EB8E1252
                                                                                                                                                                                                            SHA-256:0760D1028E733888E43E7F1E057217DC2B52786029FCEC67B27EB69CC6A54938
                                                                                                                                                                                                            SHA-512:C8FE685ACA46FD4836F3AABC15833F294E5EBED123A487D04E74A8C5668BDFAFB96D2326760452A6E5A1B9CC25AC6C3918D8C10A7F8EF737456640E3000BBA2F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Tunis) {.. {-9223372036854775808 2444 0 LMT}.. {-2797202444 561 0 PMT}.. {-1855958961 3600 0 CET}.. {-969242400 7200 1 CEST}.. {-950493600 3600 0 CET}.. {-941940000 7200 1 CEST}.. {-891136800 3600 0 CET}.. {-877827600 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-842918400 3600 0 CET}.. {-842223600 7200 1 CEST}.. {-828230400 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796269600 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-766634400 3600 0 CET}.. {231202800 7200 1 CEST}.. {243903600 3600 0 CET}.. {262825200 7200 1 CEST}.. {276044400 3600 0 CET}.. {581122800 7200 1 CEST}.. {591145200 3600 0 CET}.. {606870000 7200 1 CEST}.. {622594800 3600 0 CET}.. {641516400 7200 1 CEST}.. {654649200 3600 0 CET}.. {1114902000 7200 1 CEST}.. {1128038400 3600 0 CET}.. {1143334800 7200 1 CEST}.. {1162083600 3600 0 CET}.. {11747
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1649
                                                                                                                                                                                                            Entropy (8bit):3.9974091170263066
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5t+Lmcz0iMHHWMbnHoMcHiM0H+MCySHr/MDHqMafHO8MwHJMHHOMHSHWMHHXM5Hs:OLjQDI6jZ2WFcv
                                                                                                                                                                                                            MD5:4846FB13467BA93EB134D88228D7F534
                                                                                                                                                                                                            SHA1:477FC6144B7DF365606A2E44EF1430F8DF6FB841
                                                                                                                                                                                                            SHA-256:DFC3D1FC182B315B31D999BC103C264BD205EB16F971C8636003A71170D7BD7C
                                                                                                                                                                                                            SHA-512:A719F5083F66CE44FE047880A10B2ED04B66E01C7F0F7DADAE2FFB95172308F091D669BCFED5A236D2A0F80A4A1D78DA7A778DDE3FAECB40170ECDA705573769
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Africa/Windhoek) {.. {-9223372036854775808 4104 0 LMT}.. {-2458170504 5400 0 +0130}.. {-2109288600 7200 0 SAST}.. {-860976000 10800 1 SAST}.. {-845254800 7200 0 SAST}.. {637970400 7200 0 CAT}.. {764200800 3600 1 WAT}.. {778640400 7200 0 CAT}.. {796780800 3600 1 WAT}.. {810090000 7200 0 CAT}.. {828835200 3600 1 WAT}.. {841539600 7200 0 CAT}.. {860284800 3600 1 WAT}.. {873594000 7200 0 CAT}.. {891734400 3600 1 WAT}.. {905043600 7200 0 CAT}.. {923184000 3600 1 WAT}.. {936493200 7200 0 CAT}.. {954633600 3600 1 WAT}.. {967942800 7200 0 CAT}.. {986083200 3600 1 WAT}.. {999392400 7200 0 CAT}.. {1018137600 3600 1 WAT}.. {1030842000 7200 0 CAT}.. {1049587200 3600 1 WAT}.. {1062896400 7200 0 CAT}.. {1081036800 3600 1 WAT}.. {1094346000 7200 0 CAT}.. {1112486400 3600 1 WAT}.. {1125795600 7200 0 CAT}.. {1143936000 3600 1 WAT}.. {1157245200 7200
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8447
                                                                                                                                                                                                            Entropy (8bit):3.867931581740766
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:6hvOs5vveFaHU6lgqN/zNMkixlrxYTMcmo1LWF59:6hvOstgqN/zNMkArxiZmf
                                                                                                                                                                                                            MD5:DF52E726B33FA47EB115C1233614E101
                                                                                                                                                                                                            SHA1:26B0E49022FCB929F0160617F9C9D2DBEDC63610
                                                                                                                                                                                                            SHA-256:77231D179260C08690A70AEE6C2517E4B621ED4794D9AEEA7040539F4FF05111
                                                                                                                                                                                                            SHA-512:48AAF25419E07B06E076B0E19F9A0C27EB257556E62FD8F7B2AA963A817823DD89D33AB6AFEAAC2EF2230361D76776355E19CC2BBBB4D19536F823A347AC8AA4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Adak) {.. {-9223372036854775808 44002 0 LMT}.. {-3225223727 -42398 0 LMT}.. {-2188944802 -39600 0 NST}.. {-883573200 -39600 0 NST}.. {-880196400 -36000 1 NWT}.. {-769395600 -36000 1 NPT}.. {-765374400 -39600 0 NST}.. {-757342800 -39600 0 NST}.. {-86878800 -39600 0 BST}.. {-31496400 -39600 0 BST}.. {-21466800 -36000 1 BDT}.. {-5745600 -39600 0 BST}.. {9982800 -36000 1 BDT}.. {25704000 -39600 0 BST}.. {41432400 -36000 1 BDT}.. {57758400 -39600 0 BST}.. {73486800 -36000 1 BDT}.. {89208000 -39600 0 BST}.. {104936400 -36000 1 BDT}.. {120657600 -39600 0 BST}.. {126709200 -36000 1 BDT}.. {152107200 -39600 0 BST}.. {162392400 -36000 1 BDT}.. {183556800 -39600 0 BST}.. {199285200 -36000 1 BDT}.. {215611200 -39600 0 BST}.. {230734800 -36000 1 BDT}.. {247060800 -39600 0 BST}.. {262789200 -36000 1 BDT}.. {278510400 -39600 0 BST}.. {29423880
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8685
                                                                                                                                                                                                            Entropy (8bit):3.9620252256806845
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:esKLO6KLC9+j1giaJCUbtp0nFI+g/iexpCVaBnNnt61nctE1:etLhN9DiaJCUbPI+D/iMpCIBSuk
                                                                                                                                                                                                            MD5:BFEACEA04AAA8A69A9AC71CF86BCC15C
                                                                                                                                                                                                            SHA1:1693971B8AAA35021BA34799FB1B9FADC3DA0294
                                                                                                                                                                                                            SHA-256:DE7FBE2B3ED780C6B82099E1E249DD41F4452A3ADB9DD807B1D0EC06049C2302
                                                                                                                                                                                                            SHA-512:E94112A2A5F268C03C58CE3BB4C243B2B9B0FC17CB27FDD58BCD2CCC8D377B805C87A552AE7DE1C5698C5F2C4B0FCAB00A3420B1DAD944C1A2F7A47CE7118F78
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Anchorage) {.. {-9223372036854775808 50424 0 LMT}.. {-3225223727 -35976 0 LMT}.. {-2188951224 -36000 0 AST}.. {-883576800 -36000 0 AST}.. {-880200000 -32400 1 AWT}.. {-769395600 -32400 1 APT}.. {-765378000 -36000 0 AST}.. {-86882400 -36000 0 AHST}.. {-31500000 -36000 0 AHST}.. {-21470400 -32400 1 AHDT}.. {-5749200 -36000 0 AHST}.. {9979200 -32400 1 AHDT}.. {25700400 -36000 0 AHST}.. {41428800 -32400 1 AHDT}.. {57754800 -36000 0 AHST}.. {73483200 -32400 1 AHDT}.. {89204400 -36000 0 AHST}.. {104932800 -32400 1 AHDT}.. {120654000 -36000 0 AHST}.. {126705600 -32400 1 AHDT}.. {152103600 -36000 0 AHST}.. {162388800 -32400 1 AHDT}.. {183553200 -36000 0 AHST}.. {199281600 -32400 1 AHDT}.. {215607600 -36000 0 AHST}.. {230731200 -32400 1 AHDT}.. {247057200 -36000 0 AHST}.. {262785600 -32400 1 AHDT}.. {278506800 -36000 0 AHST}.. {294235200 -3
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):202
                                                                                                                                                                                                            Entropy (8bit):4.908728298285591
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290/8J5290ppv:MByMYbpwt290/8m90b
                                                                                                                                                                                                            MD5:1C3CE9F156ABECEAA794E8F1F3A7ADDB
                                                                                                                                                                                                            SHA1:6F84D0A424FD2DE85E3420EA320A186B277B0295
                                                                                                                                                                                                            SHA-256:F38610019C0A2C18AC71F5AA108B9647D9B5C01DCB55211AFB8312308C41FE70
                                                                                                                                                                                                            SHA-512:CA2DA6F9551E4DBF775D7D059F6F3399E0C4F2A428699726CD2A1B0BB17CCF5CDEEF645EE1759A2A349F3F29E0343600B89CE1F4659CF5D2B58280A381C018AD
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Anguilla) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):201
                                                                                                                                                                                                            Entropy (8bit):4.898881450964165
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290//MFe90ppv:MByMYbpwt290//V90b
                                                                                                                                                                                                            MD5:DB16FFE76D625DEC731AB6320F5EF9BF
                                                                                                                                                                                                            SHA1:D286994E03E4F82C08DE094B436FA098648AFADE
                                                                                                                                                                                                            SHA-256:561E58E11DC5A86CAE04B5CB40F43EFCFF9ABC0C841FAC094619E9C5E0B403F8
                                                                                                                                                                                                            SHA-512:8842B616205378AF78B0B2FC3F6517385845DE30FFD477A21ACFA0060D161FB6462A3C266DCFD54F101729446B8E1B2ECF463C9CF2E6CE227B2628A19AF365F9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Antigua) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1782
                                                                                                                                                                                                            Entropy (8bit):3.733307964154526
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5KChlvEw6kSSx5H4a8tf3fkuozd23t8VZDG8+GCRRRd:QIlvEwJSSxdF8tfMuozdCt8VZy8+GCRB
                                                                                                                                                                                                            MD5:9B01680A362EA7B462DC236F6A35E14C
                                                                                                                                                                                                            SHA1:456A5E771F6B749BFDB2BFD59836A6A930499881
                                                                                                                                                                                                            SHA-256:B1327CBEC20A21E3FF873E28A2EDFA271EE3A5C01933779300EABD6B185DA010
                                                                                                                                                                                                            SHA-512:E6C2F5C489BEA31B0AAC3CB1DB750AC2B665DAC0AC82C1CE6756E768305300297BA5E3B32EDEB9E1715452F02223E47674C4F2B1844920F664623C9F34309240
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Araguaina) {.. {-9223372036854775808 -11568 0 LMT}.. {-1767214032 -10800 0 -03}.. {-1206957600 -7200 1 -03}.. {-1191362400 -10800 0 -03}.. {-1175374800 -7200 1 -03}.. {-1159826400 -10800 0 -03}.. {-633819600 -7200 1 -03}.. {-622069200 -10800 0 -03}.. {-602283600 -7200 1 -03}.. {-591832800 -10800 0 -03}.. {-570747600 -7200 1 -03}.. {-560210400 -10800 0 -03}.. {-539125200 -7200 1 -03}.. {-531352800 -10800 0 -03}.. {-191365200 -7200 1 -03}.. {-184197600 -10800 0 -03}.. {-155163600 -7200 1 -03}.. {-150069600 -10800 0 -03}.. {-128898000 -7200 1 -03}.. {-121125600 -10800 0 -03}.. {-99954000 -7200 1 -03}.. {-89589600 -10800 0 -03}.. {-68418000 -7200 1 -03}.. {-57967200 -10800 0 -03}.. {499748400 -7200 1 -03}.. {511236000 -10800 0 -03}.. {530593200 -7200 1 -03}.. {540266400 -10800 0 -03}.. {562129200 -7200 1 -03}.. {571197600 -10800 0 -03}
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2048
                                                                                                                                                                                                            Entropy (8bit):3.7664759014118188
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5p9uuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafwwfFC8OS0wi:jIu3pfe92jCs/VOHv2kdeRtnxafwwfF0
                                                                                                                                                                                                            MD5:2B9A1EDE5110B46E24F4726664EA1E3F
                                                                                                                                                                                                            SHA1:939D1A7A50544F34B318ACDB52BC6930FE453F6D
                                                                                                                                                                                                            SHA-256:BC86AC89121EC4AA302F6259CCC97EFFD7022DC6CEE3B291C57DA72B6EA0C558
                                                                                                                                                                                                            SHA-512:C204740DACBCECF2CC5CF4FEB687E86B9150512623203C999D6F4EB5FB246D07681A35C28D8445F6A50F49940C321E0AA5E51FE5A73B8ED076F29CEB5B4D4CA2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Buenos_Aires) {.. {-9223372036854775808 -14028 0 LMT}.. {-2372097972 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-7522
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2077
                                                                                                                                                                                                            Entropy (8bit):3.742645155048276
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5/nuuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafww3mC8OS0NC:Vuu3pfe92jCs/VOHv2kdeRtnxafww3mP
                                                                                                                                                                                                            MD5:3D2AF5714DFC392ED4BC976784D5A58A
                                                                                                                                                                                                            SHA1:9252DE40B6EF872E1D2F7CDD53DDD21145E93C5C
                                                                                                                                                                                                            SHA-256:A516BB0937977EF949D47B3C8675E30F1CA6C34F8BD298DCF6EBB943580D5317
                                                                                                                                                                                                            SHA-512:8D5FFDB5B578B8EA0291D3A21BDDE25F8301CB16B11AE794FFBA8DCFFE46F6AC5EC03D93E511061B132D84E69E5FAF1BB212837EB8A5A4B4BE517F783837E615
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Catamarca) {.. {-9223372036854775808 -15788 0 LMT}.. {-2372096212 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-7522740
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):242
                                                                                                                                                                                                            Entropy (8bit):4.72138001874583
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7/MMXAXHAIgp/MMXmRN/290/MquQ90/MMXAy:MByMY/MYp/MrRt290/MquQ90/MK
                                                                                                                                                                                                            MD5:8A609667DE461CEDC1127BE38B161459
                                                                                                                                                                                                            SHA1:557D2D55DEA38D1CD1103E183F89C65F4016662B
                                                                                                                                                                                                            SHA-256:8CCD6FC77D55582938F1912B1BA66035882D1BFC18A797C631E5E89ABFBF570B
                                                                                                                                                                                                            SHA-512:DBAFDA069DB5FDBCBA11050AC91A733C1712BD6395939CFFFC5EAA78BD0B70B4AF2D9FB8954C6841CCF3AC5F8EDCF08E604D3F2CF67F1CBEA5EB6D3C4DC7F2FA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Argentina/Catamarca)]} {.. LoadTimeZoneFile America/Argentina/Catamarca..}..set TZData(:America/Argentina/ComodRivadavia) $TZData(:America/Argentina/Catamarca)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2043
                                                                                                                                                                                                            Entropy (8bit):3.7481312409221594
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5lxQuuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafww3mC8OS0n:/xBu3pfe92jCs/VOHv2kdeRtnxafww3j
                                                                                                                                                                                                            MD5:8C1D665A25E61CE462C2AC57687763BF
                                                                                                                                                                                                            SHA1:B5BBC26CF6A24BD5BEA42AC485D62C789B80905F
                                                                                                                                                                                                            SHA-256:FA75E274240A341C6BFE3539CFDC114D125AEAEA3161D3C2409347CF8046042A
                                                                                                                                                                                                            SHA-512:A89A7A92C025B87DA4CDFE99BF70CD0E64690D7BFE827DCBFBF0E91B188003FA26487E72B6B950D3BFC9C854B890E5936F414BBEAAD5F3F0673AC5EFE273CDF4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Cordoba) {.. {-9223372036854775808 -15408 0 LMT}.. {-2372096592 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-752274000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2041
                                                                                                                                                                                                            Entropy (8bit):3.7481290145270245
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5HluuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafwcSPAC8OS0E:xwu3pfe92jCs/VOHv2kdeRtnxafwcDCK
                                                                                                                                                                                                            MD5:995EDE9E1E86DB500C7437A196325E21
                                                                                                                                                                                                            SHA1:4A8FB1511AA124CA2D299EC8DE155EE9D0479180
                                                                                                                                                                                                            SHA-256:43EB79ABC03CBAC661C563DE1BC09D9DD855CBC72DD2B6467EA98F0F90421BA9
                                                                                                                                                                                                            SHA-512:B58B35EA1B2F0388B8108DCF254F3BD1B21894F00A9F313ABC093BC52C36FCDD94B7486DBA38161C9EFCDB12BC3CD81E7E02395B0CA480A7F01148C43CD3054F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Jujuy) {.. {-9223372036854775808 -15672 0 LMT}.. {-2372096328 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-752274000 -
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2106
                                                                                                                                                                                                            Entropy (8bit):3.744252944523733
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5lduuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafwwkFC8OS0NC:Tou3pfe92jCs/VOHv2kdeRtnxafwwkFP
                                                                                                                                                                                                            MD5:4A45A063D45EB94214005EF3CA5BCD6D
                                                                                                                                                                                                            SHA1:2420E8591DC53A39EE1A58B2E45DCFAF9503685F
                                                                                                                                                                                                            SHA-256:2B018B791E48269FA9EDA12662FFEC3E2DC33603A918E8B735B8D7D6BEB3B3AA
                                                                                                                                                                                                            SHA-512:0B2824FA3D40B2EDBE8488D50C30368F4CF6E45A39FF6DEBC5BB4FD86F85AD52F5331AD1EB50E5166FA2E735B7E8AA9D94A5FED9421334DB0499524DBE08F737
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/La_Rioja) {.. {-9223372036854775808 -16044 0 LMT}.. {-2372095956 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-75227400
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2077
                                                                                                                                                                                                            Entropy (8bit):3.738002814507529
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5CPBuuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafwGSmSc8OSI:GUu3pfe92jCs/VOHv2kdeRtnxafwGJld
                                                                                                                                                                                                            MD5:F6CB24E8567B2443224E9E17EE438BFE
                                                                                                                                                                                                            SHA1:8029426C30C4C645EA77C6240391CDB1C3107568
                                                                                                                                                                                                            SHA-256:DC39400BBFD5BDDDC174FE099194806FBFD3FC3AA20E670D67BE0AC35FE97AD4
                                                                                                                                                                                                            SHA-512:6869CFC24C21FBB2DFCCAA9AE7E21A0B24DC002EE792FB28A8F2F05C75C20E93C95A39BD8653AA272AF10FE95922B99EECC1208AACE814817D9441F84360E867
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Mendoza) {.. {-9223372036854775808 -16516 0 LMT}.. {-2372095484 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-752274000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2080
                                                                                                                                                                                                            Entropy (8bit):3.7580685839169545
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5oQuuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafwwfFC8OS0NC:qBu3pfe92jCs/VOHv2kdeRtnxafwwfFP
                                                                                                                                                                                                            MD5:212D13CE27AF114A8EC2E04023D218C4
                                                                                                                                                                                                            SHA1:C4C5F86BC6EC0D5EA4C9CF199309D085767B97E8
                                                                                                                                                                                                            SHA-256:A05B6708DEFF0607396BFC6661C2287341C3432841AE353D94A67AC742B5FAFA
                                                                                                                                                                                                            SHA-512:CE7201EEA6A86FB49641410D2EEE4030EDB1B96F3218D764762F5AE23883C796F5742ED69CEC985A9D3582D6C72ED74114DE81508F6DEB4B54865B6974ADC965
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Rio_Gallegos) {.. {-9223372036854775808 -16612 0 LMT}.. {-2372095388 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-7522
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2011
                                                                                                                                                                                                            Entropy (8bit):3.7415813345133975
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5NPuuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafww3mC8OS0wF:72u3pfe92jCs/VOHv2kdeRtnxafww3mz
                                                                                                                                                                                                            MD5:A06C33CDFD7E7B630CB1DF34E72E61E5
                                                                                                                                                                                                            SHA1:694826B9B910DA0BD70A9CB547C26E6838B08111
                                                                                                                                                                                                            SHA-256:CAEFC60F2F36EF9FFE0C5921C3C392DE1E95755683A96C1C4EC0BA2C242A4D84
                                                                                                                                                                                                            SHA-512:D6696A6C14EECF2B77EC586F40137BDD95E5CE5C5193570C809FAB9E5FCA4B8744283CEB6818E525C73F6EFF657274410B2622902EE8C15912C8D5F5FA5C805E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Salta) {.. {-9223372036854775808 -15700 0 LMT}.. {-2372096300 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-752274000 -
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2106
                                                                                                                                                                                                            Entropy (8bit):3.747934819596411
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5vXxuuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafwwkFC8OS0K:hUu3pfe92jCs/VOHv2kdeRtnxafwwkFl
                                                                                                                                                                                                            MD5:32A50D0ABF408D9E59C0580D5B8CC472
                                                                                                                                                                                                            SHA1:EA5BB8860982F8BAFEAEFDE1D6ACD440DA132DFE
                                                                                                                                                                                                            SHA-256:41B2C25E42146A76934B866061BB3245B8ADA0FF4E1BFBA6F8842A30BDD5C132
                                                                                                                                                                                                            SHA-512:E5D2521A4EF53AAD3E74506708EC2768C4D2EE8D6D014DCCF4A6DC290B713B4D46021B66527548C35004E10D753E1B685EEFD55BBE7BF01EC6104D7D8AAC4403
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/San_Juan) {.. {-9223372036854775808 -16444 0 LMT}.. {-2372095556 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-75227400
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2081
                                                                                                                                                                                                            Entropy (8bit):3.7399269084699975
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5MDuuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafw6bS2nZSbdI:yCu3pfe92jCs/VOHv2kdeRtnxafwWnZr
                                                                                                                                                                                                            MD5:FB06B66F5D41709C7E85C8B1E9BFCFA0
                                                                                                                                                                                                            SHA1:D5C0C4B12C6190856C300321B1C106C7474BA54B
                                                                                                                                                                                                            SHA-256:A43B35F25E54EF359D046E33281C0A978F0EE8811C93A6809F1F65750878BBB6
                                                                                                                                                                                                            SHA-512:D445F46D6A17A075AD995885E45234A711F53BF3FE2DFC6DFBB611E8AC154B10C91E137927DD66D6A7C596A93BAE5DE283796F341B5095FA0DD05595E1C3A077
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/San_Luis) {.. {-9223372036854775808 -15924 0 LMT}.. {-2372096076 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-75227400
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2105
                                                                                                                                                                                                            Entropy (8bit):3.741704529449777
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5yZujuuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafww3mC8OSf:suiu3pfe92jCs/VOHv2kdeRtnxafww3w
                                                                                                                                                                                                            MD5:D9497141EC0DC172E5FF5304FED0BE6B
                                                                                                                                                                                                            SHA1:CD20A4F0C127A84791093010D59DF119DD32340A
                                                                                                                                                                                                            SHA-256:0F7DB23E1280FC19A1FB716E09A9699ADA2AAE24084CAD472B4C325CC9783CCF
                                                                                                                                                                                                            SHA-512:0B71952055013CD6045ED209FD98168083550655FAB91B7870C92098E40C4FE6827EAAF922D34ECE28298CBB14327A76AD6780D480E552F52F865AA11A4AA083
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Tucuman) {.. {-9223372036854775808 -15652 0 LMT}.. {-2372096348 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-752274000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2075
                                                                                                                                                                                                            Entropy (8bit):3.7445758155279836
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5SHuuSYSaSISBS2ShSmSLVS+E1/SKSZSGRSoSpS7S6S4wRSenSOafwwfFC8OS0jE:YOu3pfe92jCs/VOHv2kdeRtnxafwwfFn
                                                                                                                                                                                                            MD5:16A89FD2CDEE50E534301A9797311A9D
                                                                                                                                                                                                            SHA1:4A4EBA1798214C7CF5ACDC0B2EC8B4716CD968CB
                                                                                                                                                                                                            SHA-256:10B6FF51314D8EE1D010187D8805C4E3D71B778BC6DECB26E66193A5BB3E9EA2
                                                                                                                                                                                                            SHA-512:DBB0BA3F8AA2B54C86EA8B6530C16DF95AF1331FC5F843B113A204DA20B8EF011FE93C27EB917D01B9040D4914057687B4AACCD292A847559AF69150D1BDC4B5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Argentina/Ushuaia) {.. {-9223372036854775808 -16392 0 LMT}.. {-2372095608 -15408 0 CMT}.. {-1567453392 -14400 0 -04}.. {-1233432000 -10800 0 -04}.. {-1222981200 -14400 0 -04}.. {-1205956800 -10800 1 -04}.. {-1194037200 -14400 0 -04}.. {-1172865600 -10800 1 -04}.. {-1162501200 -14400 0 -04}.. {-1141329600 -10800 1 -04}.. {-1130965200 -14400 0 -04}.. {-1109793600 -10800 1 -04}.. {-1099429200 -14400 0 -04}.. {-1078257600 -10800 1 -04}.. {-1067806800 -14400 0 -04}.. {-1046635200 -10800 1 -04}.. {-1036270800 -14400 0 -04}.. {-1015099200 -10800 1 -04}.. {-1004734800 -14400 0 -04}.. {-983563200 -10800 1 -04}.. {-973198800 -14400 0 -04}.. {-952027200 -10800 1 -04}.. {-941576400 -14400 0 -04}.. {-931032000 -10800 1 -04}.. {-900882000 -14400 0 -04}.. {-890337600 -10800 1 -04}.. {-833749200 -14400 0 -04}.. {-827265600 -10800 1 -04}.. {-752274000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):199
                                                                                                                                                                                                            Entropy (8bit):4.893042770292303
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290/V90ppv:MByMYbpwt290/V90b
                                                                                                                                                                                                            MD5:CC015E3E5D3293CAA1348B4E0EE5795C
                                                                                                                                                                                                            SHA1:75E7EFD905C9001CE9CA5872DA3915A19BCB00E0
                                                                                                                                                                                                            SHA-256:7490CD66408B8A14C549278FE67DC3338FE9E458F423F01CCBEA00B5E6F6CEF6
                                                                                                                                                                                                            SHA-512:66523F050E4A42A1C9FC8C02B822CD3864A6E35F6364FB6A675F2A503BD8030FE6E380B252068668A79A6593B5042520EE40700DA033517742B3F0ED33D79DAF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Aruba) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7944
                                                                                                                                                                                                            Entropy (8bit):3.5156463862656775
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:j7RXBXLqbvdvZsV4GGdzVUFg7XaMOhKpJq3o5GMJq90vRFhjGF3RxTBhcXBACBLo:jEJgXh
                                                                                                                                                                                                            MD5:181203CAD98E94355B9914A205514904
                                                                                                                                                                                                            SHA1:D361CB53955437270905A9432DE9E7F6C1AE7189
                                                                                                                                                                                                            SHA-256:EAEFE21276EE60C7F876C1D65039999AC069339DCDB82A23FC9206C274510575
                                                                                                                                                                                                            SHA-512:AE9262DFC35579AEB610DF8BB5F7FBB49232195F55F78402405017681F72C0D2A09FA9EB605B406065A1F44FE6785AC0163870C921DAFFC4746DA6EDA3081521
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Asuncion) {.. {-9223372036854775808 -13840 0 LMT}.. {-2524507760 -13840 0 AMT}.. {-1206389360 -14400 0 -04}.. {86760000 -10800 0 -03}.. {134017200 -14400 0 -04}.. {162878400 -14400 0 -04}.. {181368000 -10800 1 -04}.. {194497200 -14400 0 -04}.. {212990400 -10800 1 -04}.. {226033200 -14400 0 -04}.. {244526400 -10800 1 -04}.. {257569200 -14400 0 -04}.. {276062400 -10800 1 -04}.. {291783600 -14400 0 -04}.. {307598400 -10800 1 -04}.. {323406000 -14400 0 -04}.. {339220800 -10800 1 -04}.. {354942000 -14400 0 -04}.. {370756800 -10800 1 -04}.. {386478000 -14400 0 -04}.. {402292800 -10800 1 -04}.. {418014000 -14400 0 -04}.. {433828800 -10800 1 -04}.. {449636400 -14400 0 -04}.. {465451200 -10800 1 -04}.. {481172400 -14400 0 -04}.. {496987200 -10800 1 -04}.. {512708400 -14400 0 -04}.. {528523200 -10800 1 -04}.. {544244400 -14400 0 -04}.. {5
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):187
                                                                                                                                                                                                            Entropy (8bit):4.791603790249234
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0u55DyXHAIg20u5cvRL/2IAcGE/qlOi+4IAcGEu5B:SlSWB9vsM3y7oDSHAIgpdN/290/qlf+M
                                                                                                                                                                                                            MD5:5A45B70C79F533548B3DD332F988E15B
                                                                                                                                                                                                            SHA1:C7485828619A1D4F5CA59D80ABD197100AC58F64
                                                                                                                                                                                                            SHA-256:518BEB6E54AE811F8C725EA8CC42787D48FC605A3476D6E7A00A1B5733CBD6AC
                                                                                                                                                                                                            SHA-512:A81C2EBE282E019ED011EADDB8F74C3E6FBE88D87E8D8706B3022CDCC48EF92AD90F9BCF9F25031664BB6EFE069EAFDD23D9B55BF672FC7528A2DD8CB6B986B4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Panama)]} {.. LoadTimeZoneFile America/Panama..}..set TZData(:America/Atikokan) $TZData(:America/Panama)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):177
                                                                                                                                                                                                            Entropy (8bit):4.812527147763069
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0/yO5WXHAIg20/yOoNvWARL/2IAcGE/ol7x+IAcGs:SlSWB9vsM3y7/yrHAIgp/yH0AN/290/e
                                                                                                                                                                                                            MD5:13479F64BFBDC7583C637E1562C454B4
                                                                                                                                                                                                            SHA1:2F59484C779B0D6033FC14E205DA9BCAB7A5FCB1
                                                                                                                                                                                                            SHA-256:1D6FEE336E71FFFB64874A830C976867C071EBF6B133C296B32F87E3E7D814C9
                                                                                                                                                                                                            SHA-512:D2C5D35BBBDAB8D58BF6185328124796C06B67ADFB4C1828BA5A9CCA500A01BB8BE69635AE7EEA7FA837A27B20D488A08A29B121DD1617BC373390AD95D67E39
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Adak)]} {.. LoadTimeZoneFile America/Adak..}..set TZData(:America/Atka) $TZData(:America/Adak)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2012
                                                                                                                                                                                                            Entropy (8bit):3.703391569010329
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5/ChlvEw6kSSx5H4a8tf3fku+da2XUd23t8VZDG8+GyOd:VIlvEwJSSxdF8tfMu+da2kdCt8VZy8+K
                                                                                                                                                                                                            MD5:69DCC2477D8D81E2F49D295DB6907190
                                                                                                                                                                                                            SHA1:3C6ED0CEF15D3265C962873480EE1809A4DCACA2
                                                                                                                                                                                                            SHA-256:64F1EC14F6B43FF10B564F839152E88DF9262F0947D1DB347557FA902F6FD48C
                                                                                                                                                                                                            SHA-512:71DEA6D47F267AA7326A011872FA74762FA4F8CD57EB149E3B56B3DE9097B0B9258BC4F6C29188B49FC60C1942869B92D9E59FEE6980A5DA5D0029C383D99F39
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Bahia) {.. {-9223372036854775808 -9244 0 LMT}.. {-1767216356 -10800 0 -03}.. {-1206957600 -7200 1 -03}.. {-1191362400 -10800 0 -03}.. {-1175374800 -7200 1 -03}.. {-1159826400 -10800 0 -03}.. {-633819600 -7200 1 -03}.. {-622069200 -10800 0 -03}.. {-602283600 -7200 1 -03}.. {-591832800 -10800 0 -03}.. {-570747600 -7200 1 -03}.. {-560210400 -10800 0 -03}.. {-539125200 -7200 1 -03}.. {-531352800 -10800 0 -03}.. {-191365200 -7200 1 -03}.. {-184197600 -10800 0 -03}.. {-155163600 -7200 1 -03}.. {-150069600 -10800 0 -03}.. {-128898000 -7200 1 -03}.. {-121125600 -10800 0 -03}.. {-99954000 -7200 1 -03}.. {-89589600 -10800 0 -03}.. {-68418000 -7200 1 -03}.. {-57967200 -10800 0 -03}.. {499748400 -7200 1 -03}.. {511236000 -10800 0 -03}.. {530593200 -7200 1 -03}.. {540266400 -10800 0 -03}.. {562129200 -7200 1 -03}.. {571197600 -10800 0 -03}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2073
                                                                                                                                                                                                            Entropy (8bit):4.021485901155292
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:56hey9WUQwuz/V/NF01Y3A6S++S+vS+QQS+1S+9fS+BrS+HoS+8S+/N5S+5zNZf+:5pUIdFS1Y3FUlWQnH7eelN5Lh9LY5Lj
                                                                                                                                                                                                            MD5:4655AE5AB9C39CA05C1FF36FC366679F
                                                                                                                                                                                                            SHA1:F3F1D08EC35907A8F45AA2CFD097F6DCCA75C9B8
                                                                                                                                                                                                            SHA-256:A6233E5BB0D3B30D0E3B94CD797718041AC3C2E75B387D6646A5C0376C5591CD
                                                                                                                                                                                                            SHA-512:3915B845A312147C5B047096033B3D153E4E83AF4C8E4AAA73C8D12E2A8386CFE8EC4568730F9F28863017A60622DD9CC7D97991C966779B4068BC29F6C6B2B3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Bahia_Banderas) {.. {-9223372036854775808 -25260 0 LMT}.. {-1514739600 -25200 0 MST}.. {-1343066400 -21600 0 CST}.. {-1234807200 -25200 0 MST}.. {-1220292000 -21600 1 MDT}.. {-1207159200 -25200 0 MST}.. {-1191344400 -21600 0 CST}.. {-873828000 -25200 0 MST}.. {-661539600 -28800 0 PST}.. {28800 -25200 0 MST}.. {828867600 -21600 1 MDT}.. {846403200 -25200 0 MST}.. {860317200 -21600 1 MDT}.. {877852800 -25200 0 MST}.. {891766800 -21600 1 MDT}.. {909302400 -25200 0 MST}.. {923216400 -21600 1 MDT}.. {941356800 -25200 0 MST}.. {954666000 -21600 1 MDT}.. {972806400 -25200 0 MST}.. {989139600 -21600 1 MDT}.. {1001836800 -25200 0 MST}.. {1018170000 -21600 1 MDT}.. {1035705600 -25200 0 MST}.. {1049619600 -21600 1 MDT}.. {1067155200 -25200 0 MST}.. {1081069200 -21600 1 MDT}.. {1099209600 -25200 0 MST}.. {1112518800 -21600 1 MDT}.. {1130659200
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):648
                                                                                                                                                                                                            Entropy (8bit):4.251560000277241
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB86290eWmdH9Colj/uFkv/lC1/uFkOzQs/lps/Ozfah/OzT/lN/uFkX/ll/uFki:5TWeUo5Skv/Y1SkA/g/Bh/m/rSkX/zSt
                                                                                                                                                                                                            MD5:DC4FA44B2174A4E6F0644FA8EA2E83F9
                                                                                                                                                                                                            SHA1:C12DF8C862A05D569EAF189272F8BF44303595A1
                                                                                                                                                                                                            SHA-256:FD5E04136506C6543A9ACDC890A30BCF0D561148E1063EC857E3913DE1EBA404
                                                                                                                                                                                                            SHA-512:5AC307CD48132B57215CCBAF0BB63F7FA9C5B28DC9F6217C905885D75B0DF131238D4DB2AE707C3DDEE2EDE6C0914644B435FB1CDD9913600D8B69AE95578B0F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Barbados) {.. {-9223372036854775808 -14309 0 LMT}.. {-1841256091 -14400 0 AST}.. {-874263600 -10800 1 ADT}.. {-862682400 -14400 0 AST}.. {-841604400 -10800 1 ADT}.. {-830714400 -14400 0 AST}.. {-820526400 -14400 0 -0330}.. {-811882800 -12600 1 AST}.. {-798660000 -14400 0 -0330}.. {-788904000 -14400 0 AST}.. {234943200 -10800 1 ADT}.. {244616400 -14400 0 AST}.. {261554400 -10800 1 ADT}.. {276066000 -14400 0 AST}.. {293004000 -10800 1 ADT}.. {307515600 -14400 0 AST}.. {325058400 -10800 1 ADT}.. {338706000 -14400 0 AST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1031
                                                                                                                                                                                                            Entropy (8bit):3.8842563546204225
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5fe300cChlrLPsw6kSS3h5R14eH8tf3xd:5+CChlvEw6kSSx5H4a8tf3xd
                                                                                                                                                                                                            MD5:DFA5E50F6AEF1311A4CF74970477E390
                                                                                                                                                                                                            SHA1:5B63676EB8039B2BE767BAA44820F2DAE5B62876
                                                                                                                                                                                                            SHA-256:549625CCB30BD0E025BAC47668BA3AA0CDD8569E5887E483C8D62B5B7302FA50
                                                                                                                                                                                                            SHA-512:4BBB43694E3B54339C549AC3A5488B77366DB1189D8D1834DCF618D9448084A950B575E207064521B1CDFD2E41F7D1D8C5CD9CEB4668D4459585649556136EB0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Belem) {.. {-9223372036854775808 -11636 0 LMT}.. {-1767213964 -10800 0 -03}.. {-1206957600 -7200 1 -03}.. {-1191362400 -10800 0 -03}.. {-1175374800 -7200 1 -03}.. {-1159826400 -10800 0 -03}.. {-633819600 -7200 1 -03}.. {-622069200 -10800 0 -03}.. {-602283600 -7200 1 -03}.. {-591832800 -10800 0 -03}.. {-570747600 -7200 1 -03}.. {-560210400 -10800 0 -03}.. {-539125200 -7200 1 -03}.. {-531352800 -10800 0 -03}.. {-191365200 -7200 1 -03}.. {-184197600 -10800 0 -03}.. {-155163600 -7200 1 -03}.. {-150069600 -10800 0 -03}.. {-128898000 -7200 1 -03}.. {-121125600 -10800 0 -03}.. {-99954000 -7200 1 -03}.. {-89589600 -10800 0 -03}.. {-68418000 -7200 1 -03}.. {-57967200 -10800 0 -03}.. {499748400 -7200 1 -03}.. {511236000 -10800 0 -03}.. {530593200 -7200 1 -03}.. {540266400 -10800 0 -03}.. {562129200 -7200 1 -03}.. {571197600 -10800 0 -03}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3284
                                                                                                                                                                                                            Entropy (8bit):3.8546064195941097
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5pKSxZwR9IVQU55DG5krgGN8wW+YeD1yyfCwoc:HKSjgIVzrG5krRN8wWheD1yu
                                                                                                                                                                                                            MD5:4DA622B685B3B075CC94FC4E23322547
                                                                                                                                                                                                            SHA1:DEB23F0A434549DAE1BE60ACF757BB212C907B92
                                                                                                                                                                                                            SHA-256:E07F45264E28FD5AA54BD48CB701658509829CF989EC9BD79498D070A1BA270F
                                                                                                                                                                                                            SHA-512:9B00BF8870BC4AAEF7F06FCDFEEEF54686A2CC890103696631EB4DEF5AEEAD051EC9069D70A2B22397F18C0067E03A54E75DA18474D6B1BD3BDA2D5313E0AD16
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Belize) {.. {-9223372036854775808 -21168 0 LMT}.. {-1822500432 -21600 0 CST}.. {-1616954400 -19800 1 -0530}.. {-1606069800 -21600 0 CST}.. {-1585504800 -19800 1 -0530}.. {-1574015400 -21600 0 CST}.. {-1554055200 -19800 1 -0530}.. {-1542565800 -21600 0 CST}.. {-1522605600 -19800 1 -0530}.. {-1511116200 -21600 0 CST}.. {-1490551200 -19800 1 -0530}.. {-1479666600 -21600 0 CST}.. {-1459101600 -19800 1 -0530}.. {-1448217000 -21600 0 CST}.. {-1427652000 -19800 1 -0530}.. {-1416162600 -21600 0 CST}.. {-1396202400 -19800 1 -0530}.. {-1384713000 -21600 0 CST}.. {-1364752800 -19800 1 -0530}.. {-1353263400 -21600 0 CST}.. {-1333303200 -19800 1 -0530}.. {-1321813800 -21600 0 CST}.. {-1301248800 -19800 1 -0530}.. {-1290364200 -21600 0 CST}.. {-1269799200 -19800 1 -0530}.. {-1258914600 -21600 0 CST}.. {-1238349600 -19800 1 -0530}.. {-1226860200 -21600
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):206
                                                                                                                                                                                                            Entropy (8bit):4.938043196147077
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290F490ppv:MByMYbpwt290S90b
                                                                                                                                                                                                            MD5:09FD8280CC890F238126F9641DB7C90E
                                                                                                                                                                                                            SHA1:98AB4E0DE8173C2BB2532B07FAE2E71F588AB26F
                                                                                                                                                                                                            SHA-256:FACD0A835D1F425CD323EE453ADE231810B2D1CF6EBA227BA1B50522AE3879F7
                                                                                                                                                                                                            SHA-512:117C24389B7BFB079F4409B1FA6AA547654D7C69A6CBB19218BF2B96F6CFE3CBAAD400D4C2EFE8A9BFE25F44402057427FC8A62DC20A98018D23A7CF9B87401F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Blanc-Sablon) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1199
                                                                                                                                                                                                            Entropy (8bit):3.7988385604912893
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5EThevwnSRs//SFs/pS9/MHSW/WOSr/nSso/TSL/SSU/iS5X/LcSi/xScd/ZlSQZ:5EHSeSFESoSQSrSsCSeSPS1cSQSQlSsp
                                                                                                                                                                                                            MD5:9529221F9B4E104CC598491703B10E6C
                                                                                                                                                                                                            SHA1:5ACD61B525A18DE1919A7484C92EC5D787DF2F25
                                                                                                                                                                                                            SHA-256:10592EA1CB0D02C06A61059EC601F70A706A5053AC923B9EED29388D5E71EF3A
                                                                                                                                                                                                            SHA-512:66BEDB631469651A5E426155428764E3C1C14483E6FEE1505812E8676EB6E82CF0A88F6CC697F03FDA0AF906D91C7DE6E940DF3D33DD247BEF51DBD9A13DEE16
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Boa_Vista) {.. {-9223372036854775808 -14560 0 LMT}.. {-1767211040 -14400 0 -04}.. {-1206954000 -10800 1 -04}.. {-1191358800 -14400 0 -04}.. {-1175371200 -10800 1 -04}.. {-1159822800 -14400 0 -04}.. {-633816000 -10800 1 -04}.. {-622065600 -14400 0 -04}.. {-602280000 -10800 1 -04}.. {-591829200 -14400 0 -04}.. {-570744000 -10800 1 -04}.. {-560206800 -14400 0 -04}.. {-539121600 -10800 1 -04}.. {-531349200 -14400 0 -04}.. {-191361600 -10800 1 -04}.. {-184194000 -14400 0 -04}.. {-155160000 -10800 1 -04}.. {-150066000 -14400 0 -04}.. {-128894400 -10800 1 -04}.. {-121122000 -14400 0 -04}.. {-99950400 -10800 1 -04}.. {-89586000 -14400 0 -04}.. {-68414400 -10800 1 -04}.. {-57963600 -14400 0 -04}.. {499752000 -10800 1 -04}.. {511239600 -14400 0 -04}.. {530596800 -10800 1 -04}.. {540270000 -14400 0 -04}.. {562132800 -10800 1 -04}.. {571201200
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):246
                                                                                                                                                                                                            Entropy (8bit):4.705337479465446
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/290bJhDm2OHDgoHvcuknov/zEXPKV2kR/uFVEV/KVg:MB86290bLmdHDgCvcukCz8O2Y/uF2/Og
                                                                                                                                                                                                            MD5:DB019451A7D678C3E7AEE706283861F6
                                                                                                                                                                                                            SHA1:57E63C5372F50CBD1A7FA32688C1B77ADDCC06EB
                                                                                                                                                                                                            SHA-256:B6ADC16815DC95E537548CA3572D7F93626A6D1DC390DD4CBABAB5AB855BBA30
                                                                                                                                                                                                            SHA-512:6C94B2D7EFA856E6BD41FC45B0E8D16A40E61D8B895397CD71230047FAD4793DDB9ABAAC57D2841549F161C9389D7E61D54D38F1BAC6F13ED3DD4C68CDD3272C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Bogota) {.. {-9223372036854775808 -17776 0 LMT}.. {-2707671824 -17776 0 BMT}.. {-1739041424 -18000 0 -05}.. {704869200 -14400 1 -05}.. {733896000 -18000 0 -05}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8605
                                                                                                                                                                                                            Entropy (8bit):3.8563913604109064
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:eSwtktXNmGaLV911sF7Lv/PCewtA8CzSPyDLbrcUia:/jXNDPlLv/PCenJzS6cy
                                                                                                                                                                                                            MD5:005D0BF1320030A7E9CDC97D0C8BB44B
                                                                                                                                                                                                            SHA1:CB236DA840A49B4BCD261114DCA38DADA567B091
                                                                                                                                                                                                            SHA-256:93AF910CB2AD2203B71C1AD49D56DF4A4A14D07F885AFD4E755271F1372A517C
                                                                                                                                                                                                            SHA-512:16A5483392741673BEC020EF6EBE963AB0FB12629D662C586C27A1E9A1BE3FEA8DC3D05A0E84917B8166E48CADA45C74DFABFDC897A6BC94D3C5058D31AD5126
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Boise) {.. {-9223372036854775808 -27889 0 LMT}.. {-2717640000 -28800 0 PST}.. {-1633269600 -25200 1 PDT}.. {-1615129200 -28800 0 PST}.. {-1601820000 -25200 1 PDT}.. {-1583679600 -28800 0 PST}.. {-1471788000 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-84380400 -21600 1 MDT}.. {-68659200 -25200 0 MST}.. {-52930800 -21600 1 MDT}.. {-37209600 -25200 0 MST}.. {-21481200 -21600 1 MDT}.. {-5760000 -25200 0 MST}.. {9968400 -21600 1 MDT}.. {25689600 -25200 0 MST}.. {41418000 -21600 1 MDT}.. {57744000 -25200 0 MST}.. {73472400 -21600 1 MDT}.. {89193600 -25200 0 MST}.. {104922000 -21600 1 MDT}.. {120643200 -25200 0 MST}.. {126255600 -25200 0 MST}.. {129114000 -21600 0 MDT}.. {152092800 -25200 0 MST}.. {162378000 -21600 1 MDT}.. {183542400 -25200 0 MST}.. {199270800 -21600 1 MDT}.. {
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):239
                                                                                                                                                                                                            Entropy (8bit):4.821972751564724
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7/MQA+zAHAIgp/MQA+zE5N/290BFzk5h490/MQA+zd:MByMY/MV+zhp/MV+zE5t290rzy490/MW
                                                                                                                                                                                                            MD5:6700956D5FE96CEC8D34EB49FF805374
                                                                                                                                                                                                            SHA1:69B9973EF31AE204EFED7485E59CEA99E00815C8
                                                                                                                                                                                                            SHA-256:DEFC5C9DA2D4D4146145A50D692A6BFF698C3B0A1F19EFD82AD0EE7678F39FCF
                                                                                                                                                                                                            SHA-512:A80C03A519F00A4270248E885463090A34B3992B3DEBA94DD6AEBCC50736541655461E4AA10856125B8EF9B92CEB697429EE7088DBC6AB4FAE383FDF11521B7A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Argentina/Buenos_Aires)]} {.. LoadTimeZoneFile America/Argentina/Buenos_Aires..}..set TZData(:America/Buenos_Aires) $TZData(:America/Argentina/Buenos_Aires)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7739
                                                                                                                                                                                                            Entropy (8bit):3.8713679494465016
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:zsGaLV9T1sF7Lv/PCewtA8CzSPyDLbrcUia:h5lLv/PCenJzS6cy
                                                                                                                                                                                                            MD5:E6AE12CDB55FED492C253E46E2690FE0
                                                                                                                                                                                                            SHA1:CD3699E50BC1694827E51E4101C713E52FA646C8
                                                                                                                                                                                                            SHA-256:3E0506A54B562DBC3AA6889DDD39B327FE0B85C63B00F0B39D606921A0936A59
                                                                                                                                                                                                            SHA-512:BA3D5D5420210E74E74A581C9678224948266828A8FACE06383E41E13475C682F82D288426FB915D618FFE7ED95BD8F1C7E9D59D31CE5B464D5EC1363AB5E340
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Cambridge_Bay) {.. {-9223372036854775808 0 0 -00}.. {-1577923200 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-147891600 -18000 1 MDDT}.. {-131562000 -25200 0 MST}.. {325674000 -21600 1 MDT}.. {341395200 -25200 0 MST}.. {357123600 -21600 1 MDT}.. {372844800 -25200 0 MST}.. {388573200 -21600 1 MDT}.. {404899200 -25200 0 MST}.. {420022800 -21600 1 MDT}.. {436348800 -25200 0 MST}.. {452077200 -21600 1 MDT}.. {467798400 -25200 0 MST}.. {483526800 -21600 1 MDT}.. {499248000 -25200 0 MST}.. {514976400 -21600 1 MDT}.. {530697600 -25200 0 MST}.. {544611600 -21600 1 MDT}.. {562147200 -25200 0 MST}.. {576061200 -21600 1 MDT}.. {594201600 -25200 0 MST}.. {607510800 -21600 1 MDT}.. {625651200 -25200 0 MST}.. {638960400 -21600 1 MDT}.. {657100800 -25200 0 MST}.. {671014800 -21600 1 MDT}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2918
                                                                                                                                                                                                            Entropy (8bit):3.6039149423727013
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:591PSeSFESoSQSrSsCSeSPS1cSQSQlSsSyZS2SqLSwZS4vSoSUSLpSzS4X3/SxSs:5VsE3LMuJALTvn1ZdP7ZbvLfeAh+KIic
                                                                                                                                                                                                            MD5:230A9F7A87BA56C30ACB3B1732F823F3
                                                                                                                                                                                                            SHA1:8263EA723F2AEA7740C7EC54BE0000A06982D765
                                                                                                                                                                                                            SHA-256:6D5BD1355016B03EDEA58DF98BEC26281CD372725B2DCB60B4D748D2FB4346C8
                                                                                                                                                                                                            SHA-512:C357AA33833DBBDC6BC7DD3F23469EADDF08564AF17D7EE935C8AEA5F35B6E3BBDE1E181BC0DBF264051C4BE139261055633D191413DD610B0150AB3CDE161AF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Campo_Grande) {.. {-9223372036854775808 -13108 0 LMT}.. {-1767212492 -14400 0 -04}.. {-1206954000 -10800 1 -04}.. {-1191358800 -14400 0 -04}.. {-1175371200 -10800 1 -04}.. {-1159822800 -14400 0 -04}.. {-633816000 -10800 1 -04}.. {-622065600 -14400 0 -04}.. {-602280000 -10800 1 -04}.. {-591829200 -14400 0 -04}.. {-570744000 -10800 1 -04}.. {-560206800 -14400 0 -04}.. {-539121600 -10800 1 -04}.. {-531349200 -14400 0 -04}.. {-191361600 -10800 1 -04}.. {-184194000 -14400 0 -04}.. {-155160000 -10800 1 -04}.. {-150066000 -14400 0 -04}.. {-128894400 -10800 1 -04}.. {-121122000 -14400 0 -04}.. {-99950400 -10800 1 -04}.. {-89586000 -14400 0 -04}.. {-68414400 -10800 1 -04}.. {-57963600 -14400 0 -04}.. {499752000 -10800 1 -04}.. {511239600 -14400 0 -04}.. {530596800 -10800 1 -04}.. {540270000 -14400 0 -04}.. {562132800 -10800 1 -04}.. {571201
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1412
                                                                                                                                                                                                            Entropy (8bit):4.034087321254386
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5s5edTS/uVV3iVP/uaP/uAyAhbS+V8S+FfS+UvS+MS+FB3S+QS+rcS+kS+RS+dSB:5DziZAmELf0On9uhcinzPPoUlWQW3
                                                                                                                                                                                                            MD5:7FBCA91F4B7100C4667F24A9AB263109
                                                                                                                                                                                                            SHA1:163A77FF9EAC49B00B5F838DF4D47F079ECF6A83
                                                                                                                                                                                                            SHA-256:FD6C370F82E5CFE374637E0E222E72570857AC3F85143BEEEF9C3D0E7A6C0D04
                                                                                                                                                                                                            SHA-512:124A5D7F58B38F15A90BA48E63D1D38335371D98A2503E691EC6426EB51E87FD61CA05FCA83573DD1DC06DB9E599302C64D226D5DF13B8A62E0A6943318431BE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Cancun) {.. {-9223372036854775808 -20824 0 LMT}.. {-1514743200 -21600 0 CST}.. {377935200 -18000 0 EST}.. {828860400 -14400 1 EDT}.. {846396000 -18000 0 EST}.. {860310000 -14400 1 EDT}.. {877845600 -18000 0 EST}.. {891759600 -14400 1 EDT}.. {902041200 -18000 0 CDT}.. {909298800 -21600 0 CST}.. {923212800 -18000 1 CDT}.. {941353200 -21600 0 CST}.. {954662400 -18000 1 CDT}.. {972802800 -21600 0 CST}.. {989136000 -18000 1 CDT}.. {1001833200 -21600 0 CST}.. {1018166400 -18000 1 CDT}.. {1035702000 -21600 0 CST}.. {1049616000 -18000 1 CDT}.. {1067151600 -21600 0 CST}.. {1081065600 -18000 1 CDT}.. {1099206000 -21600 0 CST}.. {1112515200 -18000 1 CDT}.. {1130655600 -21600 0 CST}.. {1143964800 -18000 1 CDT}.. {1162105200 -21600 0 CST}.. {1175414400 -18000 1 CDT}.. {1193554800 -21600 0 CST}.. {1207468800 -18000 1 CDT}.. {1225004400 -21600 0
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):284
                                                                                                                                                                                                            Entropy (8bit):4.588048586971241
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2909+ETlDm2OHXoHv8HkISlvFVFQVgVJUF/R/OXFxWnVVFQVgVVvR/e:MB86290XmdHXCvydSltvAUeFZ/O/qVva
                                                                                                                                                                                                            MD5:5DDB49759D58931A06740A14F76B431C
                                                                                                                                                                                                            SHA1:E9AC99265D42D140E12BB4DAAA24FABAC65E79FA
                                                                                                                                                                                                            SHA-256:D558C25F165E956E980AA8F554AB3BF24E91B51EADBD2B1065EF6DFDA0E2F984
                                                                                                                                                                                                            SHA-512:318804ED41F36A3A8746C8CD286116787A768B06CAD6057559D1C7105170DE6EAB807EFA52AA8A0E353491B6F8C47D623D4473C1AEAD20B5C00747E07BB282B2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Caracas) {.. {-9223372036854775808 -16064 0 LMT}.. {-2524505536 -16060 0 CMT}.. {-1826739140 -16200 0 -0430}.. {-157750200 -14400 0 -04}.. {1197183600 -16200 0 -0430}.. {1462086000 -14400 0 -04}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):227
                                                                                                                                                                                                            Entropy (8bit):4.666638841481612
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7/MMXAXHAIgp/MMXmRN/29094SXAFB5290/MMXAy:MByMY/MYp/MrRt290mh5290/MK
                                                                                                                                                                                                            MD5:EEB851BE330BCC44A4831763534058B9
                                                                                                                                                                                                            SHA1:A5FC3E69DDBD3C40D9EB4317BBD5BB6C78751B36
                                                                                                                                                                                                            SHA-256:37CD6BDAA6C6EEDFAC3288CA1C11F5CBBE8A17E5F2E790E7635A64B867AFBD87
                                                                                                                                                                                                            SHA-512:7CD0BC822550325EB3198B4AD6CCD38938FA654A03A09C53117560D1FE3FDCD9C892D105F0D7AF44ED52DD7E0475721240D74A10C98619BE9EC4F5410B8FD87D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Argentina/Catamarca)]} {.. LoadTimeZoneFile America/Argentina/Catamarca..}..set TZData(:America/Catamarca) $TZData(:America/Argentina/Catamarca)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):185
                                                                                                                                                                                                            Entropy (8bit):4.832612867310476
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/2IAcGE91INMXGm2OHEFvpoeoHsdR4FIUPvGXFkUwXvp3VVV:SlSWB9eg/2909qDm2OHEdGeoHm4vOXF6
                                                                                                                                                                                                            MD5:6052E52C8E5A5F43102C47D895797A1F
                                                                                                                                                                                                            SHA1:23DBD40AE96C84E44ADCD1AC33E7871D217C17BC
                                                                                                                                                                                                            SHA-256:873285F3E13CB68DD28EB109ECAD8D260E11A9FF6DF6A4E8E0D4C00B0182695B
                                                                                                                                                                                                            SHA-512:DDE89C70B6F24AD4F585DC5424A6D029E5C898254C9085C588AE699CED4C8316840FF7C87685D7CFAA2E689F01687985454A0C9E3886342E936C56AB688DF732
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Cayenne) {.. {-9223372036854775808 -12560 0 LMT}.. {-1846269040 -14400 0 -04}.. {-71092800 -10800 0 -03}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):185
                                                                                                                                                                                                            Entropy (8bit):4.774923706273939
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0u55DyXHAIg20u5cvRL/2IAcGE91mr4IAcGEu5pvn:SlSWB9vsM3y7oDSHAIgpdN/2909Yr49F
                                                                                                                                                                                                            MD5:AD6E086BEDF05A0BEB66990BD9518BEE
                                                                                                                                                                                                            SHA1:FA0B7E8D6931E79092A90F7EECBA2293AE886AE3
                                                                                                                                                                                                            SHA-256:C38C49AE1C3E67BD2118002DCFCC3C0EFB6892FB9B0106908A9282C414D0BF2E
                                                                                                                                                                                                            SHA-512:A1E40422D15DBCB24A6FE353639A1541FAD7F394D20F8AEB32D4E39667BA264C3E815BAA703B88B90D381540168016A0641CA220BACAF05E80EAA698642B6FFA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Panama)]} {.. LoadTimeZoneFile America/Panama..}..set TZData(:America/Cayman) $TZData(:America/Panama)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):11372
                                                                                                                                                                                                            Entropy (8bit):3.814348526052702
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:l6u30Ke1rdJ8SUklvgahLi8hbZlNA604qSScBgN+4ctDzIVQ/c/3hNxTh:l1EKwdJ8SUkl4aUqtfA604qSBgI7DBch
                                                                                                                                                                                                            MD5:763E23AA7FB20F8D7CB2F0E87FAFD153
                                                                                                                                                                                                            SHA1:B131A10C1C208BB5E5E178ACD21A679FD0537AC5
                                                                                                                                                                                                            SHA-256:C7707AF88D650F90839E7258356E39D85228B33B6DBCC5C065C3D8733AE28CEE
                                                                                                                                                                                                            SHA-512:FE9C5D2EA253338DDFD79CC8ED2F94D6817BD770C0895752EFB1917E2313735C18475D67191C29BCCD53DEFFF35C1BF0CA5D98C92091DDCD1E97CD6302DC73A4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Chicago) {.. {-9223372036854775808 -21036 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-1577901600 -21600 0 CST}.. {-1563724800 -18000 1 CDT}.. {-1551632400 -21600 0 CST}.. {-1538928000 -18000 1 CDT}.. {-1520182800 -21600 0 CST}.. {-1504454400 -18000 1 CDT}.. {-1491757200 -21600 0 CST}.. {-1473004800 -18000 1 CDT}.. {-1459702800 -21600 0 CST}.. {-1441555200 -18000 1 CDT}.. {-1428253200 -21600 0 CST}.. {-1410105600 -18000 1 CDT}.. {-1396803600 -21600 0 CST}.. {-1378656000 -18000 1 CDT}.. {-1365354000 -21600 0 CST}.. {-1347206400 -18000 1 CDT}.. {-1333904400 -21600 0 CST}.. {-1315152000 -18000 1 CDT}.. {-1301850000 -21600 0 CST}.. {-1283702400 -18000 1 CDT}.. {-1270400400 -21600 0 CST}.. {-1252252800 -18000 1 CDT}.. {-1238950800
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2040
                                                                                                                                                                                                            Entropy (8bit):4.006586050664275
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5wE2e49WU0S+VS+TjV/NF01YmM/parZ375+XiBn:5wEvU033FS1YrpaV5+yBn
                                                                                                                                                                                                            MD5:67738E07092EDB5A9F484ED5CA217EFB
                                                                                                                                                                                                            SHA1:9E428C67AE4BDACA48D189DF60374F3B6523E120
                                                                                                                                                                                                            SHA-256:93438D65EA8F95691748FF749219FAFA1940469BC61CED0B7CBF995B417F20B4
                                                                                                                                                                                                            SHA-512:57C9FE7EAE37504465F33B2AB079ED91700528E330D227E94AE8A06C58DEFA65F1EA1CDF89F835910D92D037DADB45E684A2EA96512B08F83650DD33CCEB8EB6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Chihuahua) {.. {-9223372036854775808 -25460 0 LMT}.. {-1514739600 -25200 0 MST}.. {-1343066400 -21600 0 CST}.. {-1234807200 -25200 0 MST}.. {-1220292000 -21600 1 MDT}.. {-1207159200 -25200 0 MST}.. {-1191344400 -21600 0 CST}.. {820476000 -21600 0 CST}.. {828864000 -18000 1 CDT}.. {846399600 -21600 0 CST}.. {860313600 -18000 1 CDT}.. {877849200 -21600 0 CST}.. {883634400 -21600 0 CST}.. {891766800 -21600 0 MDT}.. {909302400 -25200 0 MST}.. {923216400 -21600 1 MDT}.. {941356800 -25200 0 MST}.. {954666000 -21600 1 MDT}.. {972806400 -25200 0 MST}.. {989139600 -21600 1 MDT}.. {1001836800 -25200 0 MST}.. {1018170000 -21600 1 MDT}.. {1035705600 -25200 0 MST}.. {1049619600 -21600 1 MDT}.. {1067155200 -25200 0 MST}.. {1081069200 -21600 1 MDT}.. {1099209600 -25200 0 MST}.. {1112518800 -21600 1 MDT}.. {1130659200 -25200 0 MST}.. {1143968400 -
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):192
                                                                                                                                                                                                            Entropy (8bit):4.844590153688034
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0u55DyXHAIg20u5cvRL/2IAcGE9WtEaQXs+IAcGEi:SlSWB9vsM3y7oDSHAIgpdN/2909qEacn
                                                                                                                                                                                                            MD5:A0BF04CD77026DC1D2749848AB0EE45E
                                                                                                                                                                                                            SHA1:EA0F1BC11379DF2E421675BC5DE4805CE94B96D6
                                                                                                                                                                                                            SHA-256:C8CBF5A29CC1D0827390CA6E98B2EFCF90743C6DD0ECA143B300050DD4164041
                                                                                                                                                                                                            SHA-512:61968B4E42ECC60C801F959D18D13187AD39D9B81FA1A947F6B6862F99D73E3A30849AC4233DB5705D46F5373C42D8748B15BE9B82822971B4F47E601E5766D8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Panama)]} {.. LoadTimeZoneFile America/Panama..}..set TZData(:America/Coral_Harbour) $TZData(:America/Panama)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):219
                                                                                                                                                                                                            Entropy (8bit):4.78887878252354
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7/MSHAIgp/M1ovN/29093+90/M7:MByMY/M7p/M16t290c90/M7
                                                                                                                                                                                                            MD5:C7CCF5CEC7AA60D6063D1C30F4263ADC
                                                                                                                                                                                                            SHA1:FD8E9AEEEE50656FD3C694CA051895DDC8E5590B
                                                                                                                                                                                                            SHA-256:28B84710EADEF7AD5E7FA63EF519A9D93996D3BB91DD9018333DE3AC4D8FB8DD
                                                                                                                                                                                                            SHA-512:6974F8B238977EE5222368C4B79327BB240580819FCA082261D6994781144D81E2E8843B4F1C9D07EFBEE27311C8930BDAC9C0D6D6718F6FB1600D0000576CDE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Argentina/Cordoba)]} {.. LoadTimeZoneFile America/Argentina/Cordoba..}..set TZData(:America/Cordoba) $TZData(:America/Argentina/Cordoba)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):431
                                                                                                                                                                                                            Entropy (8bit):4.506976345480408
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB86290lnmdHd5CvZN/Mi3yvI8/uF+wSJz/uF+IA/uF+i/X8/uF+ZDVxNv:5mnedIvZN/e5S+w+S+LS+i0S+pB
                                                                                                                                                                                                            MD5:0446EF1A6985A62EDFFB9FFAC7F1DE0E
                                                                                                                                                                                                            SHA1:A43468E120E585E2DCC20205BA1D1E2CCB6C0BC2
                                                                                                                                                                                                            SHA-256:E3061DC6FA9F869F013351A9FDF420448592D7F959C2B4404093432508146F7E
                                                                                                                                                                                                            SHA-512:86D41B0C49489572C3EAEDD5466AA92319C721CCEC9437EBB0F2AAD772FB5ED91A2F2061E00448FB48096B0BAAE9A4E1E644F8AF595B76BE05DBC0C801E6D6ED
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Costa_Rica) {.. {-9223372036854775808 -20173 0 LMT}.. {-2524501427 -20173 0 SJMT}.. {-1545071027 -21600 0 CST}.. {288770400 -18000 1 CDT}.. {297234000 -21600 0 CST}.. {320220000 -18000 1 CDT}.. {328683600 -21600 0 CST}.. {664264800 -18000 1 CDT}.. {678344400 -21600 0 CST}.. {695714400 -18000 1 CDT}.. {700635600 -21600 0 CST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):189
                                                                                                                                                                                                            Entropy (8bit):4.8664633847782905
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0utLaDovXHAIg20utLRYovHRL/2IAcGE9mM7x/h4y:SlSWB9vsM3y7OBHAIgpONYyHN/2909vr
                                                                                                                                                                                                            MD5:0757DD22C0E297CCE8E6678ECA4B39C7
                                                                                                                                                                                                            SHA1:81B31299F9A35C8BA2EC1F59EC21129FFCDCD52F
                                                                                                                                                                                                            SHA-256:A01DDB460420C8765CE8EF7A7D031ABD7BDB17CFA548E7C3B8574C388AA21E17
                                                                                                                                                                                                            SHA-512:F1AFC0F6371A10E4CB74FB2C8985610AEE6C3511861BC09384EDC99D250E9099A1F4430BFC3B0B396C2702BF9991A5A4ECFD53A82C92883460715FA2C1E04579
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Phoenix)]} {.. LoadTimeZoneFile America/Phoenix..}..set TZData(:America/Creston) $TZData(:America/Phoenix)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2912
                                                                                                                                                                                                            Entropy (8bit):3.588248620238414
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5tSeSFESoSQSrSsCSeSPS1cSQSQlSsSyZS2SqLSwZS4vSoSUSLpSzS4X3/SxS1S4:rVsE3LMuJALTvn1ZdP7ZbvLfeAh+KIil
                                                                                                                                                                                                            MD5:264E0CEA9491B404993594E64F13479F
                                                                                                                                                                                                            SHA1:6D4D277FA470A2C7AD0A59B5DA3CC15BEEB74E78
                                                                                                                                                                                                            SHA-256:2D8281CF3FD9E859C5206F781E264854FA876CB36562A08C6C01343C65F8A508
                                                                                                                                                                                                            SHA-512:759C19B4DD0E1F7F1176872806BFB1F17ADF9C992E41B96FEA67D77DD67E9DD3C1683E3B6D27FB092C731F534C6A7441BACFFF0301907217A064523B86992E23
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Cuiaba) {.. {-9223372036854775808 -13460 0 LMT}.. {-1767212140 -14400 0 -04}.. {-1206954000 -10800 1 -04}.. {-1191358800 -14400 0 -04}.. {-1175371200 -10800 1 -04}.. {-1159822800 -14400 0 -04}.. {-633816000 -10800 1 -04}.. {-622065600 -14400 0 -04}.. {-602280000 -10800 1 -04}.. {-591829200 -14400 0 -04}.. {-570744000 -10800 1 -04}.. {-560206800 -14400 0 -04}.. {-539121600 -10800 1 -04}.. {-531349200 -14400 0 -04}.. {-191361600 -10800 1 -04}.. {-184194000 -14400 0 -04}.. {-155160000 -10800 1 -04}.. {-150066000 -14400 0 -04}.. {-128894400 -10800 1 -04}.. {-121122000 -14400 0 -04}.. {-99950400 -10800 1 -04}.. {-89586000 -14400 0 -04}.. {-68414400 -10800 1 -04}.. {-57963600 -14400 0 -04}.. {499752000 -10800 1 -04}.. {511239600 -14400 0 -04}.. {530596800 -10800 1 -04}.. {540270000 -14400 0 -04}.. {562132800 -10800 1 -04}.. {571201200 -1
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):201
                                                                                                                                                                                                            Entropy (8bit):4.876961543280111
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/2909C4e90ppv:MByMYbpwt290690b
                                                                                                                                                                                                            MD5:9459043060E33E8EDC74E78332E96EDF
                                                                                                                                                                                                            SHA1:27963FE063965584D0F226BAE9A08EB2954398F0
                                                                                                                                                                                                            SHA-256:ACCF08CF53C9431E226714DF8BEDE3C91BAF62D5BD7B98CA8B50D7258124D129
                                                                                                                                                                                                            SHA-512:215D9AFAA7227F4447177CE2ABA5A6F7F2F46A9D787845DD32F10D5C22BF9CBE4047AF5E0E66FA7A4F70EEE064A7EC7B67949E565C3C5C60C31F3C19D6915D76
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Curacao) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1128
                                                                                                                                                                                                            Entropy (8bit):3.8794180227436557
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5geNrmFQqFi77FkiVFw1ZFt9SFUXDFH9vMF0mFdS/FyMF8AWXF7HFEJF7cSXHVFS:5/vx7O11pbzvZ+S0xAqe12vey
                                                                                                                                                                                                            MD5:6E37A78AC686A6B48A78541E1900E33C
                                                                                                                                                                                                            SHA1:D41F39FDB6D45921B57341E95A006251B4875961
                                                                                                                                                                                                            SHA-256:968C56F1D0106E1D92C7B094EEF528B6EE1FFA3D7A18BE2F2BA59178C2C0F1E0
                                                                                                                                                                                                            SHA-512:397623149D95FF9A094750EE697F62DF90124BBBE407FB49FBAE335A61629449F2A61EF4471DBD57745B323DFCF3628611CAE9295F2EF7E4A7412A697651FF68
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Danmarkshavn) {.. {-9223372036854775808 -4480 0 LMT}.. {-1686091520 -10800 0 -03}.. {323845200 -7200 0 -02}.. {338950800 -10800 0 -03}.. {354675600 -7200 1 -02}.. {370400400 -10800 0 -03}.. {386125200 -7200 1 -02}.. {401850000 -10800 0 -03}.. {417574800 -7200 1 -02}.. {433299600 -10800 0 -03}.. {449024400 -7200 1 -02}.. {465354000 -10800 0 -03}.. {481078800 -7200 1 -02}.. {496803600 -10800 0 -03}.. {512528400 -7200 1 -02}.. {528253200 -10800 0 -03}.. {543978000 -7200 1 -02}.. {559702800 -10800 0 -03}.. {575427600 -7200 1 -02}.. {591152400 -10800 0 -03}.. {606877200 -7200 1 -02}.. {622602000 -10800 0 -03}.. {638326800 -7200 1 -02}.. {654656400 -10800 0 -03}.. {670381200 -7200 1 -02}.. {686106000 -10800 0 -03}.. {701830800 -7200 1 -02}.. {717555600 -10800 0 -03}.. {733280400 -7200 1 -02}.. {749005200 -10800 0 -03}.. {764730000 -72
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2967
                                                                                                                                                                                                            Entropy (8bit):3.9564096415565855
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5IeVvxBn4nRfngnSSXRwEg7MkwY7Twbg7Uwr70vwHg7b6wa7gAHwc7/wzZg7ywJP:5zxKKpj/AOZFCARCeQbvb5wxMN6Ix
                                                                                                                                                                                                            MD5:F494405F3B250668BE00DC3864B9A2DC
                                                                                                                                                                                                            SHA1:20843AD6D95DD5D5950E2946BCAE4ECE2B676F70
                                                                                                                                                                                                            SHA-256:30E875343C81C8DE473E6313A27C55315F38E7CCDBD2CEE5783EC54D269D5807
                                                                                                                                                                                                            SHA-512:9102BD114436D5FE5A1942E31AE692ECE41F910AC1B6E52C02283801D5AA00CFF22D980C61E69928267D3DD34331E301C7324CA631B71AC2FBBDE06D7914F849
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Dawson) {.. {-9223372036854775808 -33460 0 LMT}.. {-2188996940 -32400 0 YST}.. {-1632056400 -28800 1 YDT}.. {-1615125600 -32400 0 YST}.. {-1596978000 -28800 1 YDT}.. {-1583164800 -32400 0 YST}.. {-880203600 -28800 1 YWT}.. {-769395600 -28800 1 YPT}.. {-765381600 -32400 0 YST}.. {-147884400 -25200 1 YDDT}.. {-131554800 -32400 0 YST}.. {315561600 -28800 0 PST}.. {325677600 -25200 1 PDT}.. {341398800 -28800 0 PST}.. {357127200 -25200 1 PDT}.. {372848400 -28800 0 PST}.. {388576800 -25200 1 PDT}.. {404902800 -28800 0 PST}.. {420026400 -25200 1 PDT}.. {436352400 -28800 0 PST}.. {452080800 -25200 1 PDT}.. {467802000 -28800 0 PST}.. {483530400 -25200 1 PDT}.. {499251600 -28800 0 PST}.. {514980000 -25200 1 PDT}.. {530701200 -28800 0 PST}.. {544615200 -25200 1 PDT}.. {562150800 -28800 0 PST}.. {576064800 -25200 1 PDT}.. {594205200 -28800 0 P
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1940
                                                                                                                                                                                                            Entropy (8bit):4.024810417421672
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5/eUv5wk7Zw9JmnRsw78wP+7bw+7zwN7SynwpBZ7Fwk47H+wW73wo5775w572Iwl:5DuY/YRRvkGZ+R64CjSUlTGS
                                                                                                                                                                                                            MD5:7868720D39782147B2BD6B039A5BF7E0
                                                                                                                                                                                                            SHA1:6F66404E5CCFF7F020269A316D792D5E7AD4C280
                                                                                                                                                                                                            SHA-256:540804BECDEAB92340EF02D32A62BFD550B71A3DB8D829BE426EE4D210004643
                                                                                                                                                                                                            SHA-512:9CCD124FF954CA2988F07286FFE9ED740E0CEF5F4D76BF090367B74A577E91BF5590EDFE12AFC83ACF5CBFC88C5A68867C58082A2777D08C326A7B18889B08E2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Dawson_Creek) {.. {-9223372036854775808 -28856 0 LMT}.. {-2713881544 -28800 0 PST}.. {-1632060000 -25200 1 PDT}.. {-1615129200 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-725817600 -28800 0 PST}.. {-715788000 -25200 1 PDT}.. {-702486000 -28800 0 PST}.. {-684338400 -25200 1 PDT}.. {-671036400 -28800 0 PST}.. {-652888800 -25200 1 PDT}.. {-639586800 -28800 0 PST}.. {-620834400 -25200 1 PDT}.. {-608137200 -28800 0 PST}.. {-589384800 -25200 1 PDT}.. {-576082800 -28800 0 PST}.. {-557935200 -25200 1 PDT}.. {-544633200 -28800 0 PST}.. {-526485600 -25200 1 PDT}.. {-513183600 -28800 0 PST}.. {-495036000 -25200 1 PDT}.. {-481734000 -28800 0 PST}.. {-463586400 -25200 1 PDT}.. {-450284400 -28800 0 PST}.. {-431532000 -25200 1 PDT}.. {-418230000 -28800 0 PST}.. {-400082400 -25200 1 PDT}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8920
                                                                                                                                                                                                            Entropy (8bit):3.8540632258197514
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:gjGtwmGaLV911sF7Lv/PCewtA8CzSPyDLbrcUia:gUwDPlLv/PCenJzS6cy
                                                                                                                                                                                                            MD5:0D649599A899ECB3FCF2783DCEE3E37B
                                                                                                                                                                                                            SHA1:ACC796BE75F41A12FB1F8CCBD2B2839AF9876FFE
                                                                                                                                                                                                            SHA-256:3FE2EE8C05C5D6F268B58BD9FC3E3A845DEA257473B29F7B3FB403E917448F3C
                                                                                                                                                                                                            SHA-512:C10D41AB95439B8E978F12F9F58D1ACC9AD15404123FA5FBA0D1CC716E5CF5DA6BD2252450055AC3998DBCB8DD49F7A82ACD53413E3EE78CDA2C42F603DE2C56
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Denver) {.. {-9223372036854775808 -25196 0 LMT}.. {-2717643600 -25200 0 MST}.. {-1633273200 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1601823600 -21600 1 MDT}.. {-1583683200 -25200 0 MST}.. {-1577898000 -25200 0 MST}.. {-1570374000 -21600 1 MDT}.. {-1551628800 -25200 0 MST}.. {-1538924400 -21600 1 MDT}.. {-1534089600 -25200 0 MST}.. {-883587600 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-757357200 -25200 0 MST}.. {-147884400 -21600 1 MDT}.. {-131558400 -25200 0 MST}.. {-116434800 -21600 1 MDT}.. {-100108800 -25200 0 MST}.. {-94669200 -25200 0 MST}.. {-84380400 -21600 1 MDT}.. {-68659200 -25200 0 MST}.. {-52930800 -21600 1 MDT}.. {-37209600 -25200 0 MST}.. {-21481200 -21600 1 MDT}.. {-5760000 -25200 0 MST}.. {9968400 -21600 1 MDT}.. {25689600 -25200 0 MST}.. {41418000 -2
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8430
                                                                                                                                                                                                            Entropy (8bit):3.826664943157435
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:SGiS1A5tCt/cL1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:SG/K5ItON0HY2iUmUFLqU
                                                                                                                                                                                                            MD5:2BBA922E9377D257CBDF6E1367BBB1A2
                                                                                                                                                                                                            SHA1:6F33A44834E8041E78660A326A5DDAF3D7F9DC2A
                                                                                                                                                                                                            SHA-256:84F6897B87D3978D30D35097B78C55434CE55EB65D6E488A391DFC3B3BB5A8FE
                                                                                                                                                                                                            SHA-512:D225824945C08A3521A8288B92B26DFFA712ED3505E72DEDE4A7D1777E58DEA79ADF3F042D22624E4142DD4203BAA4DFF8EB08B7033FDF00059F6C39954EA1A1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Detroit) {.. {-9223372036854775808 -19931 0 LMT}.. {-2051202469 -21600 0 CST}.. {-1724083200 -18000 0 EST}.. {-883594800 -18000 0 EST}.. {-880218000 -14400 1 EWT}.. {-769395600 -14400 1 EPT}.. {-765396000 -18000 0 EST}.. {-757364400 -18000 0 EST}.. {-684349200 -14400 1 EDT}.. {-671047200 -18000 0 EST}.. {-80506740 -14400 0 EDT}.. {-68666400 -18000 0 EST}.. {-52938000 -14400 1 EDT}.. {-37216800 -18000 0 EST}.. {-31518000 -18000 0 EST}.. {94712400 -18000 0 EST}.. {104914800 -14400 1 EDT}.. {120636000 -18000 0 EST}.. {126687600 -14400 1 EDT}.. {152085600 -18000 0 EST}.. {157784400 -18000 0 EST}.. {167814000 -14400 0 EDT}.. {183535200 -18000 0 EST}.. {199263600 -14400 1 EDT}.. {215589600 -18000 0 EST}.. {230713200 -14400 1 EDT}.. {247039200 -18000 0 EST}.. {262767600 -14400 1 EDT}.. {278488800 -18000 0 EST}.. {294217200 -14400 1 EDT}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):202
                                                                                                                                                                                                            Entropy (8bit):4.86856578093135
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290TL3290ppv:MByMYbpwt290Tr290b
                                                                                                                                                                                                            MD5:398D8DBB24CEA2D174EF05F63869C94A
                                                                                                                                                                                                            SHA1:6D0E04165952E873E6ECA33A0E54761B747F0A98
                                                                                                                                                                                                            SHA-256:3DA98AA7D3085845779BE8ED6C93CCBDA92191F17CA67BBF779803E21DA2ABF3
                                                                                                                                                                                                            SHA-512:2652AFD1A3F8A4B84078A964005FE10C64491EC2D47CDE57D5066D07D1D837308FD696F53B9E7B6B0E72F86F9A85128B8CBF5F302F91EADE6D840DF946DE85CD
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Dominica) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8600
                                                                                                                                                                                                            Entropy (8bit):3.8579895970456137
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:7SabOGaLm911sF7Lv/PCewtA8CzSPyDLbrcUia:7vf4lLv/PCenJzS6cy
                                                                                                                                                                                                            MD5:EBD169ECA4D45EED28BF7B27809361BC
                                                                                                                                                                                                            SHA1:E89C8484A29D792FB6349CFDFDD30C2FA6B78B6B
                                                                                                                                                                                                            SHA-256:026D51D73D30A3710288F440E0C337E44E3A14D0AA2D7B6C6E53AF43FC72A90C
                                                                                                                                                                                                            SHA-512:45C936ED7D4AF95261180547013454AAEC9FA7672B52AC6077DD99D9FEB6DDD57652FE4EC67BF81F1588384F3027A1872E0C72D9CAEB980B66D2CB6EE9B8ABB0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Edmonton) {.. {-9223372036854775808 -27232 0 LMT}.. {-1998663968 -25200 0 MST}.. {-1632063600 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1600614000 -21600 1 MDT}.. {-1596816000 -25200 0 MST}.. {-1567954800 -21600 1 MDT}.. {-1551628800 -25200 0 MST}.. {-1536505200 -21600 1 MDT}.. {-1523203200 -25200 0 MST}.. {-1504450800 -21600 1 MDT}.. {-1491753600 -25200 0 MST}.. {-1473001200 -21600 1 MDT}.. {-1459699200 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-715791600 -21600 1 MDT}.. {-702489600 -25200 0 MST}.. {73472400 -21600 1 MDT}.. {89193600 -25200 0 MST}.. {104922000 -21600 1 MDT}.. {120643200 -25200 0 MST}.. {136371600 -21600 1 MDT}.. {152092800 -25200 0 MST}.. {167821200 -21600 1 MDT}.. {183542400 -25200 0 MST}.. {199270800 -21600 1 MDT}.. {215596800 -25200 0 MST}.. {23072
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1230
                                                                                                                                                                                                            Entropy (8bit):3.7989525000422963
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5OXUepdkZss/uuD/uVK/uNC/uvFe/uxJs/u74O/u83C/uc8J/uhF8/uNHs/ulU6w:5OXCZsMw57XJh4CxUF/A6GTrtSUUhfL0
                                                                                                                                                                                                            MD5:6766E75702D8C2D1C986DFCEFCE554F9
                                                                                                                                                                                                            SHA1:39553F80D82BC0134FAF70C9830B96BDCBCEFF1C
                                                                                                                                                                                                            SHA-256:48FC987E5999EA79F24797E0450FE4DAB7CF320DFAD7A47A8A1E037077EC42C9
                                                                                                                                                                                                            SHA-512:A812D0D4254BB0B7DB7AE116652D2A8F97D22C59F2709A17D1CE435FCFB38B807A4E0ED6EA114A66897E29D85226875FA84D28B254A5D17BD1CBA95FAD8349B7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Eirunepe) {.. {-9223372036854775808 -16768 0 LMT}.. {-1767208832 -18000 0 -05}.. {-1206950400 -14400 1 -05}.. {-1191355200 -18000 0 -05}.. {-1175367600 -14400 1 -05}.. {-1159819200 -18000 0 -05}.. {-633812400 -14400 1 -05}.. {-622062000 -18000 0 -05}.. {-602276400 -14400 1 -05}.. {-591825600 -18000 0 -05}.. {-570740400 -14400 1 -05}.. {-560203200 -18000 0 -05}.. {-539118000 -14400 1 -05}.. {-531345600 -18000 0 -05}.. {-191358000 -14400 1 -05}.. {-184190400 -18000 0 -05}.. {-155156400 -14400 1 -05}.. {-150062400 -18000 0 -05}.. {-128890800 -14400 1 -05}.. {-121118400 -18000 0 -05}.. {-99946800 -14400 1 -05}.. {-89582400 -18000 0 -05}.. {-68410800 -14400 1 -05}.. {-57960000 -18000 0 -05}.. {499755600 -14400 1 -05}.. {511243200 -18000 0 -05}.. {530600400 -14400 1 -05}.. {540273600 -18000 0 -05}.. {562136400 -14400 1 -05}.. {571204800
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):279
                                                                                                                                                                                                            Entropy (8bit):4.760311149376001
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/29078iPDm2OHvJ4YoHxHhgdrV/uF+IcmJ3/uF+ivNv:MB8629078AmdHx4YCJSB/uF+QV/uF+w9
                                                                                                                                                                                                            MD5:CEF7277443EB6990E72C7EA7F79A122C
                                                                                                                                                                                                            SHA1:1D3FEA364B3DC129DE3998A1455D5588EBAA6FF8
                                                                                                                                                                                                            SHA-256:C02C6E79398553BD07BEA0BE4B7F0EBDD8BC821595909CFFB49DE4290A0D1D0F
                                                                                                                                                                                                            SHA-512:E6FC530B2CCF010B8D38BC3F49A6859B5C68F4AB604E6305CE75FBE4FC9FF3FCD0187DEBEF6DAE652EEF9695568DBDE31F426E404CC3CC206D78183E0D919234
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/El_Salvador) {.. {-9223372036854775808 -21408 0 LMT}.. {-1546279392 -21600 0 CST}.. {547020000 -18000 1 CDT}.. {559717200 -21600 0 CST}.. {578469600 -18000 1 CDT}.. {591166800 -21600 0 CST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):190
                                                                                                                                                                                                            Entropy (8bit):4.836337676384058
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0qfSfXHAIg20qfORL/2IAcGE7JM7QIAcGEqfBn:SlSWB9vsM3y7ekHAIgpeON/2907390eB
                                                                                                                                                                                                            MD5:005D9C0E50291616A727CFB74A9FD37E
                                                                                                                                                                                                            SHA1:846AE6720382B4F67B37B4256E45246C81DAF899
                                                                                                                                                                                                            SHA-256:3E363BF82545F24CCE8CFA6EEC97BA6E1C2A7730B2A9CE6C48F784821D308A5D
                                                                                                                                                                                                            SHA-512:452326D11D01825764BC40A77D17444D822F3AA202582233DD8B122798478FA83E3A27A02508EAC4CF0C7922AC2563742D773AA870562AE496B34FBB41FBAD63
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Tijuana)]} {.. LoadTimeZoneFile America/Tijuana..}..set TZData(:America/Ensenada) $TZData(:America/Tijuana)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4578
                                                                                                                                                                                                            Entropy (8bit):3.8944281193962818
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5QIgsB/YRRvkGZ+R64CjSUlTG5Al5pj/A1ZFCARCeQbvb5+:6IgzR864CjSETG5sjgZkR/bvt+
                                                                                                                                                                                                            MD5:4A4E023F635C4202018EA9E8F85B5047
                                                                                                                                                                                                            SHA1:38E121FE2D419413E9E791B6C22BFC8D9F7554BC
                                                                                                                                                                                                            SHA-256:AB15023807E7C7D1026C9970D190F1B405D48952464025242C2BB6C6BBB8391A
                                                                                                                                                                                                            SHA-512:F10D21A2C841224879D1C817FC7F477DF582E1BC3603666B55199C098D51D1D5429F8C088C1083C07FC7588AE5C42A1DFBCC6B7C636AD1BE84ED657807A229E5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Fort_Nelson) {.. {-9223372036854775808 -29447 0 LMT}.. {-2713880953 -28800 0 PST}.. {-1632060000 -25200 1 PDT}.. {-1615129200 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-757353600 -28800 0 PST}.. {-725817600 -28800 0 PST}.. {-715788000 -25200 1 PDT}.. {-702486000 -28800 0 PST}.. {-684338400 -25200 1 PDT}.. {-671036400 -28800 0 PST}.. {-652888800 -25200 1 PDT}.. {-639586800 -28800 0 PST}.. {-620834400 -25200 1 PDT}.. {-608137200 -28800 0 PST}.. {-589384800 -25200 1 PDT}.. {-576082800 -28800 0 PST}.. {-557935200 -25200 1 PDT}.. {-544633200 -28800 0 PST}.. {-526485600 -25200 1 PDT}.. {-513183600 -28800 0 PST}.. {-495036000 -25200 1 PDT}.. {-481734000 -28800 0 PST}.. {-463586400 -25200 1 PDT}.. {-450284400 -28800 0 PST}.. {-431532000 -25200 1 PDT}.. {-418230000 -28800 0 PST}.. {
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):231
                                                                                                                                                                                                            Entropy (8bit):4.778858143786314
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y73GK7JHAIgp3GKZRN/290HXYAp4903GK8:MByMY3GK7Kp3GKnt290Hz4903GK8
                                                                                                                                                                                                            MD5:24C369A3091452DCA7AAEBF4F48F5289
                                                                                                                                                                                                            SHA1:2C2174CB16F490689E6FAC17B6D18F4A0DBD2DC9
                                                                                                                                                                                                            SHA-256:C8948616262CF6990739343ABBBD237E572DB49310099E21DD8F9E317F7D11B3
                                                                                                                                                                                                            SHA-512:80F579572754579706B4EEA49BF30456F3231A308E0616DC430E2428A04992412773421542E4F7FE4E4C7491BA88942FA44B49E87E95A2183211AC2AB523B231
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Indiana/Indianapolis)]} {.. LoadTimeZoneFile America/Indiana/Indianapolis..}..set TZData(:America/Fort_Wayne) $TZData(:America/Indiana/Indianapolis)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1423
                                                                                                                                                                                                            Entropy (8bit):3.784027854102512
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5MeajcChlrLPsw6kSS3h5R14eH8tf3GvIkuoYVZaIBXR8nd:5rChlvEw6kSSx5H4a8tf3fkuoYVZDNRo
                                                                                                                                                                                                            MD5:E7939C9A3F83D73B82A6DE359365EFD4
                                                                                                                                                                                                            SHA1:06D6E257DA7C317CAFAF6C0B04567A2453CC1660
                                                                                                                                                                                                            SHA-256:C0A836BDAF07F0376B7B0833A0AB3D52BA6E3E1D6F95E247E1AD351CD1096066
                                                                                                                                                                                                            SHA-512:E2BEA04084489B26ADD9A768D2580C1FF7EBAC8A3EA36818F49E85FB14E01500D59D53904F5A17F4DABEF27B4CC2FC3F977EE4C125E5CE739BBE90C130ED3B07
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Fortaleza) {.. {-9223372036854775808 -9240 0 LMT}.. {-1767216360 -10800 0 -03}.. {-1206957600 -7200 1 -03}.. {-1191362400 -10800 0 -03}.. {-1175374800 -7200 1 -03}.. {-1159826400 -10800 0 -03}.. {-633819600 -7200 1 -03}.. {-622069200 -10800 0 -03}.. {-602283600 -7200 1 -03}.. {-591832800 -10800 0 -03}.. {-570747600 -7200 1 -03}.. {-560210400 -10800 0 -03}.. {-539125200 -7200 1 -03}.. {-531352800 -10800 0 -03}.. {-191365200 -7200 1 -03}.. {-184197600 -10800 0 -03}.. {-155163600 -7200 1 -03}.. {-150069600 -10800 0 -03}.. {-128898000 -7200 1 -03}.. {-121125600 -10800 0 -03}.. {-99954000 -7200 1 -03}.. {-89589600 -10800 0 -03}.. {-68418000 -7200 1 -03}.. {-57967200 -10800 0 -03}.. {499748400 -7200 1 -03}.. {511236000 -10800 0 -03}.. {530593200 -7200 1 -03}.. {540266400 -10800 0 -03}.. {562129200 -7200 1 -03}.. {571197600 -10800 0 -03}.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8372
                                                                                                                                                                                                            Entropy (8bit):3.8225708746657316
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:w4lTPB10KvnpNWMPm4bPJWXtRbALtuFW4ng2CEBJuQaeEy9P19OBYEi/B51B7/BI:wKCC
                                                                                                                                                                                                            MD5:1C8B0B85BB5578E84A4867546111F946
                                                                                                                                                                                                            SHA1:E08A96F5B369FA53BC1F3F839EC14FF9D334F727
                                                                                                                                                                                                            SHA-256:58C207CBD9DE7A7BB15E48A62CEA9F15DA184B945133DEE88EFF29FD8B66B29E
                                                                                                                                                                                                            SHA-512:54CFBF208AB3E58AFB6BEC40265A452A3C4C684D7F278F51D6495FCA544652A1A5E05BC45F600911191B33C936E5D7D43A28FD2B0884AAB9F63B7AD5EFD574A1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Glace_Bay) {.. {-9223372036854775808 -14388 0 LMT}.. {-2131646412 -14400 0 AST}.. {-1632074400 -10800 1 ADT}.. {-1615143600 -14400 0 AST}.. {-880221600 -10800 1 AWT}.. {-769395600 -10800 1 APT}.. {-765399600 -14400 0 AST}.. {-536443200 -14400 0 AST}.. {-526500000 -10800 1 ADT}.. {-513198000 -14400 0 AST}.. {-504907200 -14400 0 AST}.. {63086400 -14400 0 AST}.. {73461600 -10800 1 ADT}.. {89182800 -14400 0 AST}.. {104911200 -10800 1 ADT}.. {120632400 -14400 0 AST}.. {126244800 -14400 0 AST}.. {136360800 -10800 1 ADT}.. {152082000 -14400 0 AST}.. {167810400 -10800 1 ADT}.. {183531600 -14400 0 AST}.. {199260000 -10800 1 ADT}.. {215586000 -14400 0 AST}.. {230709600 -10800 1 ADT}.. {247035600 -14400 0 AST}.. {262764000 -10800 1 ADT}.. {278485200 -14400 0 AST}.. {294213600 -10800 1 ADT}.. {309934800 -14400 0 AST}.. {325663200 -10800 1 ADT}
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):180
                                                                                                                                                                                                            Entropy (8bit):4.973070790103308
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0wQbSeyXHAIg20wQboAFARL/2IAcGE5GZJ4IAcGEH:SlSWB9vsM3y7lbSeSHAIgplbLFAN/291
                                                                                                                                                                                                            MD5:8263D2B39C2EC3B38A179F8BAD5972DD
                                                                                                                                                                                                            SHA1:18D3462F6846768E16036E860DE90FB345C93047
                                                                                                                                                                                                            SHA-256:5FB2CFBA25CE2F49D4C3911AFF8E7E1FF84EFC2D01F5783772E88246BFBC56AC
                                                                                                                                                                                                            SHA-512:C175CAF972459759553001D48921268E9C6268CED56021BA6339F8CE3DD032DA6180E2B82974D3DCD0DC5F21566DFDBFBE1B6CF24E5E893F2335A449452DB27F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Nuuk)]} {.. LoadTimeZoneFile America/Nuuk..}..set TZData(:America/Godthab) $TZData(:America/Nuuk)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):10353
                                                                                                                                                                                                            Entropy (8bit):3.864463676759425
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:zfSacO8f7/ewzlrfFj18KvnpNWMPm4bPJvSuYUHgA0G19OBYEi/B51B7/Bm6BTdW:zfSacOI7/V3SuYUHgAuCC
                                                                                                                                                                                                            MD5:0D646C67105FD0525E7CCC79585CE9DF
                                                                                                                                                                                                            SHA1:06D91FDD8FEEDC299E40079569372F97A9AC6F04
                                                                                                                                                                                                            SHA-256:52D2478289682BF95BFB93D64D679E888C9D23C0F68DFFF7E6E34BFC44B3D892
                                                                                                                                                                                                            SHA-512:FD672613C2B65E12425415630A2F489917EB80DDED41338C9AA7D5D3C6B54E52C516A32493593F518DACF22A91D7A9D2C96DB9C5F1BE2C3BB9842D274BDC04FF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Goose_Bay) {.. {-9223372036854775808 -14500 0 LMT}.. {-2713895900 -12652 0 NST}.. {-1640982548 -12652 0 NST}.. {-1632076148 -9052 1 NDT}.. {-1615145348 -12652 0 NST}.. {-1609446548 -12652 0 NST}.. {-1096921748 -12600 0 NST}.. {-1072989000 -12600 0 NST}.. {-1061670600 -9000 1 NDT}.. {-1048973400 -12600 0 NST}.. {-1030221000 -9000 1 NDT}.. {-1017523800 -12600 0 NST}.. {-998771400 -9000 1 NDT}.. {-986074200 -12600 0 NST}.. {-966717000 -9000 1 NDT}.. {-954624600 -12600 0 NST}.. {-935267400 -9000 1 NDT}.. {-922570200 -12600 0 NST}.. {-903817800 -9000 1 NDT}.. {-891120600 -12600 0 NST}.. {-872368200 -9000 0 NWT}.. {-769395600 -9000 1 NPT}.. {-765401400 -12600 0 NST}.. {-757369800 -12600 0 NST}.. {-746044200 -9000 1 NDT}.. {-733347000 -12600 0 NST}.. {-714594600 -9000 1 NDT}.. {-701897400 -12600 0 NST}.. {-683145000 -9000 1 NDT}.. {-67044
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7522
                                                                                                                                                                                                            Entropy (8bit):3.84007813579738
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:pGStCt/cL1BRv0HY2iU7KKdFL6Aa2K4gSLf8e:pvItOx0HY2iUmUFLqU
                                                                                                                                                                                                            MD5:A17723CE27EC99D1506C45AB1531085B
                                                                                                                                                                                                            SHA1:A83ED7BD09514A829CC8F2EA47BA113F5DCA1090
                                                                                                                                                                                                            SHA-256:560B39485CED4C2A0E85A66EB875331E5879104187D92CB7F05C2F635E34AC99
                                                                                                                                                                                                            SHA-512:110D1253D6915DB046247E4FD3BA9B881146BC3896DE779215E0CC6D1DCC59958C355441955509F5D38E3A3BA166DFD0F2F277000E9E89D6551FBEA0C16974B9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Grand_Turk) {.. {-9223372036854775808 -17072 0 LMT}.. {-2524504528 -18430 0 KMT}.. {-1827687170 -18000 0 EST}.. {284014800 -18000 0 EST}.. {294217200 -14400 1 EDT}.. {309938400 -18000 0 EST}.. {325666800 -14400 1 EDT}.. {341388000 -18000 0 EST}.. {357116400 -14400 1 EDT}.. {372837600 -18000 0 EST}.. {388566000 -14400 1 EDT}.. {404892000 -18000 0 EST}.. {420015600 -14400 1 EDT}.. {436341600 -18000 0 EST}.. {452070000 -14400 1 EDT}.. {467791200 -18000 0 EST}.. {483519600 -14400 1 EDT}.. {499240800 -18000 0 EST}.. {514969200 -14400 1 EDT}.. {530690400 -18000 0 EST}.. {544604400 -14400 1 EDT}.. {562140000 -18000 0 EST}.. {576054000 -14400 1 EDT}.. {594194400 -18000 0 EST}.. {607503600 -14400 1 EDT}.. {625644000 -18000 0 EST}.. {638953200 -14400 1 EDT}.. {657093600 -18000 0 EST}.. {671007600 -14400 1 EDT}.. {688543200 -18000 0 EST}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):201
                                                                                                                                                                                                            Entropy (8bit):4.892013473075135
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/2905Qb90ppv:MByMYbpwt290Ob90b
                                                                                                                                                                                                            MD5:4B9ABEA103F55509550F8B42D88E84B7
                                                                                                                                                                                                            SHA1:E3AA1BCE5E260264E74F77E59C4071B7E496AB41
                                                                                                                                                                                                            SHA-256:EBED070E8E67C5F12FF6E03FE508BE90789F17C793DFE61237B4045B8222580F
                                                                                                                                                                                                            SHA-512:568E375464FF264C5048CB35995945BDE1D5BCC3A108B2A4D0F8389EBF18B4C58EBB1C2122F10BA777D512504A59C7EFDF6069EABD2A5DEA3189204B7F7A6EB4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Grenada) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):204
                                                                                                                                                                                                            Entropy (8bit):4.9138787435596765
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/2905AJLr490ppv:MByMYbpwt290qJLr490b
                                                                                                                                                                                                            MD5:92B091A06198E233B73DF12DFCD818D5
                                                                                                                                                                                                            SHA1:C529488D09F86755E4F22CB4F0E3013C3A1B978D
                                                                                                                                                                                                            SHA-256:6CB1930532831D12057FCB484C60DB64A60A4F6D8195DAFD464826923116A294
                                                                                                                                                                                                            SHA-512:55EAE03CDECAC43BEDD3AA1A32C632A46808F29FF4D97A330F818544E4D10B9E9BA909D6627C38065EB7AC8E2C395FA37797F532CCFC8AB89D4698CCDE17F985
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Guadeloupe) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):399
                                                                                                                                                                                                            Entropy (8bit):4.513185345162455
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB862906GGmdHKznC972f/uF+mP/uF+K67Jqd3/uF+eBxE/uF+DAWNv:5neQCgfS+6S+K67Yd3S+e0S+1
                                                                                                                                                                                                            MD5:569CDE7CE1AB84C0F16A25E85A418334
                                                                                                                                                                                                            SHA1:EADE79AB6EDD98C7FE8B10B480C5C530CA014F5C
                                                                                                                                                                                                            SHA-256:14F6A98D602F3648C816B110F3A0BA375E1FFE8FA06BEEAB419DC1ABFA6EDCAF
                                                                                                                                                                                                            SHA-512:AE2ACBF09EED857906811BE2984D6BF92BF2955A9FE2F9F3FFEBB6790902F5C2C870F8561CA13AD9CB7826EECA434BED7CFE7D0D2739996BACEE506D0EB730DC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Guatemala) {.. {-9223372036854775808 -21724 0 LMT}.. {-1617040676 -21600 0 CST}.. {123055200 -18000 1 CDT}.. {130914000 -21600 0 CST}.. {422344800 -18000 1 CDT}.. {433054800 -21600 0 CST}.. {669708000 -18000 1 CDT}.. {684219600 -21600 0 CST}.. {1146376800 -18000 1 CDT}.. {1159678800 -21600 0 CST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):249
                                                                                                                                                                                                            Entropy (8bit):4.745656594295655
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2905xDm2OHHjGeoHv5laITicKpKV0EX/uFhfF/KVg:MB86290jmdHHLCv5FT/gOR/uFpF/Og
                                                                                                                                                                                                            MD5:DF661E312C6CE279CD6829120BE33CF2
                                                                                                                                                                                                            SHA1:4ACDB31E27EF9175C5452BF95F94F9BC280A237F
                                                                                                                                                                                                            SHA-256:6806AA5814BDC679C6EF653C518D2699114BE71D973F49C0864F622038DC2048
                                                                                                                                                                                                            SHA-512:04E7FD01F4DAD981EE8A02487F4A889015C41D07D6DCF420183D387E2188FF3239E345B5D65FB195CA485F5C7B4AD8CFEF51FFFC11EE0C91F0C88FF7B7EF17C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Guayaquil) {.. {-9223372036854775808 -19160 0 LMT}.. {-2524502440 -18840 0 QMT}.. {-1230749160 -18000 0 -05}.. {722926800 -14400 1 -05}.. {728884800 -18000 0 -05}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):248
                                                                                                                                                                                                            Entropy (8bit):4.673559445766137
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2905R3SDm2OHRLx5oH8ZOXFxSyZ1yV/KMMdVVFAKFZ4KVR/ON:MB86290LGmdHBnC8ZODhyV/4d/OeZ4Ke
                                                                                                                                                                                                            MD5:F06C226D8D53EF8859AD91D7EBA5959C
                                                                                                                                                                                                            SHA1:E0B4E6F4ADCB10F1D79FFD928E8684FFE0C0DC5F
                                                                                                                                                                                                            SHA-256:4078D2E361D04A66F22F652E3810CDF7F630CF89399B47E4EC7B1D32B400FD85
                                                                                                                                                                                                            SHA-512:B4385650A0C69B7BD66415CC4BB9FCA854DBB1427E9F2D6C1D8CDB8CCEF9ECBD699C66A83A9AC289DABC5CDBB0A2B044E4097E9A2977AE1802B3BF6E2BB518CF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Guyana) {.. {-9223372036854775808 -13959 0 LMT}.. {-1843589241 -14400 0 -04}.. {-1730577600 -13500 0 -0345}.. {176096700 -10800 0 -03}.. {701841600 -14400 0 -04}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):11124
                                                                                                                                                                                                            Entropy (8bit):3.8106487461849885
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:YpQamC9XD81iWQSufutTLBCN8RWnWQ7Z/xVpmtBwXiCDLxcGMe++wzlrfFj10Kvn:2kXCvNc/1/CC
                                                                                                                                                                                                            MD5:6FB9E47841FF397CE36A36C8280E2089
                                                                                                                                                                                                            SHA1:DA210300DC3D94FC3D8BA0A4531341BCA5C5936C
                                                                                                                                                                                                            SHA-256:01E11C7B07925D05E9E1876C310A2B87E0E80EF115D062225212E472B7A964F1
                                                                                                                                                                                                            SHA-512:F61B5A8A7532BBD54A4976DF17A1C6CF51BCC6DC396482FBE169C3081AF27B6CA863F0CDE3E483C59F5A5BD3365592F6984A97173C736B41D3CEEDAD4263A4E5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Halifax) {.. {-9223372036854775808 -15264 0 LMT}.. {-2131645536 -14400 0 AST}.. {-1696276800 -10800 1 ADT}.. {-1680469200 -14400 0 AST}.. {-1640980800 -14400 0 AST}.. {-1632074400 -10800 1 ADT}.. {-1615143600 -14400 0 AST}.. {-1609444800 -14400 0 AST}.. {-1566763200 -10800 1 ADT}.. {-1557090000 -14400 0 AST}.. {-1535486400 -10800 1 ADT}.. {-1524949200 -14400 0 AST}.. {-1504468800 -10800 1 ADT}.. {-1493413200 -14400 0 AST}.. {-1472414400 -10800 1 ADT}.. {-1461963600 -14400 0 AST}.. {-1440964800 -10800 1 ADT}.. {-1429390800 -14400 0 AST}.. {-1409515200 -10800 1 ADT}.. {-1396731600 -14400 0 AST}.. {-1376856000 -10800 1 ADT}.. {-1366491600 -14400 0 AST}.. {-1346616000 -10800 1 ADT}.. {-1333832400 -14400 0 AST}.. {-1313956800 -10800 1 ADT}.. {-1303678800 -14400 0 AST}.. {-1282507200 -10800 1 ADT}.. {-1272661200 -14400 0 AST}.. {-1251057600
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8729
                                                                                                                                                                                                            Entropy (8bit):3.8227313494100867
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:BEsWduCtQA/gF6Y3Umjm67yLb5RCzhV28I:BBWACb/gF6Y3UmjBy7
                                                                                                                                                                                                            MD5:564980AECB32F5778422EA15E8956879
                                                                                                                                                                                                            SHA1:545209C95043721C1839CCE5FEFD1A6F2DE3FE5F
                                                                                                                                                                                                            SHA-256:96B62BFBF0C05CF970245597C691F89EBF631175796459642A85287F131D0215
                                                                                                                                                                                                            SHA-512:25FE5DAA55E3466EAE1CDC73918F189403C3360D4E82D72D745FA04A374DE04F479AA9811D6154FC70CC8EA620F18035EA6A3074116806D4405936FA017CE8E6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Havana) {.. {-9223372036854775808 -19768 0 LMT}.. {-2524501832 -19776 0 HMT}.. {-1402813824 -18000 0 CST}.. {-1311534000 -14400 1 CDT}.. {-1300996800 -18000 0 CST}.. {-933534000 -14400 1 CDT}.. {-925675200 -18000 0 CST}.. {-902084400 -14400 1 CDT}.. {-893620800 -18000 0 CST}.. {-870030000 -14400 1 CDT}.. {-862171200 -18000 0 CST}.. {-775681200 -14400 1 CDT}.. {-767822400 -18000 0 CST}.. {-744231600 -14400 1 CDT}.. {-736372800 -18000 0 CST}.. {-144702000 -14400 1 CDT}.. {-134251200 -18000 0 CST}.. {-113425200 -14400 1 CDT}.. {-102542400 -18000 0 CST}.. {-86295600 -14400 1 CDT}.. {-72907200 -18000 0 CST}.. {-54154800 -14400 1 CDT}.. {-41457600 -18000 0 CST}.. {-21495600 -14400 1 CDT}.. {-5774400 -18000 0 CST}.. {9954000 -14400 1 CDT}.. {25675200 -18000 0 CST}.. {41403600 -14400 1 CDT}.. {57729600 -18000 0 CST}.. {73458000 -14400 1 CD
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):616
                                                                                                                                                                                                            Entropy (8bit):4.351214377567366
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB86290e2mdH5NCtXwl3UXmMMmxL+voudQCvX70qKOV9kYNv:5Ie5k9WUQwuz/Vyu
                                                                                                                                                                                                            MD5:E35A6C6E9DCF0CA34BFA2993CE445D6C
                                                                                                                                                                                                            SHA1:4FF9C7EDBC73B1AE0815661571B7199379AF479C
                                                                                                                                                                                                            SHA-256:C0A87DC3A474D25083F0CEA0C323D8E780D937453CAD23C98AF367D81AC2CA2D
                                                                                                                                                                                                            SHA-512:56A728ABCD3EA91D2492E1331B3F76F31EF5675BCD95A692F9D94F91518B72569FD8DF1BB0515668E8A9BE0347018B391C65761D316903CA27C59883BBE0DE80
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Hermosillo) {.. {-9223372036854775808 -26632 0 LMT}.. {-1514739600 -25200 0 MST}.. {-1343066400 -21600 0 CST}.. {-1234807200 -25200 0 MST}.. {-1220292000 -21600 1 MDT}.. {-1207159200 -25200 0 MST}.. {-1191344400 -21600 0 CST}.. {-873828000 -25200 0 MST}.. {-661539600 -28800 0 PST}.. {28800 -25200 0 MST}.. {828867600 -21600 1 MDT}.. {846403200 -25200 0 MST}.. {860317200 -21600 1 MDT}.. {877852800 -25200 0 MST}.. {891766800 -21600 1 MDT}.. {909302400 -25200 0 MST}.. {915174000 -25200 0 MST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7230
                                                                                                                                                                                                            Entropy (8bit):3.882344472808608
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:nys0KHK1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:nyBKHkN0HY2iUmUFLqU
                                                                                                                                                                                                            MD5:7824B3F2D20F16A9DCC8E0F7DC45C1B8
                                                                                                                                                                                                            SHA1:77014A0502DA1342EFA41B64C5613839B627354B
                                                                                                                                                                                                            SHA-256:4B114545167326F066AB3A798180896B43AC6FDC3B80D32BCC917B5A4A2359EB
                                                                                                                                                                                                            SHA-512:03F6A18C03E79E9177D16CD7AB75AC117197638370FA675BC2854A5A563021F865F3F0672B237B83098787AB9D419AC33D67F28324B1E25AD8560B5838F70807
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Indianapolis) {.. {-9223372036854775808 -20678 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-1577901600 -21600 0 CST}.. {-900259200 -18000 1 CDT}.. {-891795600 -21600 0 CST}.. {-883591200 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-757360800 -21600 0 CST}.. {-747244800 -18000 1 CDT}.. {-733942800 -21600 0 CST}.. {-715795200 -18000 1 CDT}.. {-702493200 -21600 0 CST}.. {-684345600 -18000 1 CDT}.. {-671043600 -21600 0 CST}.. {-652896000 -18000 1 CDT}.. {-639594000 -21600 0 CST}.. {-620841600 -18000 1 CDT}.. {-608144400 -21600 0 CST}.. {-589392000 -18000 1 CDT}.. {-576090000 -21600 0 CST}.. {-557942400 -18000 1 CDT}.. {-544640400 -21600 0 CST}.. {-526492800 -18000 1
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8755
                                                                                                                                                                                                            Entropy (8bit):3.8394539560522585
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:+q2KeNrdJ8SvAgahLi8hDlNA604qSScBgN+4ctDzIVQ/c/3hNxTh:+FKUdJ8SvPaUqbA604qSBgI7DBch
                                                                                                                                                                                                            MD5:8AF080A022DA0737E94742C50EAAC62E
                                                                                                                                                                                                            SHA1:704F0565B53AA8A20F70B79A7958D4D07085E07A
                                                                                                                                                                                                            SHA-256:F1253F5F3F5AACD1A5E1F4636DD4E083F4B2A8BD995CF3E684CDD384641849F1
                                                                                                                                                                                                            SHA-512:26AAF6D24B2E2B60451E19A514533DFAEC74F01F9B1AEB9F86690669C14130D77AE1CBFB9FC9091E1CD1FC1CBC2799BB05026DB68768C3CCB960355C18D111ED
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Knox) {.. {-9223372036854775808 -20790 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-725824800 -21600 0 CST}.. {-715795200 -18000 1 CDT}.. {-702493200 -21600 0 CST}.. {-684345600 -18000 1 CDT}.. {-671043600 -21600 0 CST}.. {-652896000 -18000 1 CDT}.. {-639594000 -21600 0 CST}.. {-620841600 -18000 1 CDT}.. {-608144400 -21600 0 CST}.. {-589392000 -18000 1 CDT}.. {-576090000 -21600 0 CST}.. {-557942400 -18000 1 CDT}.. {-544640400 -21600 0 CST}.. {-526492800 -18000 1 CDT}.. {-513190800 -21600 0 CST}.. {-495043200 -18000 1 CDT}.. {-481741200 -21600 0 CST}.. {-463593600 -18000 1 CDT}.. {-447267600 -21600 0 CST}.. {-431539200 -18000 1 CDT}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7273
                                                                                                                                                                                                            Entropy (8bit):3.8700915866109535
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:7qvrv7+X1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:7Kv7+bN0HY2iUmUFLqU
                                                                                                                                                                                                            MD5:C1A10440E6CCE4C5052E2510182D9AA7
                                                                                                                                                                                                            SHA1:56D4F3CCA1245D626BADA74CF3F6BAE8034BF58D
                                                                                                                                                                                                            SHA-256:675162381639598E7100E90663D42780F8EE1CB62BD6DA5B948B494F98C02FE3
                                                                                                                                                                                                            SHA-512:96B71472AD38ECFC589F935D9F5F1C8D42C8E942D8772FB6A77F9B9C0E2BD7A07FA61729E57EC02356121518E33797A784679F8DED2FCA3FC79F5C114783DD57
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Marengo) {.. {-9223372036854775808 -20723 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-599594400 -21600 0 CST}.. {-589392000 -18000 1 CDT}.. {-576090000 -21600 0 CST}.. {-495043200 -18000 1 CDT}.. {-481741200 -21600 0 CST}.. {-463593600 -18000 1 CDT}.. {-450291600 -21600 0 CST}.. {-431539200 -18000 1 CDT}.. {-418237200 -21600 0 CST}.. {-400089600 -18000 1 CDT}.. {-386787600 -21600 0 CST}.. {-368640000 -18000 1 CDT}.. {-355338000 -21600 0 CST}.. {-337190400 -18000 1 CDT}.. {-323888400 -21600 0 CST}.. {-305740800 -18000 1 CDT}.. {-292438800 -21600 0 CST}.. {-273686400 -18000 0 EST}.. {-31518000 -18000 0 EST}.. {-21488400 -14400 1 EDT}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7611
                                                                                                                                                                                                            Entropy (8bit):3.87971256165061
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:TqervJ8SUklggahyBRP0HY2iU7KKdFL6Aa2K4gSLf8e:TpvJ8SUklvaQN0HY2iUmUFLqU
                                                                                                                                                                                                            MD5:A86042668CD478AFFC05D3383EDEE8FF
                                                                                                                                                                                                            SHA1:6476526F94A247C0ECF3B2813F2C5A4FB93E457E
                                                                                                                                                                                                            SHA-256:23B8FA75CE0A9555DFD84549723A12679FF7FC5FAA58E4B745BA3C547071FF53
                                                                                                                                                                                                            SHA-512:07A5487A087108E6D6E88580865885CA6243EF04BE8263FC913F38CADB8EA016386E8BBAD39F65FD081F1A2F14316FEAF008855E9CF2019B169D9511916AFF67
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Petersburg) {.. {-9223372036854775808 -20947 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-473364000 -21600 0 CST}.. {-462996000 -18000 1 CDT}.. {-450291600 -21600 0 CST}.. {-431539200 -18000 1 CDT}.. {-418237200 -21600 0 CST}.. {-400089600 -18000 1 CDT}.. {-386787600 -21600 0 CST}.. {-368640000 -18000 1 CDT}.. {-355338000 -21600 0 CST}.. {-337190400 -18000 1 CDT}.. {-323888400 -21600 0 CST}.. {-305740800 -18000 1 CDT}.. {-292438800 -21600 0 CST}.. {-273686400 -18000 1 CDT}.. {-257965200 -21600 0 CST}.. {-242236800 -18000 1 CDT}.. {-226515600 -21600 0 CST}.. {-210787200 -18000 1 CDT}.. {-195066000 -21600 0 CST}.. {-179337600 -18000 1 CD
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7100
                                                                                                                                                                                                            Entropy (8bit):3.8613085681914607
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:yqxrvJ8SUklLgzNA604qSScBgN+4ctDzIVQ/c/3hNxTh:yUvJ8SUkl8BA604qSBgI7DBch
                                                                                                                                                                                                            MD5:E7FE9B7CFBC6505C446056967DEBC87B
                                                                                                                                                                                                            SHA1:81ADAD89F040F62E87D2F26D1D98B3E52710F695
                                                                                                                                                                                                            SHA-256:D368123DB703B55244700876906775837D408C274C5A5801D80B77EADB6D5853
                                                                                                                                                                                                            SHA-512:9C0746DE18C80B548AA443D59BB9971BDC304975717C5FCDEBDE72828ACF408FA1D687F87C42E7B8D6D0284C9F792EA236BF79C815947BE773D07364B630AC99
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Tell_City) {.. {-9223372036854775808 -20823 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-757360800 -21600 0 CST}.. {-462996000 -18000 1 CDT}.. {-450291600 -21600 0 CST}.. {-431539200 -18000 1 CDT}.. {-418237200 -21600 0 CST}.. {-400089600 -18000 1 CDT}.. {-386787600 -21600 0 CST}.. {-368640000 -18000 1 CDT}.. {-355338000 -21600 0 CST}.. {-337190400 -18000 1 CDT}.. {-323888400 -21600 0 CST}.. {-305740800 -18000 1 CDT}.. {-292438800 -21600 0 CST}.. {-273686400 -18000 1 CDT}.. {-257965200 -21600 0 CST}.. {-242236800 -18000 1 CDT}.. {-226515600 -21600 0 CST}.. {-210787200 -18000 1 CDT}.. {-195066000 -21600 0 CST}.. {-179337600 -18000 0 EST
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):6563
                                                                                                                                                                                                            Entropy (8bit):3.866646181493734
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:juqv01BRP0HY2iU7KKdFL6Aa2K4gSLf8e:CoKN0HY2iUmUFLqU
                                                                                                                                                                                                            MD5:2CCFC3980C321ED8A852759C0BCCB12C
                                                                                                                                                                                                            SHA1:A8BFE02E4E71B28EF8E284E808F6EDE7C231F8FF
                                                                                                                                                                                                            SHA-256:0623233AA39A1A82038A56DF255ADF49E648777375B8499491C8897EBEA1CDF1
                                                                                                                                                                                                            SHA-512:A4C77689BC9BF871C756D05BAC4157F0FD324D10AC7D15F3543344C6F8C7FC9218AB7ADFBCE70C8ECCDD6EC15FD7960503FC7A8223FECE6D4227BF0BB04190C7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Vevay) {.. {-9223372036854775808 -20416 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-495043200 -18000 0 EST}.. {-31518000 -18000 0 EST}.. {-21488400 -14400 1 EDT}.. {-5767200 -18000 0 EST}.. {9961200 -14400 1 EDT}.. {25682400 -18000 0 EST}.. {41410800 -14400 1 EDT}.. {57736800 -18000 0 EST}.. {73465200 -14400 1 EDT}.. {89186400 -18000 0 EST}.. {94712400 -18000 0 EST}.. {1136091600 -18000 0 EST}.. {1143961200 -14400 1 EDT}.. {1162101600 -18000 0 EST}.. {1173596400 -14400 1 EDT}.. {1194156000 -18000 0 EST}.. {1205046000 -14400 1 EDT}.. {1225605600 -18000 0 EST}.. {1236495600 -14400 1 EDT}.. {1257055200 -18000 0 EST}.. {1268550000 -144
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7226
                                                                                                                                                                                                            Entropy (8bit):3.879195938909716
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:Vq8rdJ5UklpRBRP0HY2iU7KKdFL6Aa2K4gSLf8e:VbdJ5Uklp/N0HY2iUmUFLqU
                                                                                                                                                                                                            MD5:56D1930F5FAE2456DEC6C9AB1B0233E1
                                                                                                                                                                                                            SHA1:F6ED52EF769DF2C015C181BCFF3DC0E24497C768
                                                                                                                                                                                                            SHA-256:B8452B6AA739A78AC6D03806463B03D4175639593E19FAA3CA4B0D0FB77F18C9
                                                                                                                                                                                                            SHA-512:AFCFF383DB441DA9154B639A88700D0604F487A20E830146B14061E485A991AD8DC279AF8C0C2329265CF14C901207B9058157FAA1C039082EB7630916834156
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Vincennes) {.. {-9223372036854775808 -21007 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-757360800 -21600 0 CST}.. {-747244800 -18000 1 CDT}.. {-733942800 -21600 0 CST}.. {-526492800 -18000 1 CDT}.. {-513190800 -21600 0 CST}.. {-495043200 -18000 1 CDT}.. {-481741200 -21600 0 CST}.. {-462996000 -18000 1 CDT}.. {-450291600 -21600 0 CST}.. {-431539200 -18000 1 CDT}.. {-418237200 -21600 0 CST}.. {-400089600 -18000 1 CDT}.. {-386787600 -21600 0 CST}.. {-368640000 -18000 1 CDT}.. {-355338000 -21600 0 CST}.. {-337190400 -18000 1 CDT}.. {-323888400 -21600 0 CST}.. {-305740800 -18000 1 CDT}.. {-289414800 -21600 0 CST}.. {-273686400 -18000 1 CDT
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7410
                                                                                                                                                                                                            Entropy (8bit):3.8775722319777968
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:uq0KeKrv7c1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:unKxv7yN0HY2iUmUFLqU
                                                                                                                                                                                                            MD5:880526DC23E7BDB00506D7EC2A885907
                                                                                                                                                                                                            SHA1:DB3B13A2A4BF80E7B71C7F0604A0A80EF070B9BA
                                                                                                                                                                                                            SHA-256:4B293FDB7680C4597B8C885333719214492ECF09BD5EA342D1EC15F2BF9C8605
                                                                                                                                                                                                            SHA-512:42EEDC5EA28781D62A457F4843F38D0A3FEFCAD83BA01B07CEF0FA169C6440960E04BABD272C5E9AF2F4B0DBB2A786EF9221A48F084F16752E6D0EA66C31911E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Indiana/Winamac) {.. {-9223372036854775808 -20785 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-757360800 -21600 0 CST}.. {-747244800 -18000 1 CDT}.. {-733942800 -21600 0 CST}.. {-715795200 -18000 1 CDT}.. {-702493200 -21600 0 CST}.. {-684345600 -18000 1 CDT}.. {-671043600 -21600 0 CST}.. {-652896000 -18000 1 CDT}.. {-639594000 -21600 0 CST}.. {-620841600 -18000 1 CDT}.. {-608144400 -21600 0 CST}.. {-589392000 -18000 1 CDT}.. {-576090000 -21600 0 CST}.. {-557942400 -18000 1 CDT}.. {-544640400 -21600 0 CST}.. {-526492800 -18000 1 CDT}.. {-513190800 -21600 0 CST}.. {-495043200 -18000 1 CDT}.. {-481741200 -21600 0 CST}.. {-463593600 -18000 1 CDT}.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):233
                                                                                                                                                                                                            Entropy (8bit):4.7047837427916095
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y73GK7JHAIgp3GKZRN/2903GfJ4903GK8:MByMY3GK7Kp3GKnt2903GfJ4903GK8
                                                                                                                                                                                                            MD5:DEE404D54FD707C4A27F464B5F19D135
                                                                                                                                                                                                            SHA1:AD95D04738F6B15A93DED1DE6B5FA9F47C8E38CB
                                                                                                                                                                                                            SHA-256:437DA148B94DBA4CEA402169878541DB9C3419ABAB6750D1C36625DD3053019E
                                                                                                                                                                                                            SHA-512:421D6AF30F0C64EA6CB9F9DC4E7EF9E8EE5945F81A5E82A6D959D32AD69F325770DB6A07D8F52EFE7EE7F6C3AD4E1F34AA30A6B5E006C928119A54E746D6FE6B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Indiana/Indianapolis)]} {.. LoadTimeZoneFile America/Indiana/Indianapolis..}..set TZData(:America/Indianapolis) $TZData(:America/Indiana/Indianapolis)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7638
                                                                                                                                                                                                            Entropy (8bit):3.8629745113156004
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:/nGaLV911sF7Lv/PCewtA8CzSPyDLbrcUia:/GPlLv/PCenJzS6cy
                                                                                                                                                                                                            MD5:DBF9C2CCF786A593C9D6E4F4BB37ACE9
                                                                                                                                                                                                            SHA1:4D2332A530A36E6DB2802DD9FA2DAF5C0594D5EA
                                                                                                                                                                                                            SHA-256:5A1F7F5EDAD0251B73C33E7B5DDEE194646E9D3992B169DC1A64D155765D472C
                                                                                                                                                                                                            SHA-512:70D75371497CED3B6C731C95299CDD5F8F49C3C6EEDDF31EB05D008769D76ACFE8BFA9A2ECE45BD0BA2E279BBEF65945955791EFC04A569F5CAA13665CD2545F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Inuvik) {.. {-9223372036854775808 0 0 -00}.. {-536457600 -28800 0 PST}.. {-147888000 -21600 1 PDDT}.. {-131558400 -28800 0 PST}.. {315558000 -25200 0 MST}.. {325674000 -21600 1 MDT}.. {341395200 -25200 0 MST}.. {357123600 -21600 1 MDT}.. {372844800 -25200 0 MST}.. {388573200 -21600 1 MDT}.. {404899200 -25200 0 MST}.. {420022800 -21600 1 MDT}.. {436348800 -25200 0 MST}.. {452077200 -21600 1 MDT}.. {467798400 -25200 0 MST}.. {483526800 -21600 1 MDT}.. {499248000 -25200 0 MST}.. {514976400 -21600 1 MDT}.. {530697600 -25200 0 MST}.. {544611600 -21600 1 MDT}.. {562147200 -25200 0 MST}.. {576061200 -21600 1 MDT}.. {594201600 -25200 0 MST}.. {607510800 -21600 1 MDT}.. {625651200 -25200 0 MST}.. {638960400 -21600 1 MDT}.. {657100800 -25200 0 MST}.. {671014800 -21600 1 MDT}.. {688550400 -25200 0 MST}.. {702464400 -21600 1 MDT}.. {7200000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7671
                                                                                                                                                                                                            Entropy (8bit):3.832645570123566
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:7FE5Ct/cQ1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:7FEct/N0HY2iUmUFLqU
                                                                                                                                                                                                            MD5:8020712BBA127EA8AB52E8F5DB14286E
                                                                                                                                                                                                            SHA1:DAEBC76FE10770D3FC2B5E1C14823B2B5543BA35
                                                                                                                                                                                                            SHA-256:AFC4627879F4A618F5E3BA9EA123F3212E161F4CCFD0DF46F3B6B7CD2E2C0D7E
                                                                                                                                                                                                            SHA-512:2F5C63F427A5DEDD5BF2B3867BE4C13774E9276C1472BF4170BCB2DA462B848CC8088743D032765133EE138388DF4217E4FC1475B12D2C8AF657A45ED6FEDE93
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Iqaluit) {.. {-9223372036854775808 0 0 -00}.. {-865296000 -14400 0 EWT}.. {-769395600 -14400 1 EPT}.. {-765396000 -18000 0 EST}.. {-147898800 -10800 1 EDDT}.. {-131569200 -18000 0 EST}.. {325666800 -14400 1 EDT}.. {341388000 -18000 0 EST}.. {357116400 -14400 1 EDT}.. {372837600 -18000 0 EST}.. {388566000 -14400 1 EDT}.. {404892000 -18000 0 EST}.. {420015600 -14400 1 EDT}.. {436341600 -18000 0 EST}.. {452070000 -14400 1 EDT}.. {467791200 -18000 0 EST}.. {483519600 -14400 1 EDT}.. {499240800 -18000 0 EST}.. {514969200 -14400 1 EDT}.. {530690400 -18000 0 EST}.. {544604400 -14400 1 EDT}.. {562140000 -18000 0 EST}.. {576054000 -14400 1 EDT}.. {594194400 -18000 0 EST}.. {607503600 -14400 1 EDT}.. {625644000 -18000 0 EST}.. {638953200 -14400 1 EDT}.. {657093600 -18000 0 EST}.. {671007600 -14400 1 EDT}.. {688543200 -18000 0 EST}.. {7024
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):847
                                                                                                                                                                                                            Entropy (8bit):4.206296468996689
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5seRvZGjFS/uk1p/uue/udYR/u+zN5hi/uW9/uoUF0/u8Bb/u33RU/uMZ8/unuR3:5jUjFo1pFGzfAYFqB43RMER3
                                                                                                                                                                                                            MD5:95B59E3EA2A270A34BDF98AA899203C8
                                                                                                                                                                                                            SHA1:93599597797F4BAFE5C75179FB795058B1E3527D
                                                                                                                                                                                                            SHA-256:4B9D5177CBA057CD53D53120A49B8A47ECCB00150018581A84851E9D5437D643
                                                                                                                                                                                                            SHA-512:032BC07F9E92B756A0732AECC2DFEC4C89A58B3D6D3CA57A0F99F2AD1D51676804C7B6CE50EB3B37BB8A1EF382168AC83989D609D37C57308E29B51F1FDEFB1E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Jamaica) {.. {-9223372036854775808 -18430 0 LMT}.. {-2524503170 -18430 0 KMT}.. {-1827687170 -18000 0 EST}.. {126248400 -18000 0 EST}.. {126687600 -14400 1 EDT}.. {152085600 -18000 0 EST}.. {162370800 -14400 1 EDT}.. {183535200 -18000 0 EST}.. {199263600 -14400 1 EDT}.. {215589600 -18000 0 EST}.. {230713200 -14400 1 EDT}.. {247039200 -18000 0 EST}.. {262767600 -14400 1 EDT}.. {278488800 -18000 0 EST}.. {294217200 -14400 1 EDT}.. {309938400 -18000 0 EST}.. {325666800 -14400 1 EDT}.. {341388000 -18000 0 EST}.. {357116400 -14400 1 EDT}.. {372837600 -18000 0 EST}.. {388566000 -14400 1 EDT}.. {404892000 -18000 0 EST}.. {420015600 -14400 1 EDT}.. {436341600 -18000 0 EST}.. {441781200 -18000 0 EST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):211
                                                                                                                                                                                                            Entropy (8bit):4.94277888588308
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7/MI6HAIgp/MIwRN/290pPGe90/MIz:MByMY/Myp/M9Rt290h390/M4
                                                                                                                                                                                                            MD5:E020D4F9CB1AF91D373CD9F3C2247428
                                                                                                                                                                                                            SHA1:0ADF2E9F8D9F8641E066764BA1BAF068F0332CE9
                                                                                                                                                                                                            SHA-256:4A0495852CD4D0652B82FB57024645916DB8F192EEF9A82AFD580D87F4D496ED
                                                                                                                                                                                                            SHA-512:03190F0E7EC35A358670B1617CB5C17EA3DD41195B2C4B748479D80ABAB4DB395293F688D94B87662D0469F6C5885CF7E7C9A995493A191905753F740DF659E1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Argentina/Jujuy)]} {.. LoadTimeZoneFile America/Argentina/Jujuy..}..set TZData(:America/Jujuy) $TZData(:America/Argentina/Jujuy)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8682
                                                                                                                                                                                                            Entropy (8bit):3.9620285142779728
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:/fCG0rHPC9+j1giaJCUbtp0nFI+g/iexpCVaBnNnt61nctE1:/aG0rq9DiaJCUbPI+D/iMpCIBSuk
                                                                                                                                                                                                            MD5:8160A0D27EECEF40F6F34A06D5D02BE6
                                                                                                                                                                                                            SHA1:7CAA64F83BAA0C23EE05A72BB1079AA552FA2F3D
                                                                                                                                                                                                            SHA-256:5FBE6A1FA2D3DFE23C7378E425F32BEBCA44735DA25EA075A7E5CE24BFD4049D
                                                                                                                                                                                                            SHA-512:59B8D04595007B45E582E6D17734999074CA67A93F5DF742EFE1EB78DB8ABD359D4C3B213B678C6A46040A13AAB709A994B6A532D720D3EF6FCA2730ABF4885E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Juneau) {.. {-9223372036854775808 54139 0 LMT}.. {-3225223727 -32261 0 LMT}.. {-2188954939 -28800 0 PST}.. {-883584000 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-757353600 -28800 0 PST}.. {-31507200 -28800 0 PST}.. {-21477600 -25200 1 PDT}.. {-5756400 -28800 0 PST}.. {9972000 -25200 1 PDT}.. {25693200 -28800 0 PST}.. {41421600 -25200 1 PDT}.. {57747600 -28800 0 PST}.. {73476000 -25200 1 PDT}.. {89197200 -28800 0 PST}.. {104925600 -25200 1 PDT}.. {120646800 -28800 0 PST}.. {126698400 -25200 1 PDT}.. {152096400 -28800 0 PST}.. {162381600 -25200 1 PDT}.. {183546000 -28800 0 PST}.. {199274400 -25200 1 PDT}.. {215600400 -28800 0 PST}.. {230724000 -25200 1 PDT}.. {247050000 -28800 0 PST}.. {262778400 -25200 1 PDT}.. {278499600 -28800 0 PST}.. {294228000 -25200 1 PDT}.. {309949
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):9553
                                                                                                                                                                                                            Entropy (8bit):3.853353361425414
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:tfTwKdrdJ9+StCt/cL1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:tfUKNdJ9+SItON0HY2iUmUFLqU
                                                                                                                                                                                                            MD5:D721B38F1FFF1A6F5C02B72ECC06CDE5
                                                                                                                                                                                                            SHA1:E70D99A9FC1DA9F30389129EE00FE20FA79D66A8
                                                                                                                                                                                                            SHA-256:9EB1F2B19C44A55D6CC9FD1465BAF6535856941C067831E4B5E0494665014BF5
                                                                                                                                                                                                            SHA-512:3C82A8C27026228F359FD96A4306F1BC337DE655FD1BA02C4399162E44DE59AD58CE569DA5AEA36E586C3BDEE7256420AABB84B44D277E244FE5AD771B4BE307
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Kentucky/Louisville) {.. {-9223372036854775808 -20582 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-1546279200 -21600 0 CST}.. {-1535904000 -18000 1 CDT}.. {-1525280400 -21600 0 CST}.. {-905097600 -18000 1 CDT}.. {-891795600 -21600 0 CST}.. {-883591200 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-757360800 -21600 0 CST}.. {-747251940 -18000 1 CDT}.. {-744224400 -21600 0 CST}.. {-620841600 -18000 1 CDT}.. {-608144400 -21600 0 CST}.. {-589392000 -18000 1 CDT}.. {-576090000 -21600 0 CST}.. {-557942400 -18000 1 CDT}.. {-544640400 -21600 0 CST}.. {-526492800 -18000 1 CDT}.. {-513190800 -21600 0 CST}.. {-495043200 -18000 1 CDT}.. {-481741200 -21600 0 CST}.. {-463593600 -18000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8558
                                                                                                                                                                                                            Entropy (8bit):3.869494272122571
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:4F8qMahLi8hR1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:4F8HaUqJN0HY2iUmUFLqU
                                                                                                                                                                                                            MD5:AED6497590DA305D16AC034979C8B1E9
                                                                                                                                                                                                            SHA1:AD6F1788310A3A5A761873FEF1A32416B7DBCA89
                                                                                                                                                                                                            SHA-256:1C6C7FB0AE628EB6BB305B51859C4E5594A6B0876C386ED9C1C3355E7CB37AE1
                                                                                                                                                                                                            SHA-512:58D960AB5F2D9F8E4DD0171E5E36CE2E072F74A7AFDBC43F9340BBCF0CDC0D060AC895F9FCF551F4CC7EB6DBF2E9835C8C3D58E87CA4FBC98C720F51C462EDCD
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Kentucky/Monticello) {.. {-9223372036854775808 -20364 0 LMT}.. {-2717647200 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-757360800 -21600 0 CST}.. {-63136800 -21600 0 CST}.. {-52934400 -18000 1 CDT}.. {-37213200 -21600 0 CST}.. {-21484800 -18000 1 CDT}.. {-5763600 -21600 0 CST}.. {9964800 -18000 1 CDT}.. {25686000 -21600 0 CST}.. {41414400 -18000 1 CDT}.. {57740400 -21600 0 CST}.. {73468800 -18000 1 CDT}.. {89190000 -21600 0 CST}.. {104918400 -18000 1 CDT}.. {120639600 -21600 0 CST}.. {126691200 -18000 1 CDT}.. {152089200 -21600 0 CST}.. {162374400 -18000 1 CDT}.. {183538800 -21600 0 CST}.. {199267200 -18000 1 CDT}.. {215593200 -21600 0 CST}.. {230716800 -18000
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):204
                                                                                                                                                                                                            Entropy (8bit):4.8670778268802195
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y73GKaHAIgp3GKIN/2901iZ903GKT:MByMY3GKDp3GKIt290Q903GKT
                                                                                                                                                                                                            MD5:50434016470AC512A8E2BEBA0BCEBC15
                                                                                                                                                                                                            SHA1:F3541F6EE201FA33C66042F5C11A26434D37D42C
                                                                                                                                                                                                            SHA-256:D66E77E6FF789D4D6CA13CDB204B977E1FE64BE9AFEE7B41F2C17ED8217FD025
                                                                                                                                                                                                            SHA-512:EB1FF97050B7E067DCB68FF7C8F912C8A0C02144BB8E2EAA58C1136C6CC4A2B98C897DD23BB1E9C82D9AF6D028EE45227F97676CB34B6B830CDF5D707B990E57
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Indiana/Knox)]} {.. LoadTimeZoneFile America/Indiana/Knox..}..set TZData(:America/Knox_IN) $TZData(:America/Indiana/Knox)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):204
                                                                                                                                                                                                            Entropy (8bit):4.9362668992592456
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/2901Qv090ppv:MByMYbpwt290ev090b
                                                                                                                                                                                                            MD5:FE9CEC6C50DF451B599B98AE8A434FF7
                                                                                                                                                                                                            SHA1:60F997825766662B2C5415FBE4D65CEA6D326537
                                                                                                                                                                                                            SHA-256:5AF9B28C48661FDC81762D249B716BA077F0A40ECF431D34A893BB7EABA57965
                                                                                                                                                                                                            SHA-512:1311605021871BAFAF321AA48B352262C6BA42149101CCD4FDD4000435B2584AC564E0F76D481BB181767C010FD922BAA4E4EBB401AC2FF27B21874D89332872
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Kralendijk) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):218
                                                                                                                                                                                                            Entropy (8bit):4.902526230255025
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/290WDm2OHphvoHvKZdcyFXmBVVON:MB86290ymdHphvCvKfcyy/ON
                                                                                                                                                                                                            MD5:3BC04900A19D0152A31B353C6715A97B
                                                                                                                                                                                                            SHA1:58A6D49E0B6FA00CBEAFD695D604D740AD63C54E
                                                                                                                                                                                                            SHA-256:5488D98AA3C29D710C6AF92C42ACE36550A5BFF78C155CDF8769EE31F71CF033
                                                                                                                                                                                                            SHA-512:65302935090F98A81443A1E1158911F57C3A1564564CD401CA72DDBF66D967DB564EF5AE8A4083D83984B9EF55AB53159010EFE2DB5D7A723F7EA61A1795322D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/La_Paz) {.. {-9223372036854775808 -16356 0 LMT}.. {-2524505244 -16356 0 CMT}.. {-1205954844 -12756 1 BST}.. {-1192307244 -14400 0 -04}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):460
                                                                                                                                                                                                            Entropy (8bit):4.2444415392593875
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB86290B2mdH4VCvvCOt/Os/OCQXR/uFfC3/O3e/uFbs/OX/OqF/O+8/OOS1F5/D:59etvqOVLOR/uGD/utsg38xSP5r
                                                                                                                                                                                                            MD5:5F41E848D2DDE91261F45CB577B1B0A9
                                                                                                                                                                                                            SHA1:DF284499CF57479ADE5E1D3DC01D6DCCF6AFDFE1
                                                                                                                                                                                                            SHA-256:6E01002F264DF9A6FC247F95399F4F42DCCC7AB890B0C259DE93DCC97DEC89CE
                                                                                                                                                                                                            SHA-512:2F5472F812734E892182632B8A34A4AD7B342541D0C3F1107BD95FFBE25D9351A0CDF5F58F35A1F37365DDF8A8A5D883C89C3CC40A9AD09D54CA152DC6BE1A09
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Lima) {.. {-9223372036854775808 -18492 0 LMT}.. {-2524503108 -18516 0 LMT}.. {-1938538284 -14400 0 -05}.. {-1002052800 -18000 0 -05}.. {-986756400 -14400 1 -05}.. {-971035200 -18000 0 -05}.. {-955306800 -14400 1 -05}.. {-939585600 -18000 0 -05}.. {512712000 -18000 0 -05}.. {544248000 -18000 0 -05}.. {638942400 -18000 0 -05}.. {765172800 -18000 0 -05}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):9726
                                                                                                                                                                                                            Entropy (8bit):3.8515163794355916
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:/uX68CWSgG0U9bFzN6IkWq/WHQt/RY4yP:/uX68CWSgGVbGBt/M
                                                                                                                                                                                                            MD5:4D4F198238E4E76753411896239041C3
                                                                                                                                                                                                            SHA1:AD41D199DF0B794B5AB7F165C8A141787FAAC9A9
                                                                                                                                                                                                            SHA-256:DA3F7572F04E6AE78B8F044761E6F48D37EE259A9C1FE15A67072CC64A299FDB
                                                                                                                                                                                                            SHA-512:BA39D174B73B1D4B09E8AC07291BED0B9658A4330AE50881080F0E37C35BD8A6F55C49F1D649ED1F19CE47002435D8724048759DFC813BF9C2E9B06B581486FF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Los_Angeles) {.. {-9223372036854775808 -28378 0 LMT}.. {-2717640000 -28800 0 PST}.. {-1633269600 -25200 1 PDT}.. {-1615129200 -28800 0 PST}.. {-1601820000 -25200 1 PDT}.. {-1583679600 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-757353600 -28800 0 PST}.. {-687967140 -25200 1 PDT}.. {-662655600 -28800 0 PST}.. {-620838000 -25200 1 PDT}.. {-608137200 -28800 0 PST}.. {-589388400 -25200 1 PDT}.. {-576082800 -28800 0 PST}.. {-557938800 -25200 1 PDT}.. {-544633200 -28800 0 PST}.. {-526489200 -25200 1 PDT}.. {-513183600 -28800 0 PST}.. {-495039600 -25200 1 PDT}.. {-481734000 -28800 0 PST}.. {-463590000 -25200 1 PDT}.. {-450284400 -28800 0 PST}.. {-431535600 -25200 1 PDT}.. {-418230000 -28800 0 PST}.. {-400086000 -25200 1 PDT}.. {-386780400 -28800 0 PST}.. {-368636400 -25200 1 PDT}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):228
                                                                                                                                                                                                            Entropy (8bit):4.911677030377383
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y71PiKp4o2HAIgp1PiKp4BvN/290hp4901PiKp44v:MByMYPyApPydt290P490Pyi
                                                                                                                                                                                                            MD5:ACE87B25FE5604C83127A9F148A34C8C
                                                                                                                                                                                                            SHA1:25C8D85B4740C53F40421D0DADCA95225EAB7829
                                                                                                                                                                                                            SHA-256:F85C1253F4C1D3E85757D3DEA4FD3C61F1AA7BE6BAAE8CB8579278412905ACB2
                                                                                                                                                                                                            SHA-512:AC0662B19F336474B146E06778E1FB43B941ABC8FD51BDB31B2640C94CCDFBE7659960EF4FD18329AFA7AD11316FC08D3CF33BB27931EA70AA7218667A8D0737
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Kentucky/Louisville)]} {.. LoadTimeZoneFile America/Kentucky/Louisville..}..set TZData(:America/Louisville) $TZData(:America/Kentucky/Louisville)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):207
                                                                                                                                                                                                            Entropy (8bit):4.900350318979456
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290h48h490ppv:MByMYbpwt290/490b
                                                                                                                                                                                                            MD5:83CE86174ADB5F276AABD26FE132BB55
                                                                                                                                                                                                            SHA1:925E3F4A5DB1A2C33B3A537C8DBC9CFE309FA340
                                                                                                                                                                                                            SHA-256:1E786229B84CE86DB6316B24C85F7CF4CFE66011F973053AD0E108BFCC9A9DE2
                                                                                                                                                                                                            SHA-512:BA2AC5571D772B577735BC8E43FF8023228BC61A974DCCE0EAE20EC9B11FC757E56CABDAE00933A99834108114E598B7EC149BB017EB80BE18301A655F341A36
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Lower_Princes) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1539
                                                                                                                                                                                                            Entropy (8bit):3.7453889877550512
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5QChlvEw6kSSx5H4a8tf3fkuoLdNYVZDNR8nd:OIlvEwJSSxdF8tfMuoLdNYVZJR8nd
                                                                                                                                                                                                            MD5:EB0EDF4E075E3CF9F8EDF2B689C2FE54
                                                                                                                                                                                                            SHA1:9713D7E8AA0E7164824657D00DE6C49483D2BD19
                                                                                                                                                                                                            SHA-256:F65C5957D434A87324AAD35991E7666E426A20C40432540D9A3CB1EEE9141761
                                                                                                                                                                                                            SHA-512:0A0D1E4E0BD7D854E8F139E6F7A9BBC66422B73F7A6C2E1F1B6D2CA400B24B3D220AB519B6AEAA743443E9A4B748709CDF2C276BF52C5382669B12734A469125
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Maceio) {.. {-9223372036854775808 -8572 0 LMT}.. {-1767217028 -10800 0 -03}.. {-1206957600 -7200 1 -03}.. {-1191362400 -10800 0 -03}.. {-1175374800 -7200 1 -03}.. {-1159826400 -10800 0 -03}.. {-633819600 -7200 1 -03}.. {-622069200 -10800 0 -03}.. {-602283600 -7200 1 -03}.. {-591832800 -10800 0 -03}.. {-570747600 -7200 1 -03}.. {-560210400 -10800 0 -03}.. {-539125200 -7200 1 -03}.. {-531352800 -10800 0 -03}.. {-191365200 -7200 1 -03}.. {-184197600 -10800 0 -03}.. {-155163600 -7200 1 -03}.. {-150069600 -10800 0 -03}.. {-128898000 -7200 1 -03}.. {-121125600 -10800 0 -03}.. {-99954000 -7200 1 -03}.. {-89589600 -10800 0 -03}.. {-68418000 -7200 1 -03}.. {-57967200 -10800 0 -03}.. {499748400 -7200 1 -03}.. {511236000 -10800 0 -03}.. {530593200 -7200 1 -03}.. {540266400 -10800 0 -03}.. {562129200 -7200 1 -03}.. {571197600 -10800 0 -03}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):611
                                                                                                                                                                                                            Entropy (8bit):4.303621439025158
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB86290znTjmdHOYCvprv5EU/dLAyW+/uF+kX8/uF+RZ//dAWcP/QAWcx/uF+rbE:5GnPeOdvhxD1pLS+S8S+RVqzo4xS+3SJ
                                                                                                                                                                                                            MD5:FB09D1F064C30F9E223FA119A8875098
                                                                                                                                                                                                            SHA1:C66173FEB21761AEA649301D77FBB77ACF3A6FB1
                                                                                                                                                                                                            SHA-256:F0F0CCE8DE92D848A62B56EF48E01D763B80153C077230C435D464CF1733BA38
                                                                                                                                                                                                            SHA-512:BC3D841FF48FD0DE7C9ABF5DAE3A42C876BD4D7FBD6684B4513EC7ECC92D938A7133BCC873AD46E453DD1863E843E5C7DD14FFDB41B593E90BEB5CD8F7E66202
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Managua) {.. {-9223372036854775808 -20708 0 LMT}.. {-2524500892 -20712 0 MMT}.. {-1121105688 -21600 0 CST}.. {105084000 -18000 0 EST}.. {161758800 -21600 0 CST}.. {290584800 -18000 1 CDT}.. {299134800 -21600 0 CST}.. {322034400 -18000 1 CDT}.. {330584400 -21600 0 CST}.. {694260000 -18000 0 EST}.. {717310800 -21600 0 CST}.. {725868000 -18000 0 EST}.. {852094800 -21600 0 CST}.. {1113112800 -18000 1 CDT}.. {1128229200 -21600 0 CST}.. {1146384000 -18000 1 CDT}.. {1159682400 -21600 0 CST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1166
                                                                                                                                                                                                            Entropy (8bit):3.7842934576858482
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5GnqeKwnSRs//SFs/pS9/MHSW/WOSr/nSso/TSL/SSU/iS5X/LcSi/xScd/ZlSQz:5mSeSFESoSQSrSsCSeSPS1cSQSQlSsSQ
                                                                                                                                                                                                            MD5:E42719A9B0165490BB9E0E899EFB3643
                                                                                                                                                                                                            SHA1:2991D7EC31F47E32D2C8DB89A0F87D814122DD1B
                                                                                                                                                                                                            SHA-256:DC54E6D4FE14458B0462FA0E15B960FD4290930ADC0D13453BF49B436ED8C143
                                                                                                                                                                                                            SHA-512:F75024E27A2D679A667EA70EC948F983C7B823FDA5962DD88697D61147A6C2B1499E58BA8B01170653C4D025900491AE8E21925500DE39EACBAF883F7E62D874
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Manaus) {.. {-9223372036854775808 -14404 0 LMT}.. {-1767211196 -14400 0 -04}.. {-1206954000 -10800 1 -04}.. {-1191358800 -14400 0 -04}.. {-1175371200 -10800 1 -04}.. {-1159822800 -14400 0 -04}.. {-633816000 -10800 1 -04}.. {-622065600 -14400 0 -04}.. {-602280000 -10800 1 -04}.. {-591829200 -14400 0 -04}.. {-570744000 -10800 1 -04}.. {-560206800 -14400 0 -04}.. {-539121600 -10800 1 -04}.. {-531349200 -14400 0 -04}.. {-191361600 -10800 1 -04}.. {-184194000 -14400 0 -04}.. {-155160000 -10800 1 -04}.. {-150066000 -14400 0 -04}.. {-128894400 -10800 1 -04}.. {-121122000 -14400 0 -04}.. {-99950400 -10800 1 -04}.. {-89586000 -14400 0 -04}.. {-68414400 -10800 1 -04}.. {-57963600 -14400 0 -04}.. {499752000 -10800 1 -04}.. {511239600 -14400 0 -04}.. {530596800 -10800 1 -04}.. {540270000 -14400 0 -04}.. {562132800 -10800 1 -04}.. {571201200 -1
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):201
                                                                                                                                                                                                            Entropy (8bit):4.900738604616686
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290zzJ/90ppv:MByMYbpwt290zzN90b
                                                                                                                                                                                                            MD5:8C60DE8E522FE5D51EACD643FD8EA132
                                                                                                                                                                                                            SHA1:2E09A71DF340ECA6F7AEBD978070D56A627049EC
                                                                                                                                                                                                            SHA-256:5C26D7CE93F91CC4F5ED87E9388B1B180EF9D84681044FD23CC01A628A1284CA
                                                                                                                                                                                                            SHA-512:D2D522D041AFA638542F6FF00F5F40325E3F117C5035BA71F676B4956B054542C67A753055D17E2E2EEA925F13EACC0969D01EC18E40D274D8EA408F92777EA2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Marigot) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):251
                                                                                                                                                                                                            Entropy (8bit):4.849143012086458
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/290zlEDm2OHfueoHv9dMIqR5lRfT/VVFUFkmR/lAov:MB86290zimdHfnCv9dMIqR5lVb/uFkmD
                                                                                                                                                                                                            MD5:CFE10EE56115D3A5F44E047B3661D8ED
                                                                                                                                                                                                            SHA1:03F598CFC9AEDE2F588339B439B2361F2EBDE34F
                                                                                                                                                                                                            SHA-256:D411FB42798E93B106275EC0E054F8F3C4E9FB49431C656448739C7F20C46EDE
                                                                                                                                                                                                            SHA-512:25D6760FDF2F1B0DD91A41D29BDB7048FAE27A03F7B9D9C955ECF4C32E8402836D007B39FE62B93E7BEA017681A0C8AFC1C4CAFD823B0A6C41EDAF09DDF3435D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Martinique) {.. {-9223372036854775808 -14660 0 LMT}.. {-2524506940 -14660 0 FFMT}.. {-1851537340 -14400 0 AST}.. {323841600 -10800 1 ADT}.. {338958000 -14400 0 AST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):6745
                                                                                                                                                                                                            Entropy (8bit):3.8432520851585372
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:aD5NA604qSScBgN+4ctDzIVQ/c/3hNxTh:aDbA604qSBgI7DBch
                                                                                                                                                                                                            MD5:FC4A24AE95BA6E36285F09AB2FCEE56F
                                                                                                                                                                                                            SHA1:54ED1CD69247064B5EC775E907790D19E93A4626
                                                                                                                                                                                                            SHA-256:59C658CEA1BF5392A8F16295A09A74230EFB52EF7BF783E493E9A9C1799036F2
                                                                                                                                                                                                            SHA-512:2E8E65C487090DC8EE90F8575360A00E74C134CE34E83D4296E2CC32B773F9F0151F4049BFD1BEEAFE7B441E8684AF9FB50287E42FBD5182E4051D1FC39932E3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Matamoros) {.. {-9223372036854775808 -23400 0 LMT}.. {-1514743200 -21600 0 CST}.. {568015200 -21600 0 CST}.. {576057600 -18000 1 CDT}.. {594198000 -21600 0 CST}.. {599637600 -21600 0 CST}.. {828864000 -18000 1 CDT}.. {846399600 -21600 0 CST}.. {860313600 -18000 1 CDT}.. {877849200 -21600 0 CST}.. {891763200 -18000 1 CDT}.. {909298800 -21600 0 CST}.. {923212800 -18000 1 CDT}.. {941353200 -21600 0 CST}.. {954662400 -18000 1 CDT}.. {972802800 -21600 0 CST}.. {989136000 -18000 1 CDT}.. {1001833200 -21600 0 CST}.. {1018166400 -18000 1 CDT}.. {1035702000 -21600 0 CST}.. {1049616000 -18000 1 CDT}.. {1067151600 -21600 0 CST}.. {1081065600 -18000 1 CDT}.. {1099206000 -21600 0 CST}.. {1112515200 -18000 1 CDT}.. {1130655600 -21600 0 CST}.. {1143964800 -18000 1 CDT}.. {1162105200 -21600 0 CST}.. {1175414400 -18000 1 CDT}.. {1193554800 -21600 0
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2067
                                                                                                                                                                                                            Entropy (8bit):3.990817847620547
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5GtXed9WUQwuz/V/NF01YmM/parZ375+XiB+:5sNUIdFS1YrpaV5+yB+
                                                                                                                                                                                                            MD5:43467194416FCF6F0D67AD2456D78646
                                                                                                                                                                                                            SHA1:1FDF02EF7354D9DB71F545D32AE52D018E99D801
                                                                                                                                                                                                            SHA-256:8140084EA9D6A478C34A114D9E216DC05450ECBE4809B2CDA194B40452E2AA0F
                                                                                                                                                                                                            SHA-512:EB5CD3E95779391F096EE9A7B16920C6C9E8A90F38C7A3CBE2B0E123D088A127C5BBE21F5883DCDAD4FBB2410ED052EDE3D4F1E260483D97FEBB7BA7022874C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Mazatlan) {.. {-9223372036854775808 -25540 0 LMT}.. {-1514739600 -25200 0 MST}.. {-1343066400 -21600 0 CST}.. {-1234807200 -25200 0 MST}.. {-1220292000 -21600 1 MDT}.. {-1207159200 -25200 0 MST}.. {-1191344400 -21600 0 CST}.. {-873828000 -25200 0 MST}.. {-661539600 -28800 0 PST}.. {28800 -25200 0 MST}.. {828867600 -21600 1 MDT}.. {846403200 -25200 0 MST}.. {860317200 -21600 1 MDT}.. {877852800 -25200 0 MST}.. {891766800 -21600 1 MDT}.. {909302400 -25200 0 MST}.. {923216400 -21600 1 MDT}.. {941356800 -25200 0 MST}.. {954666000 -21600 1 MDT}.. {972806400 -25200 0 MST}.. {989139600 -21600 1 MDT}.. {1001836800 -25200 0 MST}.. {1018170000 -21600 1 MDT}.. {1035705600 -25200 0 MST}.. {1049619600 -21600 1 MDT}.. {1067155200 -25200 0 MST}.. {1081069200 -21600 1 MDT}.. {1099209600 -25200 0 MST}.. {1112518800 -21600 1 MDT}.. {1130659200 -2520
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):219
                                                                                                                                                                                                            Entropy (8bit):4.812188311941308
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7/MeHAIgp/MSvYovN/290zpH+90/MX:MByMY/M/p/MSA6t290zpe90/MX
                                                                                                                                                                                                            MD5:2A3BFEEFBB684FB3B420A6B53B588BDC
                                                                                                                                                                                                            SHA1:CC5C0BB90D847CCBB45688A8DA460AD575D64617
                                                                                                                                                                                                            SHA-256:D6B308A1619F2DE450DACBFEF0E11B237DF7375A80C90899DD02B827688CB4B8
                                                                                                                                                                                                            SHA-512:4A35C80D3454E039383FFEB06DC84933B3201BE2487C42A448AF3DA5ABAEEB9882263C011CDD3194E121EC1C31FC80120BF7829F280A79996E376CFA828EE215
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Argentina/Mendoza)]} {.. LoadTimeZoneFile America/Argentina/Mendoza..}..set TZData(:America/Mendoza) $TZData(:America/Argentina/Mendoza)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8410
                                                                                                                                                                                                            Entropy (8bit):3.8311875423131534
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:6quShLi8hbZlNA604qSScBgN+4ctDzIVQ/c/3hNxTh:6lSUqtfA604qSBgI7DBch
                                                                                                                                                                                                            MD5:C74D31382279219F805D2B138C58FBF7
                                                                                                                                                                                                            SHA1:06E2FED0A3BDF62F3D390A4054B6A2D7C1863DD3
                                                                                                                                                                                                            SHA-256:B0863F8B66F0848020651B69E7997307D62209259AE653FDC1A0FAFC8E793068
                                                                                                                                                                                                            SHA-512:7B42CBDC119651E2B2EE8B8F934801D3147A8B72EE060A0D0EA1C0C12CA9ABD03F1A102A85BF8E7424B45620151CE107D16A9173F4AA7597EDB3109840C1B2AE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Menominee) {.. {-9223372036854775808 -21027 0 LMT}.. {-2659759773 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-757360800 -21600 0 CST}.. {-747244800 -18000 1 CDT}.. {-733942800 -21600 0 CST}.. {-116438400 -18000 1 CDT}.. {-100112400 -21600 0 CST}.. {-21484800 -18000 0 EST}.. {104914800 -21600 0 CST}.. {104918400 -18000 1 CDT}.. {120639600 -21600 0 CST}.. {126691200 -18000 1 CDT}.. {152089200 -21600 0 CST}.. {162374400 -18000 1 CDT}.. {183538800 -21600 0 CST}.. {199267200 -18000 1 CDT}.. {215593200 -21600 0 CST}.. {230716800 -18000 1 CDT}.. {247042800 -21600 0 CST}.. {262771200 -18000 1 CDT}.. {278492400 -21600 0 CST}.. {294220800 -18000 1 CDT}.. {309942000 -2160
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1877
                                                                                                                                                                                                            Entropy (8bit):3.9636871490767147
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5bu36fELf0On9uhcinzPPoUlWQnH7eelN5Lh9LY5Lj:1qehpYtj
                                                                                                                                                                                                            MD5:34909341A29FF048D83B707D12A728A5
                                                                                                                                                                                                            SHA1:A4D4EC31681DB5F9DA899E20C6789D10827E6D86
                                                                                                                                                                                                            SHA-256:ADE65ADDEEA027D1BE70DC7C12513B61FDF36289021E66982D527C7FEE2A2D19
                                                                                                                                                                                                            SHA-512:57EED40425680CE2C05D961D3F21EE2E0D204E1FD6D3DB5F1EF7AC349AA269F9397D4E2121BD13BC3DE34205564FBE009CEEB5ADE4052EA742CBA15A91F5822B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Merida) {.. {-9223372036854775808 -21508 0 LMT}.. {-1514743200 -21600 0 CST}.. {377935200 -18000 0 EST}.. {407653200 -21600 0 CST}.. {828864000 -18000 1 CDT}.. {846399600 -21600 0 CST}.. {860313600 -18000 1 CDT}.. {877849200 -21600 0 CST}.. {891763200 -18000 1 CDT}.. {909298800 -21600 0 CST}.. {923212800 -18000 1 CDT}.. {941353200 -21600 0 CST}.. {954662400 -18000 1 CDT}.. {972802800 -21600 0 CST}.. {989136000 -18000 1 CDT}.. {1001833200 -21600 0 CST}.. {1018166400 -18000 1 CDT}.. {1035702000 -21600 0 CST}.. {1049616000 -18000 1 CDT}.. {1067151600 -21600 0 CST}.. {1081065600 -18000 1 CDT}.. {1099206000 -21600 0 CST}.. {1112515200 -18000 1 CDT}.. {1130655600 -21600 0 CST}.. {1143964800 -18000 1 CDT}.. {1162105200 -21600 0 CST}.. {1175414400 -18000 1 CDT}.. {1193554800 -21600 0 CST}.. {1207468800 -18000 1 CDT}.. {1225004400 -21600 0
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):6705
                                                                                                                                                                                                            Entropy (8bit):3.985641709481311
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:4DCG0haiaJCUbtp0nFI+g/iexpCVaBnNnt61nctE1:42G0IiaJCUbPI+D/iMpCIBSuk
                                                                                                                                                                                                            MD5:4999FE49C1640402CB432BC1EB667479
                                                                                                                                                                                                            SHA1:2ED0044927A66856090793ED6E5FF634617C8C40
                                                                                                                                                                                                            SHA-256:2574831391092AD44D7B2806EEF30D59CE3BAE872111917DD39EC51EFDD62E5F
                                                                                                                                                                                                            SHA-512:39DE1D24037F3FFA3101BBAA885939074E596479F68013CDA9CE53A061EA704F63FB55C15B68B66B0E29E3F07ADC0BDC2D78A2D289277E75D2EF95F54988DB74
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Metlakatla) {.. {-9223372036854775808 54822 0 LMT}.. {-3225223727 -31578 0 LMT}.. {-2188955622 -28800 0 PST}.. {-883584000 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-757353600 -28800 0 PST}.. {-31507200 -28800 0 PST}.. {-21477600 -25200 1 PDT}.. {-5756400 -28800 0 PST}.. {9972000 -25200 1 PDT}.. {25693200 -28800 0 PST}.. {41421600 -25200 1 PDT}.. {57747600 -28800 0 PST}.. {73476000 -25200 1 PDT}.. {89197200 -28800 0 PST}.. {104925600 -25200 1 PDT}.. {120646800 -28800 0 PST}.. {126698400 -25200 1 PDT}.. {152096400 -28800 0 PST}.. {162381600 -25200 1 PDT}.. {183546000 -28800 0 PST}.. {199274400 -25200 1 PDT}.. {215600400 -28800 0 PST}.. {230724000 -25200 1 PDT}.. {247050000 -28800 0 PST}.. {262778400 -25200 1 PDT}.. {278499600 -28800 0 PST}.. {294228000 -25200 1 PDT}.. {30
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2261
                                                                                                                                                                                                            Entropy (8bit):3.9546083289866267
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5CBUBUI+n36fELf5On9uhcinzPPoUlWQnH7eelN5Lh9LY5Lj:EB7qehpYtj
                                                                                                                                                                                                            MD5:7A67EA7FF5AC0E9B088298007A9370F4
                                                                                                                                                                                                            SHA1:531583F67E0C6ABA95B5A664A555BF40BF743CE8
                                                                                                                                                                                                            SHA-256:E83DB749E6AA87FD56829C2810D0F93A4194E3EE2CB0BDC12114B1EF55E92E96
                                                                                                                                                                                                            SHA-512:2C9035B415E36A769782FCFA15D79E5FEACA232439D1442407C8CD8C144EE9991030D9D58D2AD54CF6C0840BF78C81921B82BECBC74ABBD0DAC627F77772F52F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Mexico_City) {.. {-9223372036854775808 -23796 0 LMT}.. {-1514739600 -25200 0 MST}.. {-1343066400 -21600 0 CST}.. {-1234807200 -25200 0 MST}.. {-1220292000 -21600 1 MDT}.. {-1207159200 -25200 0 MST}.. {-1191344400 -21600 0 CST}.. {-975261600 -18000 1 CDT}.. {-963169200 -21600 0 CST}.. {-917114400 -18000 1 CDT}.. {-907354800 -21600 0 CST}.. {-821901600 -18000 1 CWT}.. {-810068400 -21600 0 CST}.. {-627501600 -18000 1 CDT}.. {-612990000 -21600 0 CST}.. {828864000 -18000 1 CDT}.. {846399600 -21600 0 CST}.. {860313600 -18000 1 CDT}.. {877849200 -21600 0 CST}.. {891763200 -18000 1 CDT}.. {909298800 -21600 0 CST}.. {923212800 -18000 1 CDT}.. {941353200 -21600 0 CST}.. {954662400 -18000 1 CDT}.. {972802800 -21600 0 CST}.. {989136000 -18000 1 CDT}.. {1001836800 -21600 0 CST}.. {1014184800 -21600 0 CST}.. {1018166400 -18000 1 CDT}.. {10357020
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7080
                                                                                                                                                                                                            Entropy (8bit):3.5379714312244217
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:2UViR+iORv7bw1aW5AnMyxH5e+fHbxMfOp6D7bF8qMmqyiqV1mjZe7JhlgXY7FWN:02l5qJZS
                                                                                                                                                                                                            MD5:C68889AA813C399939FCFA54E9CE0DFB
                                                                                                                                                                                                            SHA1:F3D58D7BEFF2D1CB94FECE00C31FEF5BDF58C231
                                                                                                                                                                                                            SHA-256:1B131AC968F95652667BD7EB1F6D667C8F679B31270D82B4B4271E787386CCCA
                                                                                                                                                                                                            SHA-512:EBAF8210919E34668E9DDFCB546E5A62F35954957AAE956B6302BF296C7D4CF51E1B10FB13217CB3EEB430DAC246217EB4E9250CB4109C95D8A4367457D02771
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Miquelon) {.. {-9223372036854775808 -13480 0 LMT}.. {-1850328920 -14400 0 AST}.. {326001600 -10800 0 -03}.. {536468400 -10800 0 -02}.. {544597200 -7200 1 -02}.. {562132800 -10800 0 -02}.. {576046800 -7200 1 -02}.. {594187200 -10800 0 -02}.. {607496400 -7200 1 -02}.. {625636800 -10800 0 -02}.. {638946000 -7200 1 -02}.. {657086400 -10800 0 -02}.. {671000400 -7200 1 -02}.. {688536000 -10800 0 -02}.. {702450000 -7200 1 -02}.. {719985600 -10800 0 -02}.. {733899600 -7200 1 -02}.. {752040000 -10800 0 -02}.. {765349200 -7200 1 -02}.. {783489600 -10800 0 -02}.. {796798800 -7200 1 -02}.. {814939200 -10800 0 -02}.. {828853200 -7200 1 -02}.. {846388800 -10800 0 -02}.. {860302800 -7200 1 -02}.. {877838400 -10800 0 -02}.. {891752400 -7200 1 -02}.. {909288000 -10800 0 -02}.. {923202000 -7200 1 -02}.. {941342400 -10800 0 -02}.. {954651600 -7200
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):10507
                                                                                                                                                                                                            Entropy (8bit):3.8204583916930557
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:X9+FPHyXFRsivcQYM+T7Z/xVQzxmtBWIXrObx29x8sLxcGMe++wzlrfFjxKvnpNM:gF6L0d0F2TzNc/1cYUH+CC
                                                                                                                                                                                                            MD5:80B88F57B837CD2478815796618A6AC6
                                                                                                                                                                                                            SHA1:CC2BE0213E9F0D3B307A8311D7A1013582E8A338
                                                                                                                                                                                                            SHA-256:D977D045DE5CDAEB41189B91963E03EF845CA4B45E496649B4CB541EE1B5DD22
                                                                                                                                                                                                            SHA-512:9410CBD706CAABFFF88DFF75235597D844B45A061EBD796F6708D7CEAB680273571A17935B7CCFC7C466ABF293C286D0886F47880E692F74C4E8BFB41729C73C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Moncton) {.. {-9223372036854775808 -15548 0 LMT}.. {-2715882052 -18000 0 EST}.. {-2131642800 -14400 0 AST}.. {-1632074400 -10800 1 ADT}.. {-1615143600 -14400 0 AST}.. {-1167595200 -14400 0 AST}.. {-1153681200 -10800 1 ADT}.. {-1145822400 -14400 0 AST}.. {-1122231600 -10800 1 ADT}.. {-1114372800 -14400 0 AST}.. {-1090782000 -10800 1 ADT}.. {-1082923200 -14400 0 AST}.. {-1059332400 -10800 1 ADT}.. {-1051473600 -14400 0 AST}.. {-1027882800 -10800 1 ADT}.. {-1020024000 -14400 0 AST}.. {-996433200 -10800 1 ADT}.. {-988574400 -14400 0 AST}.. {-965674800 -10800 1 ADT}.. {-955396800 -14400 0 AST}.. {-934743600 -10800 1 ADT}.. {-923947200 -14400 0 AST}.. {-904503600 -10800 1 ADT}.. {-891892800 -14400 0 AST}.. {-883598400 -14400 0 AST}.. {-880221600 -10800 1 AWT}.. {-769395600 -10800 1 APT}.. {-765399600 -14400 0 AST}.. {-757368000 -14400 0 AST
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1940
                                                                                                                                                                                                            Entropy (8bit):3.9628147491173964
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5JZKy36fELf0On9uhcinzPPoUlWQnH7eelN5Lh9LY5Lj:XwDqehpYtj
                                                                                                                                                                                                            MD5:4AE2B33D9DACE0E582FA456B361C50B7
                                                                                                                                                                                                            SHA1:5D62287F072F3687EF130BB1A9DD97BB2ABCF91C
                                                                                                                                                                                                            SHA-256:F5A66A403BF40BE7EAB188F3CEC8D7DB700F60084F7B856AB87E0AA4A0F2C0B6
                                                                                                                                                                                                            SHA-512:39BE803FD47709A1120FC8E09DB9B294DE41F69C7DD86AAB03AD8D0878B160B21D82B16398125559B792DAE99D5D917AE466C536001FEC1E618B68ACA9A80322
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Monterrey) {.. {-9223372036854775808 -24076 0 LMT}.. {-1514743200 -21600 0 CST}.. {568015200 -21600 0 CST}.. {576057600 -18000 1 CDT}.. {594198000 -21600 0 CST}.. {599637600 -21600 0 CST}.. {828864000 -18000 1 CDT}.. {846399600 -21600 0 CST}.. {860313600 -18000 1 CDT}.. {877849200 -21600 0 CST}.. {891763200 -18000 1 CDT}.. {909298800 -21600 0 CST}.. {923212800 -18000 1 CDT}.. {941353200 -21600 0 CST}.. {954662400 -18000 1 CDT}.. {972802800 -21600 0 CST}.. {989136000 -18000 1 CDT}.. {1001833200 -21600 0 CST}.. {1018166400 -18000 1 CDT}.. {1035702000 -21600 0 CST}.. {1049616000 -18000 1 CDT}.. {1067151600 -21600 0 CST}.. {1081065600 -18000 1 CDT}.. {1099206000 -21600 0 CST}.. {1112515200 -18000 1 CDT}.. {1130655600 -21600 0 CST}.. {1143964800 -18000 1 CDT}.. {1162105200 -21600 0 CST}.. {1175414400 -18000 1 CDT}.. {1193554800 -21600 0
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2936
                                                                                                                                                                                                            Entropy (8bit):3.6410670126139046
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5JgQkS4SaEcSyS0sZSUS2kSVSXSulSASX5kAXJMsCXrUari3akaWCa3M+lafpI6L:X5kH4c9GT0E01jm5keJMRXrUEi3akaWO
                                                                                                                                                                                                            MD5:D78DEBC7C0B15B31635DDC34C49248BC
                                                                                                                                                                                                            SHA1:DB2FF76DB3A79BE52E2DFD4C7B8B6592946772F9
                                                                                                                                                                                                            SHA-256:214F97A3BCB2378CCE23D280EA6A3B691604F82E383628F666BE585BB8494932
                                                                                                                                                                                                            SHA-512:E5FCD0B54F61910E70B1D0EE9911C5B4AFF850F16B651A01D69A63A97880913B0BAB99B0D864C4E613594734FA72CCA0E9607B1ADB6E75957C790990114FD0A4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Montevideo) {.. {-9223372036854775808 -13491 0 LMT}.. {-1942690509 -13491 0 MMT}.. {-1567455309 -14400 0 -04}.. {-1459627200 -10800 0 -0330}.. {-1443819600 -12600 0 -0330}.. {-1428006600 -10800 1 -0330}.. {-1412283600 -12600 0 -0330}.. {-1396470600 -10800 1 -0330}.. {-1380747600 -12600 0 -0330}.. {-1141590600 -10800 1 -0330}.. {-1128286800 -12600 0 -0330}.. {-1110141000 -10800 1 -0330}.. {-1096837200 -12600 0 -0330}.. {-1078691400 -10800 1 -0330}.. {-1065387600 -12600 0 -0330}.. {-1047241800 -10800 1 -0330}.. {-1033938000 -12600 0 -0330}.. {-1015187400 -10800 1 -0330}.. {-1002488400 -12600 0 -0330}.. {-983737800 -10800 1 -0330}.. {-971038800 -12600 0 -0330}.. {-954707400 -10800 1 -0330}.. {-938984400 -12600 0 -0330}.. {-920838600 -10800 1 -0330}.. {-907534800 -12600 0 -0330}.. {-896819400 -10800 1 -0330}.. {-853621200 -9000 0 -03}.. {-84
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):190
                                                                                                                                                                                                            Entropy (8bit):4.748877320903638
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0qMKLRXnXHAIg20qMKLRE6RL/2IAcGEzQ21h4IAcH:SlSWB9vsM3y7RQtHAIgpRQPN/290zQgp
                                                                                                                                                                                                            MD5:9130CD86BD6417DB877BF9D8F3080CE1
                                                                                                                                                                                                            SHA1:76C37982C37FE54ED539AC14B5A513817E42937C
                                                                                                                                                                                                            SHA-256:97F48948EF5108FE1F42D548EA47C88D4B51BF1896EE92634C7ED55555B06DBD
                                                                                                                                                                                                            SHA-512:EE036350AF95414392BD93DFF528F67D9A93EB192A30056ECBC3D2396AB4B2938B3C096C3EC2BC739294D4C4B7261C427B0AAEB9559F5381CB7F375892781820
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Toronto)]} {.. LoadTimeZoneFile America/Toronto..}..set TZData(:America/Montreal) $TZData(:America/Toronto)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):204
                                                                                                                                                                                                            Entropy (8bit):4.878534808314885
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290zQ1HK90ppv:MByMYbpwt290zQ490b
                                                                                                                                                                                                            MD5:CB5988A2508285B42C2BD487B8F9D6E1
                                                                                                                                                                                                            SHA1:EAD740A566245B682CE5E284D389DFAE66DF05D9
                                                                                                                                                                                                            SHA-256:6C3EE46983A3DAA91C9ADF4B18D6B4B80F1505B0057569B66D5B465D4C09B9C1
                                                                                                                                                                                                            SHA-512:48796213A67F0E3BC56B54CE4D8BE098E74BA5808C9A1082D9381CB729ADFA2ACB9CE9E39A3244B3901405761C97AEE28D44C3BF7239ECC71175C62E152029C4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Montserrat) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):188
                                                                                                                                                                                                            Entropy (8bit):4.785765433607229
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0qMKLRXnXHAIg20qMKLRE6RL/2IAcGEwEzEeIAcGu:SlSWB9vsM3y7RQtHAIgpRQPN/290xzEf
                                                                                                                                                                                                            MD5:F7DAD684104D917E0F29F6951EA627AC
                                                                                                                                                                                                            SHA1:E57B5CA730D90C5865CF32FEC4872F71E033D21C
                                                                                                                                                                                                            SHA-256:A889810B8BB42CD206D8F8961164AD03CCFBB1924D583075489F78AFA10EAF67
                                                                                                                                                                                                            SHA-512:8284F2A357A32B2F5A211904F65E3B5C37B77C9BF38C85DFA0A95A73457F3076EC12F09BC767B4D0B8FC86BF69D01A17A7BF685BAB72F3E519A397D050DA0C3B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Toronto)]} {.. LoadTimeZoneFile America/Toronto..}..set TZData(:America/Nassau) $TZData(:America/Toronto)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):11373
                                                                                                                                                                                                            Entropy (8bit):3.8110553140357086
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:HeohzORhK1a8phYvNoStCt/cL1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:+uORhK1a8phYloSItON0HY2iUmUFLqU
                                                                                                                                                                                                            MD5:385C3BDD3E41E5E75CEF0658322B5CDE
                                                                                                                                                                                                            SHA1:0334C21C8316ED2EE16FC98B1E8867D5E0916C00
                                                                                                                                                                                                            SHA-256:7BA7DA179AA7DF26AC25E7ACCD9BD83784174445285A0D9CCBD7D6A9AA34F4BC
                                                                                                                                                                                                            SHA-512:764B680FB8414B5AC8FB110247C19B1004A4453DD2BAC94BF3CFD80281FF3679A5B1D212238509165E022269503ED14A54B0EF73AF7014344752E6A627657D1F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/New_York) {.. {-9223372036854775808 -17762 0 LMT}.. {-2717650800 -18000 0 EST}.. {-1633280400 -14400 1 EDT}.. {-1615140000 -18000 0 EST}.. {-1601830800 -14400 1 EDT}.. {-1583690400 -18000 0 EST}.. {-1577905200 -18000 0 EST}.. {-1570381200 -14400 1 EDT}.. {-1551636000 -18000 0 EST}.. {-1536512400 -14400 1 EDT}.. {-1523210400 -18000 0 EST}.. {-1504458000 -14400 1 EDT}.. {-1491760800 -18000 0 EST}.. {-1473008400 -14400 1 EDT}.. {-1459706400 -18000 0 EST}.. {-1441558800 -14400 1 EDT}.. {-1428256800 -18000 0 EST}.. {-1410109200 -14400 1 EDT}.. {-1396807200 -18000 0 EST}.. {-1378659600 -14400 1 EDT}.. {-1365357600 -18000 0 EST}.. {-1347210000 -14400 1 EDT}.. {-1333908000 -18000 0 EST}.. {-1315155600 -14400 1 EDT}.. {-1301853600 -18000 0 EST}.. {-1283706000 -14400 1 EDT}.. {-1270404000 -18000 0 EST}.. {-1252256400 -14400 1 EDT}.. {-123895440
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):189
                                                                                                                                                                                                            Entropy (8bit):4.799414617322291
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0qMKLRXnXHAIg20qMKLRE6RL/2IAcGEwMueh4IAcH:SlSWB9vsM3y7RQtHAIgpRQPN/2905u+p
                                                                                                                                                                                                            MD5:B01CC44E5139066F87ADFF16728B98BF
                                                                                                                                                                                                            SHA1:4464E187AFF336C9137094308C270BB822974DF1
                                                                                                                                                                                                            SHA-256:55C37BF1A579A22A790ADE6585CE95BEC02DA356E84D2EF7832C422A4484FF9D
                                                                                                                                                                                                            SHA-512:A45166FFE444982593CBAC3E683D25D9EDB070DB6CD059A83D1C52099F409FFBFE6EA68D255AD000AF142BF8C8D100271531852263677184597877B7BF318847
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Toronto)]} {.. LoadTimeZoneFile America/Toronto..}..set TZData(:America/Nipigon) $TZData(:America/Toronto)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8680
                                                                                                                                                                                                            Entropy (8bit):3.965662913874442
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:OrBvOs5vzC9+j1giaJCUbtp0nFI+g/iexpCVaBnNnt61nctE1:OrBvOsM9DiaJCUbPI+D/iMpCIBSuk
                                                                                                                                                                                                            MD5:9A5F536932FED5A93E2C3DEB81960CD1
                                                                                                                                                                                                            SHA1:8E78396D280DD3A9564CEFC7FB722437F3C4D003
                                                                                                                                                                                                            SHA-256:8E971C9560CCE548B46626D072E62AB0F4C9682BF6A6ABFB4D0E8D63745402FE
                                                                                                                                                                                                            SHA-512:60CFDBCE87F9CD7F27E071D66B97E60F62E56F413DC867BC809490B30D00045D0757710D6B5724148E2A28BD1E45FB662391820E6350D998002BF67B16776645
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Nome) {.. {-9223372036854775808 46702 0 LMT}.. {-3225223727 -39698 0 LMT}.. {-2188947502 -39600 0 NST}.. {-883573200 -39600 0 NST}.. {-880196400 -36000 1 NWT}.. {-769395600 -36000 1 NPT}.. {-765374400 -39600 0 NST}.. {-757342800 -39600 0 NST}.. {-86878800 -39600 0 BST}.. {-31496400 -39600 0 BST}.. {-21466800 -36000 1 BDT}.. {-5745600 -39600 0 BST}.. {9982800 -36000 1 BDT}.. {25704000 -39600 0 BST}.. {41432400 -36000 1 BDT}.. {57758400 -39600 0 BST}.. {73486800 -36000 1 BDT}.. {89208000 -39600 0 BST}.. {104936400 -36000 1 BDT}.. {120657600 -39600 0 BST}.. {126709200 -36000 1 BDT}.. {152107200 -39600 0 BST}.. {162392400 -36000 1 BDT}.. {183556800 -39600 0 BST}.. {199285200 -36000 1 BDT}.. {215611200 -39600 0 BST}.. {230734800 -36000 1 BDT}.. {247060800 -39600 0 BST}.. {262789200 -36000 1 BDT}.. {278510400 -39600 0 BST}.. {29423880
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1397
                                                                                                                                                                                                            Entropy (8bit):3.78056049136398
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5TenykFxCFbF3YCFE2FBCFDFr9CFaFPBCFoF2CFTFKCFDuF1CF2F1CFWFhCFGF3a:5quY9EmFYBosNZNW/bWsBzgCccq7JYN9
                                                                                                                                                                                                            MD5:B4F4530FCE4BF5690042A2DA40413D56
                                                                                                                                                                                                            SHA1:52D5F2102485F5B326C888A287ED83CA18833BBC
                                                                                                                                                                                                            SHA-256:9011C76295E6B17CC1973876B497BEE21B9E6562FB25DF66140F811A1FFA9765
                                                                                                                                                                                                            SHA-512:08CAF75226D190D9FF0AA62AD84B13F1BF9047338A690847DF5B448BDB731A877F3E186298AFD704F4F4E133FF3F3128B098F9D90AE9A8E726AE52F84A7DA2E3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Noronha) {.. {-9223372036854775808 -7780 0 LMT}.. {-1767217820 -7200 0 -02}.. {-1206961200 -3600 1 -02}.. {-1191366000 -7200 0 -02}.. {-1175378400 -3600 1 -02}.. {-1159830000 -7200 0 -02}.. {-633823200 -3600 1 -02}.. {-622072800 -7200 0 -02}.. {-602287200 -3600 1 -02}.. {-591836400 -7200 0 -02}.. {-570751200 -3600 1 -02}.. {-560214000 -7200 0 -02}.. {-539128800 -3600 1 -02}.. {-531356400 -7200 0 -02}.. {-191368800 -3600 1 -02}.. {-184201200 -7200 0 -02}.. {-155167200 -3600 1 -02}.. {-150073200 -7200 0 -02}.. {-128901600 -3600 1 -02}.. {-121129200 -7200 0 -02}.. {-99957600 -3600 1 -02}.. {-89593200 -7200 0 -02}.. {-68421600 -3600 1 -02}.. {-57970800 -7200 0 -02}.. {499744800 -3600 1 -02}.. {511232400 -7200 0 -02}.. {530589600 -3600 1 -02}.. {540262800 -7200 0 -02}.. {562125600 -3600 1 -02}.. {571194000 -7200 0 -02}.. {592970400 -
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8557
                                                                                                                                                                                                            Entropy (8bit):3.8810445182855253
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:WEktwmGaLV911sF9A604qSScBgN+4ctDzIVQ/c/3hNxTh:WBwDPPA604qSBgI7DBch
                                                                                                                                                                                                            MD5:10AF9E9461DD03DA4F0AF0595EB36E6C
                                                                                                                                                                                                            SHA1:57AC9BDE3AC665E49D9D2463A4BFA38C053A4A54
                                                                                                                                                                                                            SHA-256:D0D8B108453265B60F525A4EC04DE9555087CD6AC5DDBA980B3A96CF0FCD68D1
                                                                                                                                                                                                            SHA-512:B6DC7D2709A19B911E086C988DB8346F42DBF7601D9E51E3093C6AF897570E43E5F1C101FE88BC5251F3DCC3B532DB22FFE8A12A4D0151BC52AF3E6DDEA7D23A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/North_Dakota/Beulah) {.. {-9223372036854775808 -24427 0 LMT}.. {-2717643600 -25200 0 MST}.. {-1633273200 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1601823600 -21600 1 MDT}.. {-1583683200 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-84380400 -21600 1 MDT}.. {-68659200 -25200 0 MST}.. {-52930800 -21600 1 MDT}.. {-37209600 -25200 0 MST}.. {-21481200 -21600 1 MDT}.. {-5760000 -25200 0 MST}.. {9968400 -21600 1 MDT}.. {25689600 -25200 0 MST}.. {41418000 -21600 1 MDT}.. {57744000 -25200 0 MST}.. {73472400 -21600 1 MDT}.. {89193600 -25200 0 MST}.. {104922000 -21600 1 MDT}.. {120643200 -25200 0 MST}.. {126694800 -21600 1 MDT}.. {152092800 -25200 0 MST}.. {162378000 -21600 1 MDT}.. {183542400 -25200 0 MST}.. {199270800 -21600 1 MDT}.. {215596800 -25200 0 MST}.. {230720400 -21600 1
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8557
                                                                                                                                                                                                            Entropy (8bit):3.867423227197841
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:ZEktwmGaLV9tZlNA604qSScBgN+4ctDzIVQ/c/3hNxTh:ZBwD6fA604qSBgI7DBch
                                                                                                                                                                                                            MD5:33C03AD65753D7ADB45FC4899B504D1A
                                                                                                                                                                                                            SHA1:ED719BB67A64DB49901BA38A945A6BA998646B8D
                                                                                                                                                                                                            SHA-256:ABC2B6C97D9E9FBA37AC582ADBA2CE996890D090060E083405D75CDAED9EABE0
                                                                                                                                                                                                            SHA-512:69592E8A370C8A5173827500CDDF8190AB44EA87CD7E0C416055CB7958B13A737801EA6B0FFE6032CB3F14F05001BF9DA83E4AEB20F385019B2985ECE7ACB40E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/North_Dakota/Center) {.. {-9223372036854775808 -24312 0 LMT}.. {-2717643600 -25200 0 MST}.. {-1633273200 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1601823600 -21600 1 MDT}.. {-1583683200 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-84380400 -21600 1 MDT}.. {-68659200 -25200 0 MST}.. {-52930800 -21600 1 MDT}.. {-37209600 -25200 0 MST}.. {-21481200 -21600 1 MDT}.. {-5760000 -25200 0 MST}.. {9968400 -21600 1 MDT}.. {25689600 -25200 0 MST}.. {41418000 -21600 1 MDT}.. {57744000 -25200 0 MST}.. {73472400 -21600 1 MDT}.. {89193600 -25200 0 MST}.. {104922000 -21600 1 MDT}.. {120643200 -25200 0 MST}.. {126694800 -21600 1 MDT}.. {152092800 -25200 0 MST}.. {162378000 -21600 1 MDT}.. {183542400 -25200 0 MST}.. {199270800 -21600 1 MDT}.. {215596800 -25200 0 MST}.. {230720400 -21600 1
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8560
                                                                                                                                                                                                            Entropy (8bit):3.879452555978431
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:GEktwmGaLV9nlNA604qSScBgN+4ctDzIVQ/c/3hNxTh:GBwD2fA604qSBgI7DBch
                                                                                                                                                                                                            MD5:3D3DC12209293086FD843738A4FE87FB
                                                                                                                                                                                                            SHA1:8103DFA18B5F3F36AF0B53FA350E0F2D300E6289
                                                                                                                                                                                                            SHA-256:8803FF7C81C933B57178B9D3C502FB4268D9AA594A3C638A7F17AF60B12D300D
                                                                                                                                                                                                            SHA-512:39BB939780A71B817F82D2B7F56815D33926D150525161051A9950E5A98BA9184670AFC884A1C69D56EADBD6198E3082975448EFBA5FE8A336DB071E6BAB8EF2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/North_Dakota/New_Salem) {.. {-9223372036854775808 -24339 0 LMT}.. {-2717643600 -25200 0 MST}.. {-1633273200 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1601823600 -21600 1 MDT}.. {-1583683200 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-84380400 -21600 1 MDT}.. {-68659200 -25200 0 MST}.. {-52930800 -21600 1 MDT}.. {-37209600 -25200 0 MST}.. {-21481200 -21600 1 MDT}.. {-5760000 -25200 0 MST}.. {9968400 -21600 1 MDT}.. {25689600 -25200 0 MST}.. {41418000 -21600 1 MDT}.. {57744000 -25200 0 MST}.. {73472400 -21600 1 MDT}.. {89193600 -25200 0 MST}.. {104922000 -21600 1 MDT}.. {120643200 -25200 0 MST}.. {126694800 -21600 1 MDT}.. {152092800 -25200 0 MST}.. {162378000 -21600 1 MDT}.. {183542400 -25200 0 MST}.. {199270800 -21600 1 MDT}.. {215596800 -25200 0 MST}.. {230720400 -2160
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7429
                                                                                                                                                                                                            Entropy (8bit):3.5470060859729253
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:0ixKXpbzvZ+FxAqe12voJ0euJFNgIHc/QEeF5Z1V8tCSfifK3facfzQWWLQelXuC:0LRJq9LstgV
                                                                                                                                                                                                            MD5:FC9CEA4B9654D0957F55CB0E1B25A3E7
                                                                                                                                                                                                            SHA1:8BFC3E8CEC34C4087579D3DA727143E3EC045B77
                                                                                                                                                                                                            SHA-256:12917DAAA60134BFE56E6979BB27B58A3F295C32BAE02B233E849BCED6B8BCA2
                                                                                                                                                                                                            SHA-512:355628F2EFF86605653A1EE7D976CE8B3229A4169D35576F6007FABAB37DD280D8F296EE88BECE3D84D3A1C476F23275D1D77CAF157E9A98672CBF14801D7292
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Nuuk) {.. {-9223372036854775808 -12416 0 LMT}.. {-1686083584 -10800 0 -03}.. {323845200 -7200 0 -02}.. {338950800 -10800 0 -03}.. {354675600 -7200 1 -02}.. {370400400 -10800 0 -03}.. {386125200 -7200 1 -02}.. {401850000 -10800 0 -03}.. {417574800 -7200 1 -02}.. {433299600 -10800 0 -03}.. {449024400 -7200 1 -02}.. {465354000 -10800 0 -03}.. {481078800 -7200 1 -02}.. {496803600 -10800 0 -03}.. {512528400 -7200 1 -02}.. {528253200 -10800 0 -03}.. {543978000 -7200 1 -02}.. {559702800 -10800 0 -03}.. {575427600 -7200 1 -02}.. {591152400 -10800 0 -03}.. {606877200 -7200 1 -02}.. {622602000 -10800 0 -03}.. {638326800 -7200 1 -02}.. {654656400 -10800 0 -03}.. {670381200 -7200 1 -02}.. {686106000 -10800 0 -03}.. {701830800 -7200 1 -02}.. {717555600 -10800 0 -03}.. {733280400 -7200 1 -02}.. {749005200 -10800 0 -03}.. {764730000 -7200 1 -0
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2069
                                                                                                                                                                                                            Entropy (8bit):3.994692300159945
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5Pe89WU0S+VS+TjV/NF01YluO53ON4Lvf3Pn:5gU033FS1YluOQiLvf3Pn
                                                                                                                                                                                                            MD5:0CB80C895BB4BFD36043F1CAAFB604B7
                                                                                                                                                                                                            SHA1:2EC2CA1D31EF1804E4EC26F449CA0D3C4F7AA7A0
                                                                                                                                                                                                            SHA-256:FC857E4DD0A4AE60A7C56637C752205E20442C7AE62158435BEFCA838174108D
                                                                                                                                                                                                            SHA-512:4BE44FF49AC588F1B441AB1B2678F5A0F0B60DB5C69F3F45C7447FC5A0175146F9FF83E132A5256CF7E559809EF7394C23DF9156A295D84D3A67EE917E661EED
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Ojinaga) {.. {-9223372036854775808 -25060 0 LMT}.. {-1514739600 -25200 0 MST}.. {-1343066400 -21600 0 CST}.. {-1234807200 -25200 0 MST}.. {-1220292000 -21600 1 MDT}.. {-1207159200 -25200 0 MST}.. {-1191344400 -21600 0 CST}.. {820476000 -21600 0 CST}.. {828864000 -18000 1 CDT}.. {846399600 -21600 0 CST}.. {860313600 -18000 1 CDT}.. {877849200 -21600 0 CST}.. {883634400 -21600 0 CST}.. {891766800 -21600 0 MDT}.. {909302400 -25200 0 MST}.. {923216400 -21600 1 MDT}.. {941356800 -25200 0 MST}.. {954666000 -21600 1 MDT}.. {972806400 -25200 0 MST}.. {989139600 -21600 1 MDT}.. {1001836800 -25200 0 MST}.. {1018170000 -21600 1 MDT}.. {1035705600 -25200 0 MST}.. {1049619600 -21600 1 MDT}.. {1067155200 -25200 0 MST}.. {1081069200 -21600 1 MDT}.. {1099209600 -25200 0 MST}.. {1112518800 -21600 1 MDT}.. {1130659200 -25200 0 MST}.. {1143968400 -21
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):186
                                                                                                                                                                                                            Entropy (8bit):4.970379147398626
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/2IAcGEu5YfMXGm2OHGf8xYoHv5BidhZvFsc1HRX1va0v:SlSWB9eg/290ZDm2OHDxYoHv5GhZd93p
                                                                                                                                                                                                            MD5:AA408A43079EC8933DE271BE3DA2B502
                                                                                                                                                                                                            SHA1:421A867DB3FD4779C5F759D0B657D8EB5FB2218B
                                                                                                                                                                                                            SHA-256:990213DDE00ADCEB74C8D1ECAF81B9C77963E4AB1F35767F7349236FC8E917DF
                                                                                                                                                                                                            SHA-512:1FB740527555A8E128E05709D05720A249BCBA4B6434D00226C07426E6283AA48973F75268F36E6044F0F0650E012781C8E5519B7EA916C625BBF018B29E9961
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Panama) {.. {-9223372036854775808 -19088 0 LMT}.. {-2524502512 -19176 0 CMT}.. {-1946918424 -18000 0 EST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7736
                                                                                                                                                                                                            Entropy (8bit):3.8533019559841972
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:tTqPm4bPJWXtRbALtuO/N0HY2iUmUFLqU:Izod
                                                                                                                                                                                                            MD5:6BA298F9CEB6406802A01C13313F8EF1
                                                                                                                                                                                                            SHA1:D77C113CFA927EF65461781FD080F590C8CFCBB9
                                                                                                                                                                                                            SHA-256:1FB962ECC1E5F02E1001C70460FFF720B114554F9AA7956D6DA154DBEA87B4D7
                                                                                                                                                                                                            SHA-512:C7F4E2DA503A3167098CFAB7AEC8D75A32D6B081E6777DE7BA3D6B4558D0C44D2CD8A0F1626968295031BABFD2CB96B031B4C00A44F2C554B5B217AE67E69EB4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Pangnirtung) {.. {-9223372036854775808 0 0 -00}.. {-1546300800 -14400 0 AST}.. {-880221600 -10800 1 AWT}.. {-769395600 -10800 1 APT}.. {-765399600 -14400 0 AST}.. {-147902400 -7200 1 ADDT}.. {-131572800 -14400 0 AST}.. {325663200 -10800 1 ADT}.. {341384400 -14400 0 AST}.. {357112800 -10800 1 ADT}.. {372834000 -14400 0 AST}.. {388562400 -10800 1 ADT}.. {404888400 -14400 0 AST}.. {420012000 -10800 1 ADT}.. {436338000 -14400 0 AST}.. {452066400 -10800 1 ADT}.. {467787600 -14400 0 AST}.. {483516000 -10800 1 ADT}.. {499237200 -14400 0 AST}.. {514965600 -10800 1 ADT}.. {530686800 -14400 0 AST}.. {544600800 -10800 1 ADT}.. {562136400 -14400 0 AST}.. {576050400 -10800 1 ADT}.. {594190800 -14400 0 AST}.. {607500000 -10800 1 ADT}.. {625640400 -14400 0 AST}.. {638949600 -10800 1 ADT}.. {657090000 -14400 0 AST}.. {671004000 -10800 1 ADT}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):253
                                                                                                                                                                                                            Entropy (8bit):4.784405839512086
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/290olofDm2OHekeoHXFIV/1Vw/9vVOzFZg/VVFAKV:MB86290oloLmdHeVCXqV/k/9v4zW/OW
                                                                                                                                                                                                            MD5:BFCE7E2618D6935031D6941AD6DDD8E3
                                                                                                                                                                                                            SHA1:1953CD224FB2363B10372C0476760F3FB020CB00
                                                                                                                                                                                                            SHA-256:B3EE44B3526BEDFC25B806371D3C465FDBD6CC647F30BF093750651E4A0C1BE4
                                                                                                                                                                                                            SHA-512:31262DF034E084DA4CDB57B99178594C29129F61F3535E5D8245B8BB4AB6BF314307B0F5E58B74C349684CD761C9CDE44EB10407FB135BA6427D3D1E9DA99B40
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Paramaribo) {.. {-9223372036854775808 -13240 0 LMT}.. {-1861906760 -13252 0 PMT}.. {-1104524348 -13236 0 PMT}.. {-765317964 -12600 0 -0330}.. {465449400 -10800 0 -03}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):496
                                                                                                                                                                                                            Entropy (8bit):4.444598497301421
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB86290OXmdH514YCvb8o1W4S9xRvhhHRVxORBYUNv:5tekdvYP1x52yq
                                                                                                                                                                                                            MD5:062ECA57C0B795780240CD7AFE70BDA0
                                                                                                                                                                                                            SHA1:89D71A11DD8D4E000F7FADBDDC77C4C1DC1195F7
                                                                                                                                                                                                            SHA-256:DFA0EC91804B789A1A7E1B1977710435D2589A5B54C1579C8E1F5BF96D2FD007
                                                                                                                                                                                                            SHA-512:7D123AA872E0B8286A26E338AE0F8E0D7A6F0F2EA8B1EBEC6DBB59477C812985CB246AD397D0901A58FDB7FF14171CF60169DC15C538B95C58BD2D46106A7A4D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Phoenix) {.. {-9223372036854775808 -26898 0 LMT}.. {-2717643600 -25200 0 MST}.. {-1633273200 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1601823600 -21600 1 MDT}.. {-1583683200 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-820519140 -25200 0 MST}.. {-796841940 -25200 0 MST}.. {-94669200 -25200 0 MST}.. {-84380400 -21600 1 MDT}.. {-68659200 -25200 0 MST}.. {-56221200 -25200 0 MST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):6613
                                                                                                                                                                                                            Entropy (8bit):3.8549788442269395
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5Ux+E2p3T6ZqrNSMEBPMcywh4NF5zCC7IOTWa1HW1241UWK9BDL+3XC4BMrS2LxP:KOfS0HY2iU7KKdFL6Aa2K4gSLf8e
                                                                                                                                                                                                            MD5:A720323DF122C70C1530788DB24700BA
                                                                                                                                                                                                            SHA1:20674BD7D84CC686ABBB5D6B36B520A5E9C813ED
                                                                                                                                                                                                            SHA-256:A89C580899AD2FF8DF45A783BB90D501DC32C28B92931CA18ABD13453E76244B
                                                                                                                                                                                                            SHA-512:02B71E537B9FDAF1B68E381F0007CCBBA53EB70719ED38F51B56C5BFA64C7E3D9797053C9DE3A920E5CAFA09BBC062FCED62B5D6B9213AFA8286B95DEDAB0532
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Port-au-Prince) {.. {-9223372036854775808 -17360 0 LMT}.. {-2524504240 -17340 0 PPMT}.. {-1670483460 -18000 0 EST}.. {421218000 -14400 1 EDT}.. {436334400 -18000 0 EST}.. {452062800 -14400 1 EDT}.. {467784000 -18000 0 EST}.. {483512400 -14400 1 EDT}.. {499233600 -18000 0 EST}.. {514962000 -14400 1 EDT}.. {530683200 -18000 0 EST}.. {546411600 -14400 1 EDT}.. {562132800 -18000 0 EST}.. {576050400 -14400 1 EDT}.. {594194400 -18000 0 EST}.. {607500000 -14400 1 EDT}.. {625644000 -18000 0 EST}.. {638949600 -14400 1 EDT}.. {657093600 -18000 0 EST}.. {671004000 -14400 1 EDT}.. {688543200 -18000 0 EST}.. {702453600 -14400 1 EDT}.. {719992800 -18000 0 EST}.. {733903200 -14400 1 EDT}.. {752047200 -18000 0 EST}.. {765352800 -14400 1 EDT}.. {783496800 -18000 0 EST}.. {796802400 -14400 1 EDT}.. {814946400 -18000 0 EST}.. {828856800 -14400 1 EDT}
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):207
                                                                                                                                                                                                            Entropy (8bit):4.919510214047913
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290e7490ppv:MByMYbpwt290190b
                                                                                                                                                                                                            MD5:4AB394CB233B101627136EB5E070CF9B
                                                                                                                                                                                                            SHA1:F00600CD2DB10FE157C3696F665B9759EEA85F99
                                                                                                                                                                                                            SHA-256:A4952380C89A6903FFE5BF8707B94B1BB72568FFD03DB04BF4D98E38AC82EEB7
                                                                                                                                                                                                            SHA-512:58F4AD08FA10F1884FA641C4EA778C0FC013EABBD68DF5DE04D5B301227396260C3D669DB33DD6A6B33F1550C24BBD7777D756DF0D61CEEAF5EC6541EDFA296C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Port_of_Spain) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):201
                                                                                                                                                                                                            Entropy (8bit):4.866417687745155
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7thteSHAIgpth9RN/290msh490th4:MByMYdIp7t290v490I
                                                                                                                                                                                                            MD5:6B570E79FA2AA7D6CB1E56A11EE0A37C
                                                                                                                                                                                                            SHA1:396A2C9BBE4F264DD5A4F2E44D3E63C57F52186B
                                                                                                                                                                                                            SHA-256:52921EEA2A1925DF06CEA4638ED4128FAAA8FBA40ED4E0741650B419E5152DCB
                                                                                                                                                                                                            SHA-512:FA75A179664BED02A0F5BC1B7C3DD5F3E986544A151634BA4C4401476F5999714C89E240D9AF805484D1BEC04A1A562157FAEECA1603C4FF8CFFB424B9DEB560
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Rio_Branco)]} {.. LoadTimeZoneFile America/Rio_Branco..}..set TZData(:America/Porto_Acre) $TZData(:America/Rio_Branco)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1051
                                                                                                                                                                                                            Entropy (8bit):3.851275104153641
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5Xe4QJnSRs//SFs/pS9/MHSW/WOSr/nSso/TSL/SSU/iS5X/LcSi/xScd/ZlSQ/8:5kSeSFESoSQSrSsCSeSPS1cSQSQlSsSX
                                                                                                                                                                                                            MD5:03046BA6F8344C32AD7A22748DC871AB
                                                                                                                                                                                                            SHA1:AB9ED078D80AE99EF6DE4BF34AC45359B82D1284
                                                                                                                                                                                                            SHA-256:E6E6F6753E7D443052A64D4DB07B8D443CE13A573946E7D0A19CDD4BBA4A2F04
                                                                                                                                                                                                            SHA-512:620953BB4C8CF203262EC0C1F807543D24B9894C3B531AE57F7CEF630452CC9AC7CA41D43A6D8891F9CF17594E9EE34CF501F8508E7C0669A8E5EF9C70B6EAA3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Porto_Velho) {.. {-9223372036854775808 -15336 0 LMT}.. {-1767210264 -14400 0 -04}.. {-1206954000 -10800 1 -04}.. {-1191358800 -14400 0 -04}.. {-1175371200 -10800 1 -04}.. {-1159822800 -14400 0 -04}.. {-633816000 -10800 1 -04}.. {-622065600 -14400 0 -04}.. {-602280000 -10800 1 -04}.. {-591829200 -14400 0 -04}.. {-570744000 -10800 1 -04}.. {-560206800 -14400 0 -04}.. {-539121600 -10800 1 -04}.. {-531349200 -14400 0 -04}.. {-191361600 -10800 1 -04}.. {-184194000 -14400 0 -04}.. {-155160000 -10800 1 -04}.. {-150066000 -14400 0 -04}.. {-128894400 -10800 1 -04}.. {-121122000 -14400 0 -04}.. {-99950400 -10800 1 -04}.. {-89586000 -14400 0 -04}.. {-68414400 -10800 1 -04}.. {-57963600 -14400 0 -04}.. {499752000 -10800 1 -04}.. {511239600 -14400 0 -04}.. {530596800 -10800 1 -04}.. {540270000 -14400 0 -04}.. {562132800 -10800 1 -04}.. {5712012
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):283
                                                                                                                                                                                                            Entropy (8bit):4.781646667761219
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/290piDm2OH9VoHvMlFoeVVF70ZVVFUFkzk/lLJpR/lAov:MB862908mdHvCvMlGe/J0Z/uFkzk/lL1
                                                                                                                                                                                                            MD5:E2E2E0D6677FFF2E37BBFC3522F2A9AA
                                                                                                                                                                                                            SHA1:4C1C93E14FBC00B8B1E78B8D9631599164305EB1
                                                                                                                                                                                                            SHA-256:2981248A9F14EBFC8791EC5453170376CBD549557E495EA0E331CC18556C958E
                                                                                                                                                                                                            SHA-512:F056B03EB9945823F5284C840E06E298DD2DE854F1555CD16D0BB19D962B73EF34A05683E6369B0D89CB7C3F7D082C312CCA6F8C6A0BB53F5C75FE4A863FCD95
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Puerto_Rico) {.. {-9223372036854775808 -15865 0 LMT}.. {-2233035335 -14400 0 AST}.. {-873057600 -10800 0 AWT}.. {-769395600 -10800 1 APT}.. {-765399600 -14400 0 AST}.. {-757368000 -14400 0 AST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3729
                                                                                                                                                                                                            Entropy (8bit):3.6253057710886956
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:2RPW7xUQjzoMUBI0nuUoDKlHslPlgiot7JC/Xk8NWse4r4g5xCEmSdLkUsZOn+ZW:247xUQjzoMUBI0nuUoDK6lPlgiot7JCV
                                                                                                                                                                                                            MD5:D4ECD2A380E55A10FB97AB1D29C619F3
                                                                                                                                                                                                            SHA1:AAAFF44590F08623BE6F61EA6EFF6488C99A73BF
                                                                                                                                                                                                            SHA-256:4E626BD8B9182E56ADA1E9276585E945957431EA9BEA949CE071305E4E3C70A2
                                                                                                                                                                                                            SHA-512:677EE7093A53B48DE526C5877DB7128E8746831FE0DC44A38EB84050757E6017C9471EEF9AFCCEEEB5794D1608E486840804C01BD6276EA53F3C7823B05ED62B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Punta_Arenas) {.. {-9223372036854775808 -17020 0 LMT}.. {-2524504580 -16965 0 SMT}.. {-1892661435 -18000 0 -05}.. {-1688410800 -16965 0 SMT}.. {-1619205435 -14400 0 -04}.. {-1593806400 -16965 0 SMT}.. {-1335986235 -18000 0 -05}.. {-1335985200 -14400 1 -05}.. {-1317585600 -18000 0 -05}.. {-1304362800 -14400 1 -05}.. {-1286049600 -18000 0 -05}.. {-1272826800 -14400 1 -05}.. {-1254513600 -18000 0 -05}.. {-1241290800 -14400 1 -05}.. {-1222977600 -18000 0 -05}.. {-1209754800 -14400 1 -05}.. {-1191355200 -18000 0 -05}.. {-1178132400 -14400 0 -04}.. {-870552000 -18000 0 -05}.. {-865278000 -14400 0 -04}.. {-736632000 -14400 1 -04}.. {-718056000 -18000 0 -05}.. {-713649600 -14400 0 -04}.. {-36619200 -10800 1 -04}.. {-23922000 -14400 0 -04}.. {-3355200 -10800 1 -04}.. {7527600 -14400 0 -04}.. {24465600 -10800 1 -04}.. {37767600 -14400 0 -04}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):196
                                                                                                                                                                                                            Entropy (8bit):4.926514352074701
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7pYHAIgppuRN/290ly90pl:MByMY/pcRt290w90X
                                                                                                                                                                                                            MD5:552FBD2FBAD42F79C7993124D9CCC54B
                                                                                                                                                                                                            SHA1:9029B7CCE8A5AD0F14C05FFBCDA4CA225DEC1708
                                                                                                                                                                                                            SHA-256:FEC74A3FCBD9B99FDFF24B54223DA187958697CBE756A54592F6171C69F1403F
                                                                                                                                                                                                            SHA-512:96315C32C1D0DEF804A560022DA12B3C63200A680F2A37D1B03E1C9EA413842EB6051E1C2315AE4E7C374280AD0E59832F834A8D6D66E259EF62735A77917ECE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Winnipeg)]} {.. LoadTimeZoneFile America/Winnipeg..}..set TZData(:America/Rainy_River) $TZData(:America/Winnipeg)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7614
                                                                                                                                                                                                            Entropy (8bit):3.8349162993762267
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:Wi8h4ZlNA604qSScBgN+4ctDzIVQ/c/3hNxTh:bqOfA604qSBgI7DBch
                                                                                                                                                                                                            MD5:793DAEDB7E3077DE52DCC3C8A7CBEC5B
                                                                                                                                                                                                            SHA1:37562E9F28D51DED41FFD5FF2FF19E2E4E453B7A
                                                                                                                                                                                                            SHA-256:AA8866D58BEAB07548180628FF423887BBF48AADB1B55392B288F7310F94A9B1
                                                                                                                                                                                                            SHA-512:68A32B41DC2D3E730D6BE53656B0D566AB1BCC1E189A2FFDB5687A947EF4F4008BC17456F8CE0D59C838EEA87A44400231A44E6AB35BEDBF5D7779E1CD7EFD8A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Rankin_Inlet) {.. {-9223372036854775808 0 0 -00}.. {-410227200 -21600 0 CST}.. {-147895200 -14400 1 CDDT}.. {-131565600 -21600 0 CST}.. {325670400 -18000 1 CDT}.. {341391600 -21600 0 CST}.. {357120000 -18000 1 CDT}.. {372841200 -21600 0 CST}.. {388569600 -18000 1 CDT}.. {404895600 -21600 0 CST}.. {420019200 -18000 1 CDT}.. {436345200 -21600 0 CST}.. {452073600 -18000 1 CDT}.. {467794800 -21600 0 CST}.. {483523200 -18000 1 CDT}.. {499244400 -21600 0 CST}.. {514972800 -18000 1 CDT}.. {530694000 -21600 0 CST}.. {544608000 -18000 1 CDT}.. {562143600 -21600 0 CST}.. {576057600 -18000 1 CDT}.. {594198000 -21600 0 CST}.. {607507200 -18000 1 CDT}.. {625647600 -21600 0 CST}.. {638956800 -18000 1 CDT}.. {657097200 -21600 0 CST}.. {671011200 -18000 1 CDT}.. {688546800 -21600 0 CST}.. {702460800 -18000 1 CDT}.. {719996400 -21600 0 CST}.. {7
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1420
                                                                                                                                                                                                            Entropy (8bit):3.78262494063765
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5aLexyGcChlrLPsw6kSS3h5R14eH8tf3GvIkuoYVZaI1kR8nd:5eTChlvEw6kSSx5H4a8tf3fkuoYVZDm+
                                                                                                                                                                                                            MD5:4D12651CEE804EB9F29567CB37F12031
                                                                                                                                                                                                            SHA1:54B2613475B8BDB1DBCCA53A4895DA021F66BDC0
                                                                                                                                                                                                            SHA-256:A36AD4614FC9A2A433712B555156EDE03980B88EB91D8DC7E8B10451D6D7F7D3
                                                                                                                                                                                                            SHA-512:E6690F6B6DF613C8B7289A2DB71FBC9B87B997707A6C3B4B45BDE8F347082AE8C69F212BAACE50F3C04E325ABE0976AF1F61107BDF8A15D5B88F11FAE11A9D00
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Recife) {.. {-9223372036854775808 -8376 0 LMT}.. {-1767217224 -10800 0 -03}.. {-1206957600 -7200 1 -03}.. {-1191362400 -10800 0 -03}.. {-1175374800 -7200 1 -03}.. {-1159826400 -10800 0 -03}.. {-633819600 -7200 1 -03}.. {-622069200 -10800 0 -03}.. {-602283600 -7200 1 -03}.. {-591832800 -10800 0 -03}.. {-570747600 -7200 1 -03}.. {-560210400 -10800 0 -03}.. {-539125200 -7200 1 -03}.. {-531352800 -10800 0 -03}.. {-191365200 -7200 1 -03}.. {-184197600 -10800 0 -03}.. {-155163600 -7200 1 -03}.. {-150069600 -10800 0 -03}.. {-128898000 -7200 1 -03}.. {-121125600 -10800 0 -03}.. {-99954000 -7200 1 -03}.. {-89589600 -10800 0 -03}.. {-68418000 -7200 1 -03}.. {-57967200 -10800 0 -03}.. {499748400 -7200 1 -03}.. {511236000 -10800 0 -03}.. {530593200 -7200 1 -03}.. {540266400 -10800 0 -03}.. {562129200 -7200 1 -03}.. {571197600 -10800 0 -03}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1781
                                                                                                                                                                                                            Entropy (8bit):4.034282439637634
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB86290hjmdHfCv24Q1NAvHaE+YB+Q4kRcMxIeRUVX/SEQd1rRR9xRv0+Ro/wPjp:5EjeavTGOtAVvSRBpx0yq1epwD+yz+
                                                                                                                                                                                                            MD5:14B29B4391B643E5707096ADCC33C57E
                                                                                                                                                                                                            SHA1:B3F875ABB79C634C74307B7CB7B276B13AEE11D1
                                                                                                                                                                                                            SHA-256:50105E788288CF4C680B29BBDCDE94D8713A5361B38C6C469FD97CF05503FF7D
                                                                                                                                                                                                            SHA-512:D92A51547DF2C1AB6E6CDEFF34C07B755D3F6BB5E7DD1907693E7658EDE4D2BADC5DEFDB658ADD0F8D8F14B3B87CEA17BC00DAC364C5CB7ACBF8778C245276A9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Regina) {.. {-9223372036854775808 -25116 0 LMT}.. {-2030202084 -25200 0 MST}.. {-1632063600 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1251651600 -21600 1 MDT}.. {-1238349600 -25200 0 MST}.. {-1220202000 -21600 1 MDT}.. {-1206900000 -25200 0 MST}.. {-1188752400 -21600 1 MDT}.. {-1175450400 -25200 0 MST}.. {-1156698000 -21600 1 MDT}.. {-1144000800 -25200 0 MST}.. {-1125248400 -21600 1 MDT}.. {-1111946400 -25200 0 MST}.. {-1032714000 -21600 1 MDT}.. {-1016992800 -25200 0 MST}.. {-1001264400 -21600 1 MDT}.. {-986148000 -25200 0 MST}.. {-969814800 -21600 1 MDT}.. {-954093600 -25200 0 MST}.. {-937760400 -21600 1 MDT}.. {-922039200 -25200 0 MST}.. {-906310800 -21600 1 MDT}.. {-890589600 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-748450800 -21600 1 MDT}.. {-732729600 -25200 0 MST
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7610
                                                                                                                                                                                                            Entropy (8bit):3.8312000314798085
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:li8h4Z80NA604qSScBgN+4ctDzIVQ/c/3hNxTh:EqOzA604qSBgI7DBch
                                                                                                                                                                                                            MD5:541EACD872723603971058CB205121D7
                                                                                                                                                                                                            SHA1:8F7DFD5ECA2913846D9342839AE1C60882153DA0
                                                                                                                                                                                                            SHA-256:643CC43E3F906779C040E1F0C20E78D6E95CC7301B3C7370A8ADBCBD76A8C5E8
                                                                                                                                                                                                            SHA-512:971D06D3FB67B7AE79EEDB6D3EBB805B5992C2BF4A7166016B405E21BFB25D9A87A757E8065073D5FBEB9084F6F742269A5BF432BF2F03D30913DB092E1AB3A1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Resolute) {.. {-9223372036854775808 0 0 -00}.. {-704937600 -21600 0 CST}.. {-147895200 -14400 1 CDDT}.. {-131565600 -21600 0 CST}.. {325670400 -18000 1 CDT}.. {341391600 -21600 0 CST}.. {357120000 -18000 1 CDT}.. {372841200 -21600 0 CST}.. {388569600 -18000 1 CDT}.. {404895600 -21600 0 CST}.. {420019200 -18000 1 CDT}.. {436345200 -21600 0 CST}.. {452073600 -18000 1 CDT}.. {467794800 -21600 0 CST}.. {483523200 -18000 1 CDT}.. {499244400 -21600 0 CST}.. {514972800 -18000 1 CDT}.. {530694000 -21600 0 CST}.. {544608000 -18000 1 CDT}.. {562143600 -21600 0 CST}.. {576057600 -18000 1 CDT}.. {594198000 -21600 0 CST}.. {607507200 -18000 1 CDT}.. {625647600 -21600 0 CST}.. {638956800 -18000 1 CDT}.. {657097200 -21600 0 CST}.. {671011200 -18000 1 CDT}.. {688546800 -21600 0 CST}.. {702460800 -18000 1 CDT}.. {719996400 -21600 0 CST}.. {73391
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1112
                                                                                                                                                                                                            Entropy (8bit):3.8413073465060457
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5Ybe/k5Yss/uuD/uVK/uNC/uvFe/uxJs/u74O/u83C/uc8J/uhF8/uNHs/ulU6Gs:505YsMw57XJh4CxUF/A6GTrtSUDwr
                                                                                                                                                                                                            MD5:7E23FDE0E158E8ED2E7536EDE70D2588
                                                                                                                                                                                                            SHA1:319052BE076DC79F130E807D68B11CCAA0636340
                                                                                                                                                                                                            SHA-256:28082D20872B61D6098D31D1C40F12464A946A933CD9AF74475C5AF384210890
                                                                                                                                                                                                            SHA-512:BE078ED12F05AB5CEE5D77212EB76A01A1BC52EEAA17E3B91D93B88D75E5281B6AF164E712A9AB0F57A21B3CDB20F6FCCADB73CAC4745B5D2E665D18F9F06B55
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Rio_Branco) {.. {-9223372036854775808 -16272 0 LMT}.. {-1767209328 -18000 0 -05}.. {-1206950400 -14400 1 -05}.. {-1191355200 -18000 0 -05}.. {-1175367600 -14400 1 -05}.. {-1159819200 -18000 0 -05}.. {-633812400 -14400 1 -05}.. {-622062000 -18000 0 -05}.. {-602276400 -14400 1 -05}.. {-591825600 -18000 0 -05}.. {-570740400 -14400 1 -05}.. {-560203200 -18000 0 -05}.. {-539118000 -14400 1 -05}.. {-531345600 -18000 0 -05}.. {-191358000 -14400 1 -05}.. {-184190400 -18000 0 -05}.. {-155156400 -14400 1 -05}.. {-150062400 -18000 0 -05}.. {-128890800 -14400 1 -05}.. {-121118400 -18000 0 -05}.. {-99946800 -14400 1 -05}.. {-89582400 -18000 0 -05}.. {-68410800 -14400 1 -05}.. {-57960000 -18000 0 -05}.. {499755600 -14400 1 -05}.. {511243200 -18000 0 -05}.. {530600400 -14400 1 -05}.. {540273600 -18000 0 -05}.. {562136400 -14400 1 -05}.. {57120480
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):219
                                                                                                                                                                                                            Entropy (8bit):4.801485647578614
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7/MSHAIgp/M1ovN/290rI5290/M7:MByMY/M7p/M16t290r190/M7
                                                                                                                                                                                                            MD5:90830F3B1F91FE48AC2944C7C92A3F6E
                                                                                                                                                                                                            SHA1:777377AE4959DDD2B472EB6041A23A5B93D64BB6
                                                                                                                                                                                                            SHA-256:0117D33D4F326AA536162D36A02439FBD5F2EB3B4F540B5BA91ED7747DDAC180
                                                                                                                                                                                                            SHA-512:20A371E4550E402AFEB83EF19EFFF6B3C0D7A68DCAA06AD894D04DB63B7096560E701C45B455B23A98BB20FE3B590F920219152415CA506AEDA427BB1381B826
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Argentina/Cordoba)]} {.. LoadTimeZoneFile America/Argentina/Cordoba..}..set TZData(:America/Rosario) $TZData(:America/Argentina/Cordoba)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):194
                                                                                                                                                                                                            Entropy (8bit):4.869058214823402
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7ekHAIgpeON/290tX2U490eBn:MByMYMpJt290c90m
                                                                                                                                                                                                            MD5:F4E62378AA05771D348AA6DA516CD386
                                                                                                                                                                                                            SHA1:07FCA813693F7944CBCBB128F2F2FE32929D37A2
                                                                                                                                                                                                            SHA-256:3B4C2F3A5B9CD22A73F05187C032723D07BB53C9946D04D35E1BA1CB90CA0A62
                                                                                                                                                                                                            SHA-512:E9F6CEB824D656CA25A72BF8EB4347A22E1A8E40410F01E0C2EDE19ACAF32D76540399796B3EBC7781C8B5D48C1A6B2C856CA06158AE37D95C95CF0567DFA2E5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Tijuana)]} {.. LoadTimeZoneFile America/Tijuana..}..set TZData(:America/Santa_Isabel) $TZData(:America/Tijuana)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1079
                                                                                                                                                                                                            Entropy (8bit):3.8200568741699223
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5zeUdunSRs//SFs/pS9/MHSW/WOSr/nSso/TSL/SSU/iS5X/LcSi/xScd/ZlSQ/h:52SeSFESoSQSrSsCSeSPS1cSQSQlSsSU
                                                                                                                                                                                                            MD5:7F2658032008F2C1308F121C2EBF2479
                                                                                                                                                                                                            SHA1:B6F24E818B4424C0DEF818C103D1DA5359958932
                                                                                                                                                                                                            SHA-256:4A397BD937DE1D7E6A941D18001B34D4CD195AEFD08951C30C7EE8E48656AA0E
                                                                                                                                                                                                            SHA-512:F78853AA75F58A85555DD79E08A7487E5161854650DBF480189790D855738FEDCBDA936870067DE40FE000861008A9E9AAF61DF02B6B30B96038C61B5E1F1C1D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Santarem) {.. {-9223372036854775808 -13128 0 LMT}.. {-1767212472 -14400 0 -04}.. {-1206954000 -10800 1 -04}.. {-1191358800 -14400 0 -04}.. {-1175371200 -10800 1 -04}.. {-1159822800 -14400 0 -04}.. {-633816000 -10800 1 -04}.. {-622065600 -14400 0 -04}.. {-602280000 -10800 1 -04}.. {-591829200 -14400 0 -04}.. {-570744000 -10800 1 -04}.. {-560206800 -14400 0 -04}.. {-539121600 -10800 1 -04}.. {-531349200 -14400 0 -04}.. {-191361600 -10800 1 -04}.. {-184194000 -14400 0 -04}.. {-155160000 -10800 1 -04}.. {-150066000 -14400 0 -04}.. {-128894400 -10800 1 -04}.. {-121122000 -14400 0 -04}.. {-99950400 -10800 1 -04}.. {-89586000 -14400 0 -04}.. {-68414400 -10800 1 -04}.. {-57963600 -14400 0 -04}.. {499752000 -10800 1 -04}.. {511239600 -14400 0 -04}.. {530596800 -10800 1 -04}.. {540270000 -14400 0 -04}.. {562132800 -10800 1 -04}.. {571201200
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8871
                                                                                                                                                                                                            Entropy (8bit):3.5351636359890537
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:2Xv/lxUQjzoMUBI0nuUoDK6lPlgiot7JC/k8NWse4r4g5xCEmMQUs8nCxvisEbzu:2fD9TzDC9g32+E
                                                                                                                                                                                                            MD5:81FC6AFF68B1CF2EA57ED13A42B35BE1
                                                                                                                                                                                                            SHA1:5889E502FBDCBCDFE9E7053625FFFBAD61FFE256
                                                                                                                                                                                                            SHA-256:77CED11337F43241D57C10BA752C7104A7AF8727992E7B90A3C5D62AA15E81C7
                                                                                                                                                                                                            SHA-512:7756CBAF76966F3D45883B725B791A8DD60E8329F6FE19C12029C6FEBC90D7322765A0A8BA26FC586443A902B372D0C0189426A8F99B2B535BB8F1EE74796B44
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Santiago) {.. {-9223372036854775808 -16965 0 LMT}.. {-2524504635 -16965 0 SMT}.. {-1892661435 -18000 0 -05}.. {-1688410800 -16965 0 SMT}.. {-1619205435 -14400 0 -04}.. {-1593806400 -16965 0 SMT}.. {-1335986235 -18000 0 -05}.. {-1335985200 -14400 1 -05}.. {-1317585600 -18000 0 -05}.. {-1304362800 -14400 1 -05}.. {-1286049600 -18000 0 -05}.. {-1272826800 -14400 1 -05}.. {-1254513600 -18000 0 -05}.. {-1241290800 -14400 1 -05}.. {-1222977600 -18000 0 -05}.. {-1209754800 -14400 1 -05}.. {-1191355200 -18000 0 -05}.. {-1178132400 -14400 0 -04}.. {-870552000 -18000 0 -05}.. {-865278000 -14400 0 -04}.. {-740520000 -10800 1 -03}.. {-736635600 -14400 1 -04}.. {-718056000 -18000 0 -05}.. {-713649600 -14400 0 -04}.. {-36619200 -10800 1 -04}.. {-23922000 -14400 0 -04}.. {-3355200 -10800 1 -04}.. {7527600 -14400 0 -04}.. {24465600 -10800 1 -04}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):616
                                                                                                                                                                                                            Entropy (8bit):4.330655351784895
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB86290/StmdHhvCvuCY/h/uFkS/5MVvMrW//MVvMrpx/m0XVvMr4UB/47VvMr/d:5+seQvuCY5/u/REfk+xxdbUBQpu652GO
                                                                                                                                                                                                            MD5:FAD0621010889164ADC4472003C9391F
                                                                                                                                                                                                            SHA1:C4EE0B8D6925338D17D5745DE9D45FA3C628DFC5
                                                                                                                                                                                                            SHA-256:2217E72B11A90F2D679C175DE3CC0F2FED4C280C9FF9707CFFAF118BF9A06A4B
                                                                                                                                                                                                            SHA-512:90E8E5A109CD72458C7796CF0324F63E543CCD63D13A09A3DD28EDC8B2793C964C18E79FDF0C5067C5A481B7FB03E8413139C32F59DA07E9D7893378ABBBD2B3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Santo_Domingo) {.. {-9223372036854775808 -16776 0 LMT}.. {-2524504824 -16800 0 SDMT}.. {-1159773600 -18000 0 EST}.. {-100119600 -14400 1 EDT}.. {-89668800 -18000 0 EST}.. {-5770800 -16200 1 -0430}.. {4422600 -18000 0 EST}.. {25678800 -16200 1 -0430}.. {33193800 -18000 0 EST}.. {57733200 -16200 1 -0430}.. {64816200 -18000 0 EST}.. {89182800 -16200 1 -0430}.. {96438600 -18000 0 EST}.. {120632400 -16200 1 -0430}.. {127974600 -18000 0 EST}.. {152082000 -14400 0 AST}.. {975823200 -14400 0 AST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2900
                                                                                                                                                                                                            Entropy (8bit):3.6548008349990755
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5uFChlvEwR9xSSx5H4a8tf3fku+da2XUd23t8VZDG8+w/ghBPWTRz908a9zRgwun:cFIlvEwZSSxdF8tfMu+da2kdCt8VZy8n
                                                                                                                                                                                                            MD5:F6B732A862659EB131C2E6FEC00E9734
                                                                                                                                                                                                            SHA1:49517DF63BC5B6FEC875CE9477BBF84F4072FA31
                                                                                                                                                                                                            SHA-256:0E7BA1C5A3FA3DABDAA226BFE1E8D797A3835EA554828881AB5E365EDA09B92E
                                                                                                                                                                                                            SHA-512:670A5B604B5EA0F5FA15083BC1EA115B7EFD449F9EAC4518E109493591893DD3627AFC6628E0EDD1953E932E2A7AD9B5A379526548677158EC445366E4ED7166
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Sao_Paulo) {.. {-9223372036854775808 -11188 0 LMT}.. {-1767214412 -10800 0 -03}.. {-1206957600 -7200 1 -03}.. {-1191362400 -10800 0 -03}.. {-1175374800 -7200 1 -03}.. {-1159826400 -10800 0 -03}.. {-633819600 -7200 1 -03}.. {-622069200 -10800 0 -03}.. {-602283600 -7200 1 -03}.. {-591832800 -10800 0 -03}.. {-570747600 -7200 1 -03}.. {-560210400 -10800 0 -03}.. {-539125200 -7200 1 -03}.. {-531352800 -10800 0 -03}.. {-195429600 -7200 1 -02}.. {-189381600 -7200 0 -03}.. {-184197600 -10800 0 -03}.. {-155163600 -7200 1 -03}.. {-150069600 -10800 0 -03}.. {-128898000 -7200 1 -03}.. {-121125600 -10800 0 -03}.. {-99954000 -7200 1 -03}.. {-89589600 -10800 0 -03}.. {-68418000 -7200 1 -03}.. {-57967200 -10800 0 -03}.. {499748400 -7200 1 -03}.. {511236000 -10800 0 -03}.. {530593200 -7200 1 -03}.. {540266400 -10800 0 -03}.. {562129200 -7200 1 -03}
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):6839
                                                                                                                                                                                                            Entropy (8bit):3.565857684485945
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:9OgtbdF7TI7nYUYXg9W/OAcv7vuShytWi0PnvLrqPoKR2XszXckXtogYN4Ezlk0X:PJr9Q7TMq+ML
                                                                                                                                                                                                            MD5:D1BF579FE8123E8EE9248A51E794CC78
                                                                                                                                                                                                            SHA1:BF9CB9BED143C7529719E0C1E2F88BE1AC9F8DD4
                                                                                                                                                                                                            SHA-256:158BD9E4EB0B9DFF3F2D3E2DBA72F217B73423012DD33A688FD57852124E884A
                                                                                                                                                                                                            SHA-512:78192AC38912021F848592D0B208CB122EFFC6DDB326540FFAADA4FD3322B7A442FD1116F408D64B8788520B46545DFAE571EA42046D62A282A97ECCD5663655
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Scoresbysund) {.. {-9223372036854775808 -5272 0 LMT}.. {-1686090728 -7200 0 -02}.. {323841600 -3600 0 -01}.. {338961600 -7200 0 -02}.. {354679200 0 0 +00}.. {370400400 -3600 0 -01}.. {386125200 0 1 +00}.. {401850000 -3600 0 -01}.. {417574800 0 1 +00}.. {433299600 -3600 0 -01}.. {449024400 0 1 +00}.. {465354000 -3600 0 -01}.. {481078800 0 1 +00}.. {496803600 -3600 0 -01}.. {512528400 0 1 +00}.. {528253200 -3600 0 -01}.. {543978000 0 1 +00}.. {559702800 -3600 0 -01}.. {575427600 0 1 +00}.. {591152400 -3600 0 -01}.. {606877200 0 1 +00}.. {622602000 -3600 0 -01}.. {638326800 0 1 +00}.. {654656400 -3600 0 -01}.. {670381200 0 1 +00}.. {686106000 -3600 0 -01}.. {701830800 0 1 +00}.. {717555600 -3600 0 -01}.. {733280400 0 1 +00}.. {749005200 -3600 0 -01}.. {764730000 0 1 +00}.. {780454800 -3600 0 -01}.. {796179600 0 1 +00}.. {8
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):187
                                                                                                                                                                                                            Entropy (8bit):4.888573146674231
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx06RGFfXHAIg206RORL/2IAcGEtOFBx+IAcGE6RB:SlSWB9vsM3y7+SPHAIgp+ON/290tO09Z
                                                                                                                                                                                                            MD5:2FF74846ADF32AA3A9418376775B7F25
                                                                                                                                                                                                            SHA1:130D7548DFFEBCE74969962E335B40299D7C5C54
                                                                                                                                                                                                            SHA-256:BF4FAB3AE72CC7FA4F9E34CF0551A85C54A084CD826DF5D9CC684DE6188E84DB
                                                                                                                                                                                                            SHA-512:9E52C017E595EEF1C68C8A1943416A9109D7DB4C32D25F83D05213C4200869A50E2E726894E39ECA364C558BB7F5566F6150CEA5D3CB14D1DEAE28C3D8C810E0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Denver)]} {.. LoadTimeZoneFile America/Denver..}..set TZData(:America/Shiprock) $TZData(:America/Denver)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8651
                                                                                                                                                                                                            Entropy (8bit):3.959337076866423
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:IGCG0hPC9+j1giaJCUbtp0nFI+g/iexpCVaBnNnt61nctE1:I5G0A9DiaJCUbPI+D/iMpCIBSuk
                                                                                                                                                                                                            MD5:7CCB6902749079A0496F1E2E2137448E
                                                                                                                                                                                                            SHA1:3D0ED7BF1C26659F6794E26AE3869F8AB925B6DF
                                                                                                                                                                                                            SHA-256:ABB08435CAE80119068A85984BFFE9C1596F4FB90F07CC01124C907E5162C189
                                                                                                                                                                                                            SHA-512:0B5B2DCECC70F357DB6D590AB63E600C572EA6B3F430565EFEB29777B1901AAC55CACC7495C668F739201076B180402141BC1B2ED2357E9B4DFBABF3B122AB44
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Sitka) {.. {-9223372036854775808 53927 0 LMT}.. {-3225223727 -32473 0 LMT}.. {-2188954727 -28800 0 PST}.. {-883584000 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-757353600 -28800 0 PST}.. {-31507200 -28800 0 PST}.. {-21477600 -25200 1 PDT}.. {-5756400 -28800 0 PST}.. {9972000 -25200 1 PDT}.. {25693200 -28800 0 PST}.. {41421600 -25200 1 PDT}.. {57747600 -28800 0 PST}.. {73476000 -25200 1 PDT}.. {89197200 -28800 0 PST}.. {104925600 -25200 1 PDT}.. {120646800 -28800 0 PST}.. {126698400 -25200 1 PDT}.. {152096400 -28800 0 PST}.. {162381600 -25200 1 PDT}.. {183546000 -28800 0 PST}.. {199274400 -25200 1 PDT}.. {215600400 -28800 0 PST}.. {230724000 -25200 1 PDT}.. {247050000 -28800 0 PST}.. {262778400 -25200 1 PDT}.. {278499600 -28800 0 PST}.. {294228000 -25200 1 PDT}.. {3099492
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):207
                                                                                                                                                                                                            Entropy (8bit):4.932842207797733
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290txP90ppv:MByMYbpwt2907P90b
                                                                                                                                                                                                            MD5:CBFA61DBF6F7459CF8D517402B29998E
                                                                                                                                                                                                            SHA1:A562B29C9470DBD25480966B0462433124BA4164
                                                                                                                                                                                                            SHA-256:353CDBD46BA8C7472A93E9E800A69105801F6784B22EC50A59294CDC3BE40E18
                                                                                                                                                                                                            SHA-512:00B333EAA2C32EDDA8F06457AD0E10013A0147B20F504F4F1096656F731A7C1896D5ABD83E7EDBD5D4E7DA587EE9BFA796539EB1E9F4056D75D1FDF203251150
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/St_Barthelemy) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):11289
                                                                                                                                                                                                            Entropy (8bit):3.8713946894934614
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:PmxVjd1cO8f7/EjUhSicN6zvfwb+8YbTE0M0J:PmrcOI7/EjiskY01J
                                                                                                                                                                                                            MD5:8F068899DA75663128320633E1881333
                                                                                                                                                                                                            SHA1:E9161B45D7B11A2DD6E9679AC080E84EC51561E3
                                                                                                                                                                                                            SHA-256:E2917204B0C843C32051BB371CF6D0AD272C02720B9C0D913AC072C8ABE1EC64
                                                                                                                                                                                                            SHA-512:2200E9B9D816157330ADAEA7383635876E5A37329B1AF9613D38BCFBE8143835837A25132A94E44A61DB8058ED98B1A33F295EA64BC1F4CE30966D52BB0B673D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/St_Johns) {.. {-9223372036854775808 -12652 0 LMT}.. {-2713897748 -12652 0 NST}.. {-1664130548 -9052 1 NDT}.. {-1650137348 -12652 0 NST}.. {-1640982548 -12652 0 NST}.. {-1632076148 -9052 1 NDT}.. {-1615145348 -12652 0 NST}.. {-1609446548 -12652 0 NST}.. {-1598650148 -9052 1 NDT}.. {-1590100148 -12652 0 NST}.. {-1567286948 -9052 1 NDT}.. {-1551565748 -12652 0 NST}.. {-1535837348 -9052 1 NDT}.. {-1520116148 -12652 0 NST}.. {-1503782948 -9052 1 NDT}.. {-1488666548 -12652 0 NST}.. {-1472333348 -9052 1 NDT}.. {-1457216948 -12652 0 NST}.. {-1440883748 -9052 1 NDT}.. {-1425767348 -12652 0 NST}.. {-1409434148 -9052 1 NDT}.. {-1394317748 -12652 0 NST}.. {-1377984548 -9052 1 NDT}.. {-1362263348 -12652 0 NST}.. {-1346534948 -9052 1 NDT}.. {-1330813748 -12652 0 NST}.. {-1314480548 -9052 1 NDT}.. {-1299364148 -12652 0 NST}.. {-1283030948 -9052 1 ND
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):202
                                                                                                                                                                                                            Entropy (8bit):4.907031043022691
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290tMp490ppv:MByMYbpwt290g490b
                                                                                                                                                                                                            MD5:D521F2D9B28C5374FC3BD540C6B6F40D
                                                                                                                                                                                                            SHA1:39A3D86CB71F742F33B02F50B316638815B3CD4E
                                                                                                                                                                                                            SHA-256:EDB9457A7C64E47062BDC6458FD3BCFCD6C37820F1A2BC89DFE99ED77355011F
                                                                                                                                                                                                            SHA-512:05C1BE92550A962904ED3BB7DECCAC16FCB54D258F24F2AEDF755FCC44E4FEF5F86AB663945809F5D7AFA64178E807BBDAE77048270ED516DFF2C7720A746D52
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/St_Kitts) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):202
                                                                                                                                                                                                            Entropy (8bit):4.9037013606484905
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290tY90ppv:MByMYbpwt290a90b
                                                                                                                                                                                                            MD5:9392E5A7BD198B0308F9271E4C7E59B2
                                                                                                                                                                                                            SHA1:A902440920A0318BC930957C74804A9A51EF7818
                                                                                                                                                                                                            SHA-256:6727A509BB937CB3446D41B57826DE70C7028E96F088AB5B7F803BEAA18279E8
                                                                                                                                                                                                            SHA-512:6DA1EAC390E72905DF1A14D82362B499D20FAD6D85F3DF116AE01E566D5D19C6D16E56DA72C458BB6143345EF45F35A53B245488C641D80BFBA200B16A59719E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/St_Lucia) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):203
                                                                                                                                                                                                            Entropy (8bit):4.919272465019375
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290tXIMFJ490ppv:MByMYbpwt290tJ490b
                                                                                                                                                                                                            MD5:49D0C8DAFCA053C9967EDCC4C0A484B1
                                                                                                                                                                                                            SHA1:7B4999D4B9AD93306BD411DF2946D741EC597770
                                                                                                                                                                                                            SHA-256:974AEED3D79124B50265C83D84F23CBE4F0328D00C75F42DD3ABC5D4C0A78DE1
                                                                                                                                                                                                            SHA-512:378E3657B26C5A039FF82ECCAC7797FF45CBC6479596629B3048164EE4E035F4ECFC557AA9EAF6848E78999B4FF8C63E53C7163BDF6F626ED6111004490D6F80
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/St_Thomas) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):204
                                                                                                                                                                                                            Entropy (8bit):4.909053768717241
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290tzb+Q90ppv:MByMYbpwt290xyQ90b
                                                                                                                                                                                                            MD5:6CFB23E7164605CDE380FB7C4D88DF11
                                                                                                                                                                                                            SHA1:CC513B29AD7B59E600DBCBC97927EB632558F657
                                                                                                                                                                                                            SHA-256:6B19404D295964EF66F47802836BB728FCE8E6481115797C0B5F200C354D7C8A
                                                                                                                                                                                                            SHA-512:728987D0925B6E12E8A220920BEDF94180880E78F3F08F6AC740E6304B22D446846068CEA499F61E7032ADB2E700CE31954921D478C9A8B6CB599E05A6292EA3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/St_Vincent) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):874
                                                                                                                                                                                                            Entropy (8bit):4.253846650171654
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB86290hEbmdHLCvYX4Q19xRv0+RmwPj+uLkQOzL3+ORL4FXgenM7RSslKA1PyKp:5zeOvT4xuyqoYaAxt7l
                                                                                                                                                                                                            MD5:C91F801CC5E9F78B966D1DF2259C38A8
                                                                                                                                                                                                            SHA1:D29C970CBFC74684D46AAAD543B73B520775632C
                                                                                                                                                                                                            SHA-256:939B25C9412B9E25D73F552E87826999FC8C929770E66491D1E4530046D3E758
                                                                                                                                                                                                            SHA-512:093378E61DE9310F9C48170CBB0FDBD3C79E184DA1489F759B20BCE410006A9D5A793C82E79A46E0AFF0DAA47D9DBAFD605959E491BA9ED4E55D26F293642D32
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Swift_Current) {.. {-9223372036854775808 -25880 0 LMT}.. {-2030201320 -25200 0 MST}.. {-1632063600 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-747241200 -21600 0 MDT}.. {-732729600 -25200 0 MST}.. {-715791600 -21600 1 MDT}.. {-702489600 -25200 0 MST}.. {-684342000 -21600 1 MDT}.. {-671040000 -25200 0 MST}.. {-652892400 -21600 1 MDT}.. {-639590400 -25200 0 MST}.. {-631126800 -25200 0 MST}.. {-400086000 -21600 1 MDT}.. {-384364800 -25200 0 MST}.. {-337186800 -21600 1 MDT}.. {-321465600 -25200 0 MST}.. {-305737200 -21600 1 MDT}.. {-292435200 -25200 0 MST}.. {-273682800 -21600 1 MDT}.. {-260985600 -25200 0 MST}.. {73472400 -21600 0 CST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):341
                                                                                                                                                                                                            Entropy (8bit):4.638828647226646
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2903fDm2OHskeoHxbV1ULhgdrV/uF+IcmJ3/uF+ivi9/uF+SNv:MB862903LmdHsVCn1ULSB/uF+QV/uF+q
                                                                                                                                                                                                            MD5:4C4034ABAB9E4804CCB23E51694044C9
                                                                                                                                                                                                            SHA1:7DB24CE83AB2C07E6F6784D27C4E3AC0F149D080
                                                                                                                                                                                                            SHA-256:1F0503579B0DDDBAF88814A278127D9CD7019EDD3C35F4CBFC0EF11C0EDAFE5B
                                                                                                                                                                                                            SHA-512:0BC366CD3AB2E1388D11770DC8DEC1FC94C48FDC846ABB6C487828BF9FF15CD9A1C15B33E08F6E48B7F4A6F2AD1617FF12B359784CA4C32256D72422E6825105
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Tegucigalpa) {.. {-9223372036854775808 -20932 0 LMT}.. {-1538503868 -21600 0 CST}.. {547020000 -18000 1 CDT}.. {559717200 -21600 0 CST}.. {578469600 -18000 1 CDT}.. {591166800 -21600 0 CST}.. {1146981600 -18000 1 CDT}.. {1154926800 -21600 0 CST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):6890
                                                                                                                                                                                                            Entropy (8bit):3.8331465442823704
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:mJInJuFW4ng2CEBJuQaeEy9P19OBYEi/B51B7/Bm6BTd69xK7KjhVbHyR3h1gOZM:miFCC
                                                                                                                                                                                                            MD5:D93B62D5F7EEBC28AC047BED2307CAE8
                                                                                                                                                                                                            SHA1:8B3E02240A01B5AA42D30E86005E880916432227
                                                                                                                                                                                                            SHA-256:7FB0CBB101D3B6FBB6B9DAD5446BBF9E6AEC65EC38472739E604F68F6AA9AB7B
                                                                                                                                                                                                            SHA-512:3648106F4DF84CFD94AAD4E9430F8D3BBCB38A9196DE9A59246DFBBC170FADBF106DD1FD08FE2E4F7319BFFB1C2607E4F5D563C222CED8267483D1A0C388CCE5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Thule) {.. {-9223372036854775808 -16508 0 LMT}.. {-1686079492 -14400 0 AST}.. {670399200 -10800 1 ADT}.. {686120400 -14400 0 AST}.. {701848800 -10800 1 ADT}.. {717570000 -14400 0 AST}.. {733903200 -10800 1 ADT}.. {752043600 -14400 0 AST}.. {765352800 -10800 1 ADT}.. {783493200 -14400 0 AST}.. {796802400 -10800 1 ADT}.. {814942800 -14400 0 AST}.. {828856800 -10800 1 ADT}.. {846392400 -14400 0 AST}.. {860306400 -10800 1 ADT}.. {877842000 -14400 0 AST}.. {891756000 -10800 1 ADT}.. {909291600 -14400 0 AST}.. {923205600 -10800 1 ADT}.. {941346000 -14400 0 AST}.. {954655200 -10800 1 ADT}.. {972795600 -14400 0 AST}.. {986104800 -10800 1 ADT}.. {1004245200 -14400 0 AST}.. {1018159200 -10800 1 ADT}.. {1035694800 -14400 0 AST}.. {1049608800 -10800 1 ADT}.. {1067144400 -14400 0 AST}.. {1081058400 -10800 1 ADT}.. {1099198800 -14400 0 AST}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):193
                                                                                                                                                                                                            Entropy (8bit):4.838326820531248
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7RQtHAIgpRQPN/2903MA90RQk:MByMYzp4t2903MA90D
                                                                                                                                                                                                            MD5:D68B69B05D8743977BA4815B8AFE8E92
                                                                                                                                                                                                            SHA1:364796989B6DD0110F1D85A8844419EB49772EC0
                                                                                                                                                                                                            SHA-256:845101F85A6DAF9DEB58A075473F9E541A0B68461677779B1461DE59E3FA3D18
                                                                                                                                                                                                            SHA-512:DEAA60DDF1521C269D7D386A7FCC40C8FAFB00EEA6764E6B23F4C65B8F6F596B3D5D2D3F6F7B1C22016C530B8789839F8052FDE1C2794C9F9C700C46DC8A3AEE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Toronto)]} {.. LoadTimeZoneFile America/Toronto..}..set TZData(:America/Thunder_Bay) $TZData(:America/Toronto)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8755
                                                                                                                                                                                                            Entropy (8bit):3.8521303835918115
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:CuS6mjvZk53mtw+N6IkWq/WHQlb/RYRWVIKr7cRRL:26jFOzN6IkWq/WHQt/RY4yP
                                                                                                                                                                                                            MD5:2F9983FE6248F3BF18ADE00192F4B458
                                                                                                                                                                                                            SHA1:73F7302C914E442FC50DD4BFF3C57FD310E6455C
                                                                                                                                                                                                            SHA-256:D7C5CB477A591931FF03C794C84EDB2319760C0B70047B325382F211E28648E3
                                                                                                                                                                                                            SHA-512:B1F66008F2B62D4E1B59ED1A78A9E4F5D06BE074EB3B2466BDE3C9ED98DE96AD03FACDB8EDA6EE8F8EE890860DE6011F2BB364DE8C1276B31F37C9C525F4EC3F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Tijuana) {.. {-9223372036854775808 -28084 0 LMT}.. {-1514739600 -25200 0 MST}.. {-1451667600 -28800 0 PST}.. {-1343062800 -25200 0 MST}.. {-1234803600 -28800 0 PST}.. {-1222963200 -25200 1 PDT}.. {-1207242000 -28800 0 PST}.. {-873820800 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-761677200 -28800 0 PST}.. {-686073600 -25200 1 PDT}.. {-661539600 -28800 0 PST}.. {-504892800 -28800 0 PST}.. {-495039600 -25200 1 PDT}.. {-481734000 -28800 0 PST}.. {-463590000 -25200 1 PDT}.. {-450284400 -28800 0 PST}.. {-431535600 -25200 1 PDT}.. {-418230000 -28800 0 PST}.. {-400086000 -25200 1 PDT}.. {-386780400 -28800 0 PST}.. {-368636400 -25200 1 PDT}.. {-355330800 -28800 0 PST}.. {-337186800 -25200 1 PDT}.. {-323881200 -28800 0 PST}.. {-305737200 -25200 1 PDT}.. {-292431600 -28800 0 PST}.. {-283968000 -28800 0 PST}.. {189331200 -28800 0 PST}.. {19
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):11248
                                                                                                                                                                                                            Entropy (8bit):3.8061065077303926
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:lBew85RnK1a8phYBNXEtCt/cL1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:lBq5RnK1a8phYTXEItON0HY2iUmUFLqU
                                                                                                                                                                                                            MD5:0D906EC3F658730131A65C5A770D885F
                                                                                                                                                                                                            SHA1:BFA72C43BCE0F37F795E974457FBE4A664687B38
                                                                                                                                                                                                            SHA-256:5A98C6BEDDA4DF608051D702A8E037093A8068E1B85F8F55D42B4468F45662A5
                                                                                                                                                                                                            SHA-512:CC634DAF4EEC7F57E3AB0C20D891380A7F96DE79602A7B57C6C2BF229DD76A69B399A689FA6D0675380B1432C2115B0C8577DC49C3C9E567A08CAD6FCC3599BC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Toronto) {.. {-9223372036854775808 -19052 0 LMT}.. {-2366736148 -18000 0 EST}.. {-1632070800 -14400 1 EDT}.. {-1615140000 -18000 0 EST}.. {-1609441200 -18000 0 EST}.. {-1601753400 -14400 1 EDT}.. {-1583697600 -18000 0 EST}.. {-1567357200 -14400 1 EDT}.. {-1554667200 -18000 0 EST}.. {-1534698000 -14400 1 EDT}.. {-1524074400 -18000 0 EST}.. {-1503248400 -14400 1 EDT}.. {-1492365600 -18000 0 EST}.. {-1471798800 -14400 1 EDT}.. {-1460916000 -18000 0 EST}.. {-1440954000 -14400 1 EDT}.. {-1428861600 -18000 0 EST}.. {-1409504400 -14400 1 EDT}.. {-1397412000 -18000 0 EST}.. {-1378054800 -14400 1 EDT}.. {-1365962400 -18000 0 EST}.. {-1346605200 -14400 1 EDT}.. {-1333908000 -18000 0 EST}.. {-1315155600 -14400 1 EDT}.. {-1301853600 -18000 0 EST}.. {-1283706000 -14400 1 EDT}.. {-1270404000 -18000 0 EST}.. {-1252256400 -14400 1 EDT}.. {-1238954400
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):201
                                                                                                                                                                                                            Entropy (8bit):4.864308662322047
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290RRKl290ppv:MByMYbpwt290V90b
                                                                                                                                                                                                            MD5:21D152A2359A4EFDE6DCC304F16096F3
                                                                                                                                                                                                            SHA1:961B3CFB351615604981114A115D396D1F2006A2
                                                                                                                                                                                                            SHA-256:46A236EC38F3A122D414208328A462B2A937392ECC6C55F673FB7A402F118D96
                                                                                                                                                                                                            SHA-512:04A2AD6DDC2E7B0D3F95DA1C731FF553F8CBC0DD6BDFC36FB2EDCE755612103E3B4EA6F3AB7FE63CA60976538EFABF40827539DFC35B7E83129BD48471FE514B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Tortola) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):9815
                                                                                                                                                                                                            Entropy (8bit):3.8481935495337356
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:sOR864CjSAG5a9bFzN6IkWq/WHQt/RY4yP:sO664CjSAGYbGBt/M
                                                                                                                                                                                                            MD5:9423BC81647BC4C37888860CE0518BBB
                                                                                                                                                                                                            SHA1:37E6E6554576D1DD36C3494EAF0BD169003D870D
                                                                                                                                                                                                            SHA-256:00B5FB8F37DFF43925C501AEAB039F39F058E002572C4203286317046CC1D700
                                                                                                                                                                                                            SHA-512:1830CA2B62B7CA6EEB5A924D2148925DF7DD87A7B93B21F4F023E4678EF42DC20BFF57F702923E10F4382FE6757323D21414D094E99FEEB43316DE4A7E5A909E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Vancouver) {.. {-9223372036854775808 -29548 0 LMT}.. {-2713880852 -28800 0 PST}.. {-1632060000 -25200 1 PDT}.. {-1615129200 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-747237600 -25200 1 PDT}.. {-733935600 -28800 0 PST}.. {-715788000 -25200 1 PDT}.. {-702486000 -28800 0 PST}.. {-684338400 -25200 1 PDT}.. {-671036400 -28800 0 PST}.. {-652888800 -25200 1 PDT}.. {-639586800 -28800 0 PST}.. {-620834400 -25200 1 PDT}.. {-608137200 -28800 0 PST}.. {-589384800 -25200 1 PDT}.. {-576082800 -28800 0 PST}.. {-557935200 -25200 1 PDT}.. {-544633200 -28800 0 PST}.. {-526485600 -25200 1 PDT}.. {-513183600 -28800 0 PST}.. {-495036000 -25200 1 PDT}.. {-481734000 -28800 0 PST}.. {-463586400 -25200 1 PDT}.. {-450284400 -28800 0 PST}.. {-431532000 -25200 1 PDT}.. {-418230000 -28800 0 PST}.. {-4
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):200
                                                                                                                                                                                                            Entropy (8bit):4.914983069791254
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7p5oeSHAIgppON/290RXgr490ppv:MByMYbpwt290xg090b
                                                                                                                                                                                                            MD5:9F7DA15BE387B8F7DEC5DFFE069F3505
                                                                                                                                                                                                            SHA1:D298B963B0048E9ECA3BC7B85248506AB1388479
                                                                                                                                                                                                            SHA-256:561D9D04B0CE0F96A9C351C7D5C30AA1D5A42A3D70066CD9AF0DA6CBC5388DBE
                                                                                                                                                                                                            SHA-512:606C2A918633C74BD2954D39B00EFA2CD9DA852BC7034F129A04258A65DC74942FA0826E9BC6E4433926E7F1375612554B04845077E434D0CD3BD15832DC6B95
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:America/Virgin) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2971
                                                                                                                                                                                                            Entropy (8bit):3.9652694533791917
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5CeFvmpn4nRfngnSSXRwEg7MkwY7Twbg7Uwr70vwHg7b6wa7gAHwc7/wzZg7ywJP:5BmCKpj/AOZFCARCeQbvb5wxMN6Ix
                                                                                                                                                                                                            MD5:2F2D39B5FB844E170FA7B6AF11B948CA
                                                                                                                                                                                                            SHA1:3D89672134D979FCF65225A58249380D9C8A4A65
                                                                                                                                                                                                            SHA-256:8E0BC71BD7146145DDE3C064AE205DF08124FE2402853A9655B0EB799E90F31F
                                                                                                                                                                                                            SHA-512:6C046D1133C8CCF697C8FB553A1F539948F71FA80BA447B87AA8D1D1D7113B32A6B764C5C1734C615319A27961B6116FCA087EB571869119BE87656FCA351498
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Whitehorse) {.. {-9223372036854775808 -32412 0 LMT}.. {-2188997988 -32400 0 YST}.. {-1632056400 -28800 1 YDT}.. {-1615125600 -32400 0 YST}.. {-1596978000 -28800 1 YDT}.. {-1583164800 -32400 0 YST}.. {-880203600 -28800 1 YWT}.. {-769395600 -28800 1 YPT}.. {-765381600 -32400 0 YST}.. {-147884400 -25200 1 YDDT}.. {-131554800 -32400 0 YST}.. {315561600 -28800 0 PST}.. {325677600 -25200 1 PDT}.. {341398800 -28800 0 PST}.. {357127200 -25200 1 PDT}.. {372848400 -28800 0 PST}.. {388576800 -25200 1 PDT}.. {404902800 -28800 0 PST}.. {420026400 -25200 1 PDT}.. {436352400 -28800 0 PST}.. {452080800 -25200 1 PDT}.. {467802000 -28800 0 PST}.. {483530400 -25200 1 PDT}.. {499251600 -28800 0 PST}.. {514980000 -25200 1 PDT}.. {530701200 -28800 0 PST}.. {544615200 -25200 1 PDT}.. {562150800 -28800 0 PST}.. {576064800 -25200 1 PDT}.. {594205200 -28800
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):9695
                                                                                                                                                                                                            Entropy (8bit):3.8209220355628766
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:pOEhc8/rvNZONqXXyIjNA604qSScBgN+4ctDzIVQ/c/3hNxTh:pY8DvbO+A604qSBgI7DBch
                                                                                                                                                                                                            MD5:E8DB00D2B99B308018F4F5E48AC47C3A
                                                                                                                                                                                                            SHA1:8841467CB264DC9F87FABAADBE90EE2C8DACC80F
                                                                                                                                                                                                            SHA-256:F3FC5F6D93D1D9EB0F3DED33873F33C47F841797D96439966F8E0A5A189941FA
                                                                                                                                                                                                            SHA-512:5D684B07332ED53F9F8CB71FFF3B6D0F848426A5E4D9E7DA84E49E358C666F1C3BB9CF21352D939B35B558FC691839E24BC84656317F73C768B474AF5AC480EB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Winnipeg) {.. {-9223372036854775808 -23316 0 LMT}.. {-2602258284 -21600 0 CST}.. {-1694368800 -18000 1 CDT}.. {-1681671600 -21600 0 CST}.. {-1632067200 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1029686400 -18000 1 CDT}.. {-1018198800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-746035200 -18000 1 CDT}.. {-732733200 -21600 0 CST}.. {-715795200 -18000 1 CDT}.. {-702493200 -21600 0 CST}.. {-684345600 -18000 1 CDT}.. {-671043600 -21600 0 CST}.. {-652896000 -18000 1 CDT}.. {-639594000 -21600 0 CST}.. {-620755200 -18000 1 CDT}.. {-607626000 -21600 0 CST}.. {-589392000 -18000 1 CDT}.. {-576090000 -21600 0 CST}.. {-557942400 -18000 1 CDT}.. {-544640400 -21600 0 CST}.. {-526492800 -18000 1 CDT}.. {-513190800 -21600 0 CST}.. {-495043200 -18000 1 CDT}.. {-481741200 -21600 0 CST}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8683
                                                                                                                                                                                                            Entropy (8bit):3.957710943557426
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:po1acs6yyyxC9+j1giaJCUbtp0nFI+g/iexpCVaBnNnt61nctE1:p4acsW9DiaJCUbPI+D/iMpCIBSuk
                                                                                                                                                                                                            MD5:18EC35FCEC15CE9304818E22222411EF
                                                                                                                                                                                                            SHA1:F4A04B3E2B5F55C9582F578C3142E706C4EB6BD6
                                                                                                                                                                                                            SHA-256:79B44F245D86A4EC299D1A9A2EDB2AB92D50AB5A7C1C03759D283AC4070F9005
                                                                                                                                                                                                            SHA-512:40AC47AC278DF22C7ECFF568456E7C3767B38701B9A2E2639C2201DC53CDD794CF7521BCB773A8AF2A8D4A034D3BBD35BF9788FB5B4E4D51A7A139B3B3353479
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Yakutat) {.. {-9223372036854775808 52865 0 LMT}.. {-3225223727 -33535 0 LMT}.. {-2188953665 -32400 0 YST}.. {-883580400 -32400 0 YST}.. {-880203600 -28800 1 YWT}.. {-769395600 -28800 1 YPT}.. {-765381600 -32400 0 YST}.. {-757350000 -32400 0 YST}.. {-31503600 -32400 0 YST}.. {-21474000 -28800 1 YDT}.. {-5752800 -32400 0 YST}.. {9975600 -28800 1 YDT}.. {25696800 -32400 0 YST}.. {41425200 -28800 1 YDT}.. {57751200 -32400 0 YST}.. {73479600 -28800 1 YDT}.. {89200800 -32400 0 YST}.. {104929200 -28800 1 YDT}.. {120650400 -32400 0 YST}.. {126702000 -28800 1 YDT}.. {152100000 -32400 0 YST}.. {162385200 -28800 1 YDT}.. {183549600 -32400 0 YST}.. {199278000 -28800 1 YDT}.. {215604000 -32400 0 YST}.. {230727600 -28800 1 YDT}.. {247053600 -32400 0 YST}.. {262782000 -28800 1 YDT}.. {278503200 -32400 0 YST}.. {294231600 -28800 1 YDT}.. {30995
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7737
                                                                                                                                                                                                            Entropy (8bit):3.8656193813344064
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:42GaLV911sF7Lv/PCewtA8CzSPyDLbrcUia:uPlLv/PCenJzS6cy
                                                                                                                                                                                                            MD5:A7606AE597027C26BC90702B2BCC80E9
                                                                                                                                                                                                            SHA1:7B2AB2E0A23B8D770D1305A171DBCCE2D471EF2F
                                                                                                                                                                                                            SHA-256:B33838F12640C64BA4F10F50657EC4D8D5B30FD226DA4ACA21B169B53AD30576
                                                                                                                                                                                                            SHA-512:B18711B4110D6DB0CC7A6EF66639E1B38323F0B61DA4F5287A51BC9EC8534133568C6D3E4F18F6328564DAD291E0CA707768DE4478DD502A40FFD189C08114A1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:America/Yellowknife) {.. {-9223372036854775808 0 0 -00}.. {-1104537600 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-147891600 -18000 1 MDDT}.. {-131562000 -25200 0 MST}.. {315558000 -25200 0 MST}.. {325674000 -21600 1 MDT}.. {341395200 -25200 0 MST}.. {357123600 -21600 1 MDT}.. {372844800 -25200 0 MST}.. {388573200 -21600 1 MDT}.. {404899200 -25200 0 MST}.. {420022800 -21600 1 MDT}.. {436348800 -25200 0 MST}.. {452077200 -21600 1 MDT}.. {467798400 -25200 0 MST}.. {483526800 -21600 1 MDT}.. {499248000 -25200 0 MST}.. {514976400 -21600 1 MDT}.. {530697600 -25200 0 MST}.. {544611600 -21600 1 MDT}.. {562147200 -25200 0 MST}.. {576061200 -21600 1 MDT}.. {594201600 -25200 0 MST}.. {607510800 -21600 1 MDT}.. {625651200 -25200 0 MST}.. {638960400 -21600 1 MDT}.. {657100800 -25200 0 MST}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):478
                                                                                                                                                                                                            Entropy (8bit):4.205595904143294
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2L09xSDm2OHE5QMFUH+KNUoTVsBEE0ZZICxZbDtVby:MB862LcUmdHE5QMFi+KdTVPZIwXDy
                                                                                                                                                                                                            MD5:7D8132A23238C14CCEDD520BBEB49F77
                                                                                                                                                                                                            SHA1:A8BAE9269DAA2AC535B292E1AE8632B451A0BBA5
                                                                                                                                                                                                            SHA-256:04247ACB2B4FA126D13F4573FF74D15A89CF42B2C5CD7E688D5BB1C1FD3972BF
                                                                                                                                                                                                            SHA-512:74FCB14037B0AE11A95B036791D69037590F8EC7F09D90A866E6A6CAAD6D58E4EC3723A3BB356FBF0E25ED1239A5820A8513EBF6653578E4BFB8988D6D20EF13
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Casey) {.. {-9223372036854775808 0 0 -00}.. {-31536000 28800 0 +08}.. {1255802400 39600 0 +11}.. {1267714800 28800 0 +08}.. {1319738400 39600 0 +11}.. {1329843600 28800 0 +08}.. {1477065600 39600 0 +11}.. {1520701200 28800 0 +08}.. {1538856000 39600 0 +11}.. {1552752000 28800 0 +08}.. {1570129200 39600 0 +11}.. {1583596800 28800 0 +08}.. {1601740860 39600 0 +11}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):324
                                                                                                                                                                                                            Entropy (8bit):4.360007144607037
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2L0mDm2OHEfwz0/MVSYyF/KZ7VoX/MVSYyF/VpVQVF9RXhNXSMVSYy6:MB862LVmdHEIjsF/KZOksF/Vp6v9RRFl
                                                                                                                                                                                                            MD5:97AA556F7EF06786B76316133794F4E9
                                                                                                                                                                                                            SHA1:B3CDA284DE80987B954E2CC9BFA3ED33462CDD4F
                                                                                                                                                                                                            SHA-256:2F36D2E13D7E251322B7A7B30F39645393525CEB49A2B5C26F27797F2AAF4D7F
                                                                                                                                                                                                            SHA-512:14C6F17252C2AC89D86FE00BD8A8934D627C85478B0AB08AB6237988922D18616B00878498FFFC0E1978308BC6D775E2DC3ADCEF827AB0A06B214BE4DDABAB52
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Davis) {.. {-9223372036854775808 0 0 -00}.. {-409190400 25200 0 +07}.. {-163062000 0 0 -00}.. {-28857600 25200 0 +07}.. {1255806000 18000 0 +05}.. {1268251200 25200 0 +07}.. {1319742000 18000 0 +05}.. {1329854400 25200 0 +07}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):214
                                                                                                                                                                                                            Entropy (8bit):4.938579775653117
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3yci/452HAIgObi/4oA6N/2L0/3Zp5/4pv:MByMdNXiU5t2Lkwv
                                                                                                                                                                                                            MD5:CC22302B9FAE52E36A2A35C0361E774B
                                                                                                                                                                                                            SHA1:45CFD95A5821C4C4FDF2E1519F08029FF0BE664B
                                                                                                                                                                                                            SHA-256:96F2AB9A9FFCD10598FDF105F68460CC4B4EBC1F18054D1BC8E39DF6AD24D1AC
                                                                                                                                                                                                            SHA-512:FC9084D7B16EAA985681762F2658D32C77EE186D8D3C7225093CC5CB4A6AEB74A3D0A41A904EB6C8AEF7DB110A89497BAFAF811BBC26103F96E5E1D4D4E1002A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Port_Moresby)]} {.. LoadTimeZoneFile Pacific/Port_Moresby..}..set TZData(:Antarctica/DumontDUrville) $TZData(:Pacific/Port_Moresby)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8447
                                                                                                                                                                                                            Entropy (8bit):3.850137279218428
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:s1qigkx6WsYyS391QiAmcO38EJ8i/V9cYgCqMEjKeIZ3wQb25Ly04:s1q05h1QiAmcOM6e0pj
                                                                                                                                                                                                            MD5:81C612A1544910544173687C416841C6
                                                                                                                                                                                                            SHA1:4A707B403F0B9556A3D3D50B08BE0F56660F3F0B
                                                                                                                                                                                                            SHA-256:C4EA7F1C0B5A0FAE653419F1C6D058BDDD745A3CDBA11900005C157DF23DDC01
                                                                                                                                                                                                            SHA-512:122E2DC3D8D61CCDB83E03C9487DD29AABE7AB3F71FE4F6315209AF0BBCFD01FBDC3A1E3F6D910FB0D690378DF852170A9819D8C1EF96BE6BC8C0811BFB453A9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Macquarie) {.. {-9223372036854775808 0 0 -00}.. {-2214259200 36000 0 AEST}.. {-1680508800 39600 1 AEDT}.. {-1669892400 39600 0 AEDT}.. {-1665388800 36000 0 AEST}.. {-1601719200 0 0 -00}.. {-94730400 36000 0 AEST}.. {-71136000 39600 1 AEDT}.. {-55411200 36000 0 AEST}.. {-37267200 39600 1 AEDT}.. {-25776000 36000 0 AEST}.. {-5817600 39600 1 AEDT}.. {5673600 36000 0 AEST}.. {25632000 39600 1 AEDT}.. {37728000 36000 0 AEST}.. {57686400 39600 1 AEDT}.. {67968000 36000 0 AEST}.. {89136000 39600 1 AEDT}.. {100022400 36000 0 AEST}.. {120585600 39600 1 AEDT}.. {131472000 36000 0 AEST}.. {152035200 39600 1 AEDT}.. {162921600 36000 0 AEST}.. {183484800 39600 1 AEDT}.. {194976000 36000 0 AEST}.. {215539200 39600 1 AEDT}.. {226425600 36000 0 AEST}.. {246988800 39600 1 AEDT}.. {257875200 36000 0 AEST}.. {278438400 39600 1 AEDT}.. {28932480
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):180
                                                                                                                                                                                                            Entropy (8bit):4.7511104559982
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/2L0GRHEzyeyFNMXGm2OHvavFeVU/VPKVVFSTVF9svUX0VQr:SlSWB9eg/2L0zyfXDm2OHEVy/Ur9s/Vg
                                                                                                                                                                                                            MD5:7A2AD9BD8F8DEE5C600CABF2D5E9D07B
                                                                                                                                                                                                            SHA1:CF5D230A29946B7FA3ECD8EB99F1EF1BF0FA5B50
                                                                                                                                                                                                            SHA-256:ACA533B8BC82296373EDEC82F6E0AA45A34D817C7C18FF5E8E94B81C0BD30259
                                                                                                                                                                                                            SHA-512:95F8FA68735E88AB15C403191928FA4AA5D1628453BE64B87EE7E8DF9F35FB5DA74A3CED5F5289A13D84A8A12BBB86734E578059CA8B6405399CFF5E33C9384C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Mawson) {.. {-9223372036854775808 0 0 -00}.. {-501206400 21600 0 +06}.. {1255809600 18000 0 +05}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):195
                                                                                                                                                                                                            Entropy (8bit):4.880387042335617
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3ycqXHAIgObOvRN/2L0z6/fy:MByMdTiYt2LrK
                                                                                                                                                                                                            MD5:88EE32AE5C538AEBFDE2D1D944ED5B2B
                                                                                                                                                                                                            SHA1:55E7234E6FFF298182A6C8889A9F506CDCE7C959
                                                                                                                                                                                                            SHA-256:E9D99293C5B275D8E0D7B066084177EDF670D5B52B81E87608BAB02025F33155
                                                                                                                                                                                                            SHA-512:45A3EA146CA719BA6F22E99EAA57AC1DED1C762E19BDFBA176E5FEAC36EC58586F771572DD16ACE09E660F97DEB91A701BA1B1F1AEF3BD8688F3451C0772420A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Auckland)]} {.. LoadTimeZoneFile Pacific/Auckland..}..set TZData(:Antarctica/McMurdo) $TZData(:Pacific/Auckland)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2613
                                                                                                                                                                                                            Entropy (8bit):3.6082359166067905
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5fzJS6S4wRSenSOaf7HSKSkSqS7STslSmSMSCSxygSiXS/SrS+S9SfShS7SoSlSL:jdeRtnxaf7HlPlgiot7JC/Xk8NWse4rf
                                                                                                                                                                                                            MD5:BDFA5908E735F866FEC16F6B481AD385
                                                                                                                                                                                                            SHA1:524AEE21BB97D923A8812A5722AF2FEA43B4D971
                                                                                                                                                                                                            SHA-256:1637381A20E9D5C6A530F110BDB08D9515E675C9206F000407D8511074948E61
                                                                                                                                                                                                            SHA-512:3D65C7941BA15A698264848F9B6F43ED5B63D4CF86D495334E8E1DC381D63435E9424BBBC389229693D20044FDB8425A7CC805AB5EA055F59D3E0DD4C7AC2A28
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Palmer) {.. {-9223372036854775808 0 0 -00}.. {-157766400 -14400 0 -04}.. {-152654400 -14400 0 -04}.. {-132955200 -10800 1 -04}.. {-121122000 -14400 0 -04}.. {-101419200 -10800 1 -04}.. {-86821200 -14400 0 -04}.. {-71092800 -10800 1 -04}.. {-54766800 -14400 0 -04}.. {-39038400 -10800 1 -04}.. {-23317200 -14400 0 -04}.. {-7588800 -10800 0 -03}.. {128142000 -7200 1 -03}.. {136605600 -10800 0 -03}.. {389070000 -14400 0 -04}.. {403070400 -10800 1 -04}.. {416372400 -14400 0 -04}.. {434520000 -10800 1 -04}.. {447822000 -14400 0 -04}.. {466574400 -10800 1 -04}.. {479271600 -14400 0 -04}.. {498024000 -10800 1 -04}.. {510721200 -14400 0 -04}.. {529473600 -10800 1 -04}.. {545194800 -14400 0 -04}.. {560923200 -10800 1 -04}.. {574225200 -14400 0 -04}.. {592372800 -10800 1 -04}.. {605674800 -14400 0 -04}.. {624427200 -10800 1 -04}.. {63712
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):151
                                                                                                                                                                                                            Entropy (8bit):4.829975802206526
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/2L0GRHEsKRsMXGm2OHvavFN/H3VVFVGAvFv:SlSWB9eg/2L0rRsDm2OHEN/VVFAKV
                                                                                                                                                                                                            MD5:C330982049AA053DA62B926627D2F2FA
                                                                                                                                                                                                            SHA1:050CE68265F1A183F0173C825AC59EAE8B6AB9EB
                                                                                                                                                                                                            SHA-256:943F10D8E836773F0B7ACD13ED8422C0B27813C7BBE0B09B57697D1D70D21ECE
                                                                                                                                                                                                            SHA-512:DE9953D0E505D6B110C0CC4E756B5B0311646C9CA4703A33B92147D36CFB4C288D73851E6766CE1432F41AB51B5D0A1D58680BDB4E28F067E1D36F670B4A192E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Rothera) {.. {-9223372036854775808 0 0 -00}.. {218246400 -10800 0 -03}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):198
                                                                                                                                                                                                            Entropy (8bit):4.906125935761354
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3ycqXHAIgObOvRN/2L0tlo+ply:MByMdTiYt2LMq+p8
                                                                                                                                                                                                            MD5:8095A3749DBDE05377836D74A4EEFE33
                                                                                                                                                                                                            SHA1:6987CA972B63AE26A65654961588D51D3EF2166C
                                                                                                                                                                                                            SHA-256:88057832175BB642B23FC99F788A2F78A24005CF1F84A7B1B5E8C84FB8F4D4C1
                                                                                                                                                                                                            SHA-512:9066104C9C16D2AB88523D651C74CE268468E093A497D128D0D12A986BD62DBC1388A56ED1737C2AFACF04185CF06FD0EE66797A3390B2F0E1EB08A4D92AAFAD
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Auckland)]} {.. LoadTimeZoneFile Pacific/Auckland..}..set TZData(:Antarctica/South_Pole) $TZData(:Pacific/Auckland)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):178
                                                                                                                                                                                                            Entropy (8bit):4.871844665431957
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8t14XHAIgNsM13oOARL/2L0GRHEtWlFBQWFK81Fn:SlSWB9vsM3yN14HAIgaM1YOAN/2L0tQB
                                                                                                                                                                                                            MD5:CA52057130DCF506D11A7CC069F4FBA3
                                                                                                                                                                                                            SHA1:2C38B7E7872BB41C3569DFCB539C3EC3AAE24FDD
                                                                                                                                                                                                            SHA-256:2488805DE4FEA42305689F679F1AE2D80B1E934E657FEA329AD39A82DAC63022
                                                                                                                                                                                                            SHA-512:B19D409870939C8F0834C6C028239E010EE5128DFA6E97D4903BECA229B04FE530EA376B936767D9BFE21709720C1791289D8E3622B17C18F2680B0670794A02
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Riyadh)]} {.. LoadTimeZoneFile Asia/Riyadh..}..set TZData(:Antarctica/Syowa) $TZData(:Asia/Riyadh)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):5370
                                                                                                                                                                                                            Entropy (8bit):3.5134546899897146
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:YveRdmbxnKIJqU9XThVIsopb8BcrFgoZVlzeEG+PtJ:UeRdmNnKIIajfopb3FVVJ
                                                                                                                                                                                                            MD5:442F495C36B31CA5D7A9BEFF12105AEF
                                                                                                                                                                                                            SHA1:B3F6CA5B4A5756F9B2C09A27198F7A651CC6032D
                                                                                                                                                                                                            SHA-256:6FD5AB8B7B308CDCEA4B747A81D8675988AE218813C91714FC4CA97919CEBEA5
                                                                                                                                                                                                            SHA-512:C6EAECC26D67D218615EBB5602639DAB62A2578BD9683553D765DC1AC5580627D29B6F911388F5F1BFC284278EA4EBECE94630D3C6B95FF9EF93D3D61A3C2028
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Antarctica/Troll) {.. {-9223372036854775808 0 0 -00}.. {1108166400 0 0 +00}.. {1111885200 7200 1 +02}.. {1130634000 0 0 +00}.. {1143334800 7200 1 +02}.. {1162083600 0 0 +00}.. {1174784400 7200 1 +02}.. {1193533200 0 0 +00}.. {1206838800 7200 1 +02}.. {1224982800 0 0 +00}.. {1238288400 7200 1 +02}.. {1256432400 0 0 +00}.. {1269738000 7200 1 +02}.. {1288486800 0 0 +00}.. {1301187600 7200 1 +02}.. {1319936400 0 0 +00}.. {1332637200 7200 1 +02}.. {1351386000 0 0 +00}.. {1364691600 7200 1 +02}.. {1382835600 0 0 +00}.. {1396141200 7200 1 +02}.. {1414285200 0 0 +00}.. {1427590800 7200 1 +02}.. {1445734800 0 0 +00}.. {1459040400 7200 1 +02}.. {1477789200 0 0 +00}.. {1490490000 7200 1 +02}.. {1509238800 0 0 +00}.. {1521939600 7200 1 +02}.. {1540688400 0 0 +00}.. {1553994000 7200 1 +02}.. {1572138000 0 0 +00}.. {1585443600 7200 1 +02}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):179
                                                                                                                                                                                                            Entropy (8bit):4.940298769001579
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8s4YkyXHAIgNrYOARL/2L0GRHEoKcMFeWFKjov:SlSWB9vsM3yMGSHAIgvAN/2L0XcMFewh
                                                                                                                                                                                                            MD5:F61B4D02530B54A8EB1CA7B34BF6D553
                                                                                                                                                                                                            SHA1:EB85E044EF9F7D11310C5EBB8D1D0C49A1E3067F
                                                                                                                                                                                                            SHA-256:1892E98C13AC141C8C92EAB942B073A464BA5E2C000C250F97F860BE6B108127
                                                                                                                                                                                                            SHA-512:E725E909A4056B7E4FADBE66B69E6C4752595F3357E670A7D740A2DA957F2C9502ECA57B9BA874045ED032B8F65A10D11AFAF69EA9673187FD4AE08793492470
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Urumqi)]} {.. LoadTimeZoneFile Asia/Urumqi..}..set TZData(:Antarctica/Vostok) $TZData(:Asia/Urumqi)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):187
                                                                                                                                                                                                            Entropy (8bit):4.947168975083595
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/y+YF3vXHAIgoq8yFRRL/2XbeLo4cA4FH/h8QahV:SlSWB9vsM3ymhVoPHAIgoh6N/2XbUyAH
                                                                                                                                                                                                            MD5:A4F076D7D716467B78EA382FA222CB38
                                                                                                                                                                                                            SHA1:21D7FBA308ADC652F541A0336929B862F7B1BD0B
                                                                                                                                                                                                            SHA-256:25462B656D240DA6B01C1A630FAC04B25DD65C799B659BE1C8BD3AB62610966F
                                                                                                                                                                                                            SHA-512:1B6BD455E533D5BDC7F3506561A9CA804B1F9CA5CC0665AAB0FC083106AB32FF149DD5FFF62EF7BABAD87E3274F264446D492FB8BE160C9C7F281C7060BF1F61
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Berlin)]} {.. LoadTimeZoneFile Europe/Berlin..}..set TZData(:Arctic/Longyearbyen) $TZData(:Europe/Berlin)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):171
                                                                                                                                                                                                            Entropy (8bit):4.829666491766117
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8t14XHAIgNsM13oOARL/2WFK4h4WFK81Fn:SlSWB9vsM3yN14HAIgaM1YOAN/2wKs46
                                                                                                                                                                                                            MD5:60D7F3194F19179E0CF0F561F9C40EE6
                                                                                                                                                                                                            SHA1:B079EC49485CFBFFB7A5BE6149319B75684258E9
                                                                                                                                                                                                            SHA-256:8FCDDB246932BAED880B70C0CA867057E7989AEA55EDDC174430E1055CD1058D
                                                                                                                                                                                                            SHA-512:0BDC86B1D473D4875C6F7C092F955D0999E6C1F2EF83CFC7726A3C5BFEB0F5CB8E00B1F0CBC1F91F806EC635C472927504DF681A32DAC55EF372DA16FEA9EF40
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Riyadh)]} {.. LoadTimeZoneFile Asia/Riyadh..}..set TZData(:Asia/Aden) $TZData(:Asia/Riyadh)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1637
                                                                                                                                                                                                            Entropy (8bit):3.732051305399264
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5qehddmvOt81FCuLqecDngO6jPvTpYy5T4TXvKT10SvPFu+a+CK/Eu3CWuD0Vob1:5YvdJqxiF0rvK50Sv9fGSM
                                                                                                                                                                                                            MD5:D6BCB21F65642F36A159AFD72EC93953
                                                                                                                                                                                                            SHA1:D3E670E579924E6E4F04AB574D48334FF521D8B2
                                                                                                                                                                                                            SHA-256:06DC608C0B8CDD69CCE66A6BF86F141C46DF39CB45312E684E46F19ED8CAFF15
                                                                                                                                                                                                            SHA-512:9A633B629873E5EE5AF923A94865EBE5FD9ECA181B2C47B7368A0828468715E07AD3FD825D5E2312D2D0BA1FA5490E3817C36B6339824C8012A0B75538C4A0DC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Almaty) {.. {-9223372036854775808 18468 0 LMT}.. {-1441170468 18000 0 +05}.. {-1247547600 21600 0 +06}.. {354909600 25200 1 +06}.. {370717200 21600 0 +06}.. {386445600 25200 1 +06}.. {402253200 21600 0 +06}.. {417981600 25200 1 +06}.. {433789200 21600 0 +06}.. {449604000 25200 1 +06}.. {465336000 21600 0 +06}.. {481060800 25200 1 +06}.. {496785600 21600 0 +06}.. {512510400 25200 1 +06}.. {528235200 21600 0 +06}.. {543960000 25200 1 +06}.. {559684800 21600 0 +06}.. {575409600 25200 1 +06}.. {591134400 21600 0 +06}.. {606859200 25200 1 +06}.. {622584000 21600 0 +06}.. {638308800 25200 1 +06}.. {654638400 21600 0 +06}.. {670363200 18000 0 +05}.. {670366800 21600 1 +05}.. {686091600 18000 0 +05}.. {695768400 21600 0 +06}.. {701812800 25200 1 +06}.. {717537600 21600 0 +06}.. {733262400 25200 1 +06}.. {748987200 21600 0 +06}.. {764712
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2682
                                                                                                                                                                                                            Entropy (8bit):3.7873260611521915
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5MUNHl0Nhb9bGA9jSb0PWtsjOuH7Ay2n3yy7QYoTZg703q4oPuJ9/YXjpdaOP9kA:Fz0T52akyId7+xOXdkwqeIFcR
                                                                                                                                                                                                            MD5:7E70BD44FBF5BF70E3C5246D3A83A49B
                                                                                                                                                                                                            SHA1:10A28B0A3189DF347CF9853C024E9467CAC56DBA
                                                                                                                                                                                                            SHA-256:B70AABECACD3F62AF506DF395AB44F47F2CA091522B04EC87AC1407172DD1BFA
                                                                                                                                                                                                            SHA-512:766565F837EB777749B2C8AAE6C73A2274A772CEF12E7C2E30A89809FEF1E9ED6B067DF044A4676AA4BE76A64A904692C3887336BF01BA4D5D9A5020FB792938
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Amman) {.. {-9223372036854775808 8624 0 LMT}.. {-1230776624 7200 0 EET}.. {108165600 10800 1 EEST}.. {118270800 7200 0 EET}.. {136591200 10800 1 EEST}.. {149806800 7200 0 EET}.. {168127200 10800 1 EEST}.. {181342800 7200 0 EET}.. {199749600 10800 1 EEST}.. {215643600 7200 0 EET}.. {231285600 10800 1 EEST}.. {244501200 7200 0 EET}.. {262735200 10800 1 EEST}.. {275950800 7200 0 EET}.. {481154400 10800 1 EEST}.. {496962000 7200 0 EET}.. {512949600 10800 1 EEST}.. {528670800 7200 0 EET}.. {544399200 10800 1 EEST}.. {560120400 7200 0 EET}.. {575848800 10800 1 EEST}.. {592174800 7200 0 EET}.. {610581600 10800 1 EEST}.. {623624400 7200 0 EET}.. {641167200 10800 1 EEST}.. {655074000 7200 0 EET}.. {671839200 10800 1 EEST}.. {685918800 7200 0 EET}.. {702856800 10800 1 EEST}.. {717973200 7200 0 EET}.. {733701600 10800 1 EEST}.. {749422800
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2086
                                                                                                                                                                                                            Entropy (8bit):3.7698340044911616
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5DeEdVrEOeFt7YFpR2kHmxCcUdBbcHDLV2vpXt25A0UeRr9ydzkMfF6USRWk9UuV:5ZejsFLrcZwvJt2F+doTr9Q3G80
                                                                                                                                                                                                            MD5:6EFC35043BDCA4AB61D72E931DB954E6
                                                                                                                                                                                                            SHA1:F0B4E76C154DC773073E41AA8E94030E972A986A
                                                                                                                                                                                                            SHA-256:D9DF64FDA4638F7604624B0F68A885D5ABADB1DE12AF1AF5581C2AF7DD971562
                                                                                                                                                                                                            SHA-512:16AE582B113D6960C73B64620A8AF20F9D436AA4B3EC8E881617AED3389EB4357931882103F162F19EE8202953A7E6FB4FDD6D7760FB7621F4DB9D229AD13F17
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Anadyr) {.. {-9223372036854775808 42596 0 LMT}.. {-1441194596 43200 0 +12}.. {-1247572800 46800 0 +14}.. {354884400 50400 1 +14}.. {370692000 46800 0 +13}.. {386420400 43200 0 +13}.. {386424000 46800 1 +13}.. {402231600 43200 0 +12}.. {417960000 46800 1 +13}.. {433767600 43200 0 +12}.. {449582400 46800 1 +13}.. {465314400 43200 0 +12}.. {481039200 46800 1 +13}.. {496764000 43200 0 +12}.. {512488800 46800 1 +13}.. {528213600 43200 0 +12}.. {543938400 46800 1 +13}.. {559663200 43200 0 +12}.. {575388000 46800 1 +13}.. {591112800 43200 0 +12}.. {606837600 46800 1 +13}.. {622562400 43200 0 +12}.. {638287200 46800 1 +13}.. {654616800 43200 0 +12}.. {670341600 39600 0 +12}.. {670345200 43200 1 +12}.. {686070000 39600 0 +11}.. {695746800 43200 0 +13}.. {701791200 46800 1 +13}.. {717516000 43200 0 +12}.. {733240800 46800 1 +13}.. {748965
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1665
                                                                                                                                                                                                            Entropy (8bit):3.7149890651919644
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5uvFlvNhQQvmRKqv0fvzQIovWdvEGvDaDvs5vZlovKWyvNSvTqvIkhYwr:sFBNKs6b03zB0WJEuDa7sFZiKWaN6TiF
                                                                                                                                                                                                            MD5:A72FB1FE01C93BD7E0A8136635C72639
                                                                                                                                                                                                            SHA1:2383CF839F50784D4BF8B7EDDB324C80E2DDD0DC
                                                                                                                                                                                                            SHA-256:96B510AF9B8C6BC1DFA84E9ED5E072F3FD484EEB66BBEBC7B6826ED859ED9027
                                                                                                                                                                                                            SHA-512:061FECE3C750C0229638DD8AF38FB3E8E48E59E0DE1B13BCFE46483A7A170B71B9BCB0D6F110B6B2EF68510FA940F9066F14CBD59829E222D6644D3657CE1893
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Aqtau) {.. {-9223372036854775808 12064 0 LMT}.. {-1441164064 14400 0 +04}.. {-1247544000 18000 0 +05}.. {370724400 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 14400 0 +04}.. {670370400 18000 1 +04}.. {686095200 14400 0 +04}.. {695772000 18000 0 +05}.. {701816400 21600 1 +05}.. {717541200 18000 0 +05}.. {733266000 21600 1 +05}.. {748990800 18000 0 +05}.. {7647156
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1666
                                                                                                                                                                                                            Entropy (8bit):3.721746335201775
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5FUvalvNhQQvmRKqv0fvzQIovWdvEGvDaDvs5vZlovKWyvNSvTqvIQvyovklvqQR:PwaBNKs6b03zB0WJEuDa7sFZiKWaN6Tt
                                                                                                                                                                                                            MD5:E278B985BD2515DBCAED8CB741BE9208
                                                                                                                                                                                                            SHA1:BC9F5E72C430661D7ED1AF04571CE5D0F73DD18D
                                                                                                                                                                                                            SHA-256:991638FA2AB2A2F7A091A23D78D99306EE73A740F1A03FBAC448EDCAB55A0E38
                                                                                                                                                                                                            SHA-512:9951DB729B837647CC4B3D2E605525DCCBAFFD39D76460331BF62235DCAE5E4470CDA578F940B1739AABFEC55D293FF60D79AE0EFDFE1EB64E84571881FDEA6A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Aqtobe) {.. {-9223372036854775808 13720 0 LMT}.. {-1441165720 14400 0 +04}.. {-1247544000 18000 0 +05}.. {354913200 21600 1 +06}.. {370720800 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 14400 0 +04}.. {670370400 18000 1 +04}.. {686095200 14400 0 +04}.. {695772000 18000 0 +05}.. {701816400 21600 1 +05}.. {717541200 18000 0 +05}.. {733266000 21600 1 +05}.. {748990
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):878
                                                                                                                                                                                                            Entropy (8bit):3.937249024843323
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5ggeRMdIQvNcDvNhQQvmRKqvzQfv7PQIovWxrvEGvDWdDvs5v/RlovKTob3CGcr:5gbkvNSvNhQQvmRKqv0fvzQIovWdvEGD
                                                                                                                                                                                                            MD5:259179C7A1CA04F9F3A373B6C8FCB8C5
                                                                                                                                                                                                            SHA1:D042DF8EFD8EC1473B45B1131BD5EB714F1B2C17
                                                                                                                                                                                                            SHA-256:13745BFA25E6E2D8D0FABAE42CB7C37CF9F974CFB343D4FE84E4E2D64A25926B
                                                                                                                                                                                                            SHA-512:703BEAD5A1E5B3816D98057A08A87C2139F418787F38561FE35175B84E2005365727F85D1B949CC5DF464B207A7D01BB65FB1A632E73DDA523E843B82D76FBBD
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Ashgabat) {.. {-9223372036854775808 14012 0 LMT}.. {-1441166012 14400 0 +04}.. {-1247544000 18000 0 +05}.. {354913200 21600 1 +05}.. {370720800 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 14400 0 +04}.. {670370400 18000 1 +04}.. {686095200 14400 0 +04}.. {695772000 18000 0 +05}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):182
                                                                                                                                                                                                            Entropy (8bit):4.801820439218014
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8xEYM4DyXHAIgN/ZEYovFvWARL/2WFKUNSH+WFKYEQ:SlSWB9vsM3yR+HAIgH8VWAN/2wKUNSeq
                                                                                                                                                                                                            MD5:5193EF7ADB646798801245BC50C8DDA6
                                                                                                                                                                                                            SHA1:83ED851CBC60EFB330A8FC119E1BED5B4C0BA630
                                                                                                                                                                                                            SHA-256:2C752F641B98E3C05B14AE31330D1F198DAA4A7E354BA9670C7754926BFB891A
                                                                                                                                                                                                            SHA-512:E940E1BE67A9AC895F3D060B1CB34797A429147A9DC2AC0F1162D37D86661EF217EDABA720F0AE3796186FE801229210AC785BB4511CBBE5A41791D236101D8C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Ashgabat)]} {.. LoadTimeZoneFile Asia/Ashgabat..}..set TZData(:Asia/Ashkhabad) $TZData(:Asia/Ashgabat)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1666
                                                                                                                                                                                                            Entropy (8bit):3.7265766742957402
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:55TvFlvNhQQvmRKqv0fvzQIovWdvEGvDaDvs5vZlovKWyvNSvTqvIQvyovklvqQJ:XrFBNKs6b03zB0WJEuDa7sFZiKWaN6Tl
                                                                                                                                                                                                            MD5:0236793F90ABC6F68718DDBB44AF5E2F
                                                                                                                                                                                                            SHA1:A5EFAEEF9B9159E748A3FED231F8A978E400482E
                                                                                                                                                                                                            SHA-256:4B7B118E6AE72D41740CF0CB2BD8E970700758DCBC0DD6F298199D841DF8408E
                                                                                                                                                                                                            SHA-512:851C7A9C110790454312BB9C5B5D3C426365EEF4673191B9ABB2E4A32301894C5FB1ADCBE2A4C67BEE416AD63FB8BED85F94EF9BF42473DA4BFFA7824935A1D5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Atyrau) {.. {-9223372036854775808 12464 0 LMT}.. {-1441164464 10800 0 +03}.. {-1247540400 18000 0 +05}.. {370724400 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 14400 0 +04}.. {670370400 18000 1 +04}.. {686095200 14400 0 +04}.. {695772000 18000 0 +05}.. {701816400 21600 1 +05}.. {717541200 18000 0 +05}.. {733266000 21600 1 +05}.. {748990800 18000 0 +05}.. {764715
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1702
                                                                                                                                                                                                            Entropy (8bit):3.7261419515679393
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5/eVvyGiHD6UC4UrUomFMmUZcjbUKNFcUEUvUOpU8MYUWCUlbf/U9bUiUUybUQUF:5m8G9mFdnNF1FfsTuvQXHCe
                                                                                                                                                                                                            MD5:690013310A46BD1AE250A5E019353809
                                                                                                                                                                                                            SHA1:0DF434C7EEB707DC071007FAB112F4DEB37E936F
                                                                                                                                                                                                            SHA-256:D20B75D2604C3B742C1629C5EE02CFF6783E472249982B272B68F2A6DE9BDC38
                                                                                                                                                                                                            SHA-512:FF8C33E55E4F006C38D3FD37A1AD3E1200718CA374ECBEAE8255C7635912F0BB23A59A600BF7130D5660A24C515F726E8440D0D908E560CB59F74059638E6AA2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Baghdad) {.. {-9223372036854775808 10660 0 LMT}.. {-2524532260 10656 0 BMT}.. {-1641005856 10800 0 +03}.. {389048400 14400 0 +03}.. {402264000 10800 0 +03}.. {417906000 14400 1 +03}.. {433800000 10800 0 +03}.. {449614800 14400 1 +03}.. {465422400 10800 0 +03}.. {481150800 14400 1 +03}.. {496792800 10800 0 +03}.. {512517600 14400 1 +03}.. {528242400 10800 0 +03}.. {543967200 14400 1 +03}.. {559692000 10800 0 +03}.. {575416800 14400 1 +03}.. {591141600 10800 0 +03}.. {606866400 14400 1 +03}.. {622591200 10800 0 +03}.. {638316000 14400 1 +03}.. {654645600 10800 0 +03}.. {670464000 14400 1 +03}.. {686275200 10800 0 +03}.. {702086400 14400 1 +03}.. {717897600 10800 0 +03}.. {733622400 14400 1 +03}.. {749433600 10800 0 +03}.. {765158400 14400 1 +03}.. {780969600 10800 0 +03}.. {796694400 14400 1 +03}.. {812505600 10800 0 +03}.. {82831
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):171
                                                                                                                                                                                                            Entropy (8bit):4.784355129067593
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8hkXHAIgNvZORL/2WFKENUKMFB/4WFKKB:SlSWB9vsM3yBkHAIgPON/2wKENUr/4wT
                                                                                                                                                                                                            MD5:1B5E0D449DAEF469D586A853CB3073AD
                                                                                                                                                                                                            SHA1:FD735B0472B31644E787767B82B737CC39EC4175
                                                                                                                                                                                                            SHA-256:3D437037FBF2BBDF969C8E71967080947F24860D431B39F5D8F23151316ABCD5
                                                                                                                                                                                                            SHA-512:2A2DC33D4258A5E1AE59172883F3B11723798ED35CF5AF1B8BA81A8807DC6F8222C8044D82B152EF6AF43E7350FEB2625D4406C6C7DD309CE65810EA3D3286B6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Qatar)]} {.. LoadTimeZoneFile Asia/Qatar..}..set TZData(:Asia/Bahrain) $TZData(:Asia/Qatar)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2149
                                                                                                                                                                                                            Entropy (8bit):3.6155622322573713
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5/eFdqlykbocXcwJUE5iu8JmFebARoc9lVNk7/9bq8dq16b3C9UPBUTIEjvZJ+76:5RsUf8mFpNWFny1ZGMte3aivUKo
                                                                                                                                                                                                            MD5:294DFC98F67AC00A188EC3D3B87C501C
                                                                                                                                                                                                            SHA1:93C434CD9AA170E35AD676C88EE09986A94EC02A
                                                                                                                                                                                                            SHA-256:873E8F08B87610D0DAFE239D32345248A4595C6B13D1DA83EC214D78E88FA12C
                                                                                                                                                                                                            SHA-512:5346082CCA733724C0D2C36B768467E59BA9ED6452B6CF1BA923AF4F0D2BC05C67DB49E804CA81DAD449D30D0835026D708D9AB632D02FDA1EA1A0BF717111DE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Baku) {.. {-9223372036854775808 11964 0 LMT}.. {-1441163964 10800 0 +03}.. {-405140400 14400 0 +04}.. {354916800 18000 1 +04}.. {370724400 14400 0 +04}.. {386452800 18000 1 +04}.. {402260400 14400 0 +04}.. {417988800 18000 1 +04}.. {433796400 14400 0 +04}.. {449611200 18000 1 +04}.. {465343200 14400 0 +04}.. {481068000 18000 1 +04}.. {496792800 14400 0 +04}.. {512517600 18000 1 +04}.. {528242400 14400 0 +04}.. {543967200 18000 1 +04}.. {559692000 14400 0 +04}.. {575416800 18000 1 +04}.. {591141600 14400 0 +04}.. {606866400 18000 1 +04}.. {622591200 14400 0 +04}.. {638316000 18000 1 +04}.. {654645600 14400 0 +04}.. {670370400 10800 0 +03}.. {670374000 14400 1 +03}.. {686098800 10800 0 +03}.. {701823600 14400 1 +03}.. {717548400 14400 0 +04}.. {820440000 14400 0 +04}.. {828234000 18000 1 +05}.. {846378000 14400 0 +04}.. {852062400
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):181
                                                                                                                                                                                                            Entropy (8bit):4.911309754748998
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/2WFKELYOiMXGm2OHB+keoHvZKmrROpDovFFsQ+8EXVeVSYe:SlSWB9eg/2wKELeDm2OHxeoHvZ3FO1og
                                                                                                                                                                                                            MD5:9AC4947AC29C797055B7EBFA4F6AC710
                                                                                                                                                                                                            SHA1:E7758A9A8BFA255F6B2D27F5366D9FE2A26DDF6C
                                                                                                                                                                                                            SHA-256:6E72BA908F250FD45D554A12E3E7B3BD2F1C02A6C2431F806FD2A054F843AA90
                                                                                                                                                                                                            SHA-512:F9D0F0CB7D3726C2AB3B5049429172D9DD4BA21353F6F98570CBA4EE969F7D97BD973CB165AECFF930AFFA8633E8052624D44EE7FB91763681ED3F78A61F4F98
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Bangkok) {.. {-9223372036854775808 24124 0 LMT}.. {-2840164924 24124 0 BMT}.. {-1570084924 25200 0 +07}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2117
                                                                                                                                                                                                            Entropy (8bit):3.7025684250364725
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5VeTtXJfsFN/3sFrOksF/sF7IyksF7FRZsFLsFTsFcsFk73sFK/XCFKTipnFEnsr:5n40yVRB7VfXucdKmtTTDOV
                                                                                                                                                                                                            MD5:6CC13B6910412A3A3D16CA36ADF00352
                                                                                                                                                                                                            SHA1:061CF4A8FEA8C139F50F96E6B6506B50ED3DD792
                                                                                                                                                                                                            SHA-256:992F93A7975F8CD4E94D96B3BA1ECFB3585E52A53F4442A15993402D3F955F66
                                                                                                                                                                                                            SHA-512:4E9750B1C3C0BA4F7922BCBC76276A3E74031D78A98E21DC59F66D6EA8E1B70865BBEB50A6B77EB0423421A18428B97B47412053CE15213128CEED669F4DD6E8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Barnaul) {.. {-9223372036854775808 20100 0 LMT}.. {-1579844100 21600 0 +06}.. {-1247551200 25200 0 +08}.. {354906000 28800 1 +08}.. {370713600 25200 0 +07}.. {386442000 28800 1 +08}.. {402249600 25200 0 +07}.. {417978000 28800 1 +08}.. {433785600 25200 0 +07}.. {449600400 28800 1 +08}.. {465332400 25200 0 +07}.. {481057200 28800 1 +08}.. {496782000 25200 0 +07}.. {512506800 28800 1 +08}.. {528231600 25200 0 +07}.. {543956400 28800 1 +08}.. {559681200 25200 0 +07}.. {575406000 28800 1 +08}.. {591130800 25200 0 +07}.. {606855600 28800 1 +08}.. {622580400 25200 0 +07}.. {638305200 28800 1 +08}.. {654634800 25200 0 +07}.. {670359600 21600 0 +07}.. {670363200 25200 1 +07}.. {686088000 21600 0 +06}.. {695764800 25200 0 +08}.. {701809200 28800 1 +08}.. {717534000 25200 0 +07}.. {733258800 28800 1 +08}.. {748983600 25200 0 +07}.. {76470
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8024
                                                                                                                                                                                                            Entropy (8bit):3.7230911686481774
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:4nBKPP8LFH0TDkywaZb1QSCK5VUjiO1PoBQpo7778CZicJZS80EGcLt4Mok1MgJl:4M38LCRZb+sAiO1PoBQpo1ikjD
                                                                                                                                                                                                            MD5:1D99E2BBB01B1669403CFBAF7E03F733
                                                                                                                                                                                                            SHA1:DBDD58C7FD195FC602C4541D6F416CC96094C121
                                                                                                                                                                                                            SHA-256:17AF14646D562AFE17DCCFD1D2FBA95C122F3E0263906A36EB48BFF04ACF233E
                                                                                                                                                                                                            SHA-512:98524E8DCD17C090058F17BDA1200D9801EB1B14EB5CEB8C31149A4A402A53BA4923A2AFF457E0A72DAA601D88095247806F945F704000F874FCBF73631DD135
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Beirut) {.. {-9223372036854775808 8520 0 LMT}.. {-2840149320 7200 0 EET}.. {-1570413600 10800 1 EEST}.. {-1552186800 7200 0 EET}.. {-1538359200 10800 1 EEST}.. {-1522551600 7200 0 EET}.. {-1507514400 10800 1 EEST}.. {-1490583600 7200 0 EET}.. {-1473645600 10800 1 EEST}.. {-1460948400 7200 0 EET}.. {-399866400 10800 1 EEST}.. {-386650800 7200 0 EET}.. {-368330400 10800 1 EEST}.. {-355114800 7200 0 EET}.. {-336794400 10800 1 EEST}.. {-323578800 7200 0 EET}.. {-305172000 10800 1 EEST}.. {-291956400 7200 0 EET}.. {-273636000 10800 1 EEST}.. {-260420400 7200 0 EET}.. {78012000 10800 1 EEST}.. {86734800 7200 0 EET}.. {105055200 10800 1 EEST}.. {118270800 7200 0 EET}.. {136591200 10800 1 EEST}.. {149806800 7200 0 EET}.. {168127200 10800 1 EEST}.. {181342800 7200 0 EET}.. {199749600 10800 1 EEST}.. {212965200 7200 0 EET}.. {231285600 10800
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1669
                                                                                                                                                                                                            Entropy (8bit):3.7443715330695735
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5qvdJqxiF0rvK5XvV4vUzvCjvT7voPvkPvJUbvn0vYpv99v3uvuWvKJhv3T:Ad1mzK5/VkULCbTjoHkHJUDnQYV9p3mO
                                                                                                                                                                                                            MD5:1EE8FF3DF0D931A140ADBB021EB3BFEB
                                                                                                                                                                                                            SHA1:F1F15EF70C4E9F456849AF89CAC97AD747D9E192
                                                                                                                                                                                                            SHA-256:1D5E9A8F6A04273AF741F648EF10718B004A60D7884FE432DDF85A8F558BEA98
                                                                                                                                                                                                            SHA-512:155539A5CF21A34FBFACBF1652D934BF32255F4E505E60B3B4D8B5F2F7FAE552E6CB4824D8608A9C56370F58E48702335995BBD16B7A296A86A72A615FBC8ABC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Bishkek) {.. {-9223372036854775808 17904 0 LMT}.. {-1441169904 18000 0 +05}.. {-1247547600 21600 0 +06}.. {354909600 25200 1 +06}.. {370717200 21600 0 +06}.. {386445600 25200 1 +06}.. {402253200 21600 0 +06}.. {417981600 25200 1 +06}.. {433789200 21600 0 +06}.. {449604000 25200 1 +06}.. {465336000 21600 0 +06}.. {481060800 25200 1 +06}.. {496785600 21600 0 +06}.. {512510400 25200 1 +06}.. {528235200 21600 0 +06}.. {543960000 25200 1 +06}.. {559684800 21600 0 +06}.. {575409600 25200 1 +06}.. {591134400 21600 0 +06}.. {606859200 25200 1 +06}.. {622584000 21600 0 +06}.. {638308800 25200 1 +06}.. {654638400 21600 0 +06}.. {670363200 18000 0 +05}.. {670366800 21600 1 +05}.. {683586000 18000 0 +05}.. {703018800 21600 1 +05}.. {717530400 18000 0 +05}.. {734468400 21600 1 +05}.. {748980000 18000 0 +05}.. {765918000 21600 1 +05}.. {78042
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):176
                                                                                                                                                                                                            Entropy (8bit):4.949517569857329
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8kLP/vXHAIgN16L1RL/2WFKXeAMM7QWFKPLPyn:SlSWB9vsM3yELPHAIg+L1N/2wK0oQwKW
                                                                                                                                                                                                            MD5:716D842F23974137C5E07A1A65CEFC5D
                                                                                                                                                                                                            SHA1:C7248C9DBD6AE5AF33BD4B3602D17737EBE023A0
                                                                                                                                                                                                            SHA-256:F3110E9DD514E3654A9DE777E22B2D2391692927954B4B7E42ED54AB665C3CF5
                                                                                                                                                                                                            SHA-512:4EC012EAABE60728D9447EEDF4BA7B16CA82786AA39EE79B2F9B32F227F9816FCE42F173153261F9AF88A12209752E84EBD7170C54D126C2DBB1ED3A8D069668
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Kuching)]} {.. LoadTimeZoneFile Asia/Kuching..}..set TZData(:Asia/Brunei) $TZData(:Asia/Kuching)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):178
                                                                                                                                                                                                            Entropy (8bit):4.774027471796823
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq864DyXHAIgN1QvRL/2WFKh0s+WFKvovn:SlSWB9vsM3ya4DSHAIgcvN/2wKN+wKvy
                                                                                                                                                                                                            MD5:8BB098AB77CB0469B1FA0E0B64C4A9E7
                                                                                                                                                                                                            SHA1:88C73626985071DD0923E1CAB343ACCD854A7297
                                                                                                                                                                                                            SHA-256:1BAEF7850111D2C33B2A766A8AE804534ABA1711BF80A4087A89656DDD8469D5
                                                                                                                                                                                                            SHA-512:82216A7F787AF20A4C97C7AA754CD6BE979FEF24137CF9A8B18EECA5E8FBCF12834DD8A6FC9CD2357D807F1629806745B46B11DC0472E0284E18DCCC983897DE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Kolkata)]} {.. LoadTimeZoneFile Asia/Kolkata..}..set TZData(:Asia/Calcutta) $TZData(:Asia/Kolkata)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2086
                                                                                                                                                                                                            Entropy (8bit):3.6981807774781017
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5Bpr1gIgWH/lt0irzEzCSCItWiIrW+rDQk9CVhyFY7rRWjYuhUmgr2M:95PhtjLiII2ZFlgd
                                                                                                                                                                                                            MD5:69E03A5CEB689E19B60168C0F7EBAE8E
                                                                                                                                                                                                            SHA1:95C6396EB753753B4FE4AE1B98D76332523E72A4
                                                                                                                                                                                                            SHA-256:10B6F435B05D887176A4D90CA5AC957F327F62F36F15D6F6E4F81844662429B9
                                                                                                                                                                                                            SHA-512:DFA72EDC54A11F0840ADBEE7F5AD8EA472AA52A1F196292F1341CD92A68FB2EC0A5BC7DE6C8E83C975420DB4B76CECD4393370FDB2C09F86EC11A50E540F6F02
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Chita) {.. {-9223372036854775808 27232 0 LMT}.. {-1579419232 28800 0 +08}.. {-1247558400 32400 0 +10}.. {354898800 36000 1 +10}.. {370706400 32400 0 +09}.. {386434800 36000 1 +10}.. {402242400 32400 0 +09}.. {417970800 36000 1 +10}.. {433778400 32400 0 +09}.. {449593200 36000 1 +10}.. {465325200 32400 0 +09}.. {481050000 36000 1 +10}.. {496774800 32400 0 +09}.. {512499600 36000 1 +10}.. {528224400 32400 0 +09}.. {543949200 36000 1 +10}.. {559674000 32400 0 +09}.. {575398800 36000 1 +10}.. {591123600 32400 0 +09}.. {606848400 36000 1 +10}.. {622573200 32400 0 +09}.. {638298000 36000 1 +10}.. {654627600 32400 0 +09}.. {670352400 28800 0 +09}.. {670356000 32400 1 +09}.. {686080800 28800 0 +08}.. {695757600 32400 0 +10}.. {701802000 36000 1 +10}.. {717526800 32400 0 +09}.. {733251600 36000 1 +10}.. {748976400 32400 0 +09}.. {7647012
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1619
                                                                                                                                                                                                            Entropy (8bit):3.775783980828041
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5th5fSW2sp4Qh2rRSQnGw7GywvWbC25XrMYWG4AIQTUhp9pkTGdXguHaena44XY5:rh5kpmWG29QFUmD
                                                                                                                                                                                                            MD5:540A7304A62ABB8D7F84454ABD6E2556
                                                                                                                                                                                                            SHA1:52C37529929218A668D7A4AD6FD1B5FE0A727E16
                                                                                                                                                                                                            SHA-256:94B2C14EF45C695EF6B19D94722E1BCBB629A595F2866DBA80F00A66721040B5
                                                                                                                                                                                                            SHA-512:3B535D109DB369E301D6B412F21EC990976B997826F22B2E16ECEEEB048D60F064C7CA1A616393DC2F1B491BAC0548DC0965B9EA149A95280FFDBCAD6726EF0F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Choibalsan) {.. {-9223372036854775808 27480 0 LMT}.. {-2032933080 25200 0 +07}.. {252435600 28800 0 +08}.. {417974400 36000 0 +09}.. {433778400 32400 0 +09}.. {449593200 36000 1 +09}.. {465314400 32400 0 +09}.. {481042800 36000 1 +09}.. {496764000 32400 0 +09}.. {512492400 36000 1 +09}.. {528213600 32400 0 +09}.. {543942000 36000 1 +09}.. {559663200 32400 0 +09}.. {575391600 36000 1 +09}.. {591112800 32400 0 +09}.. {606841200 36000 1 +09}.. {622562400 32400 0 +09}.. {638290800 36000 1 +09}.. {654616800 32400 0 +09}.. {670345200 36000 1 +09}.. {686066400 32400 0 +09}.. {701794800 36000 1 +09}.. {717516000 32400 0 +09}.. {733244400 36000 1 +09}.. {748965600 32400 0 +09}.. {764694000 36000 1 +09}.. {780415200 32400 0 +09}.. {796143600 36000 1 +09}.. {811864800 32400 0 +09}.. {828198000 36000 1 +09}.. {843919200 32400 0 +09}.. {8596
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):182
                                                                                                                                                                                                            Entropy (8bit):4.865222436335267
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8qvfXHAIgNtaYFARL/2WFKh2V7/4WFKdy:SlSWB9vsM3yMPHAIgO8AN/2wKho4wKU
                                                                                                                                                                                                            MD5:C5DC40C6325391F7247251ADB2C07F78
                                                                                                                                                                                                            SHA1:3DDB1BF94532FB1F1271095B9C8CAA779BC545EF
                                                                                                                                                                                                            SHA-256:A87382DC5F3C3141547A65E3746AF1DAF94B51468B96DA6CEF30E95754C97D37
                                                                                                                                                                                                            SHA-512:062FF8D5E5392E5372B0405EDF3C7CF997AC33F95EBFFAA9CC9AB82BBE27B60C80255FCCEE9E6F5E02CBFCB163F99984BB2103217FFD1F80BDEC5C684BF2F61A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Shanghai)]} {.. LoadTimeZoneFile Asia/Shanghai..}..set TZData(:Asia/Chongqing) $TZData(:Asia/Shanghai)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):182
                                                                                                                                                                                                            Entropy (8bit):4.889115378893491
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8qvfXHAIgNtaYFARL/2WFK7LeL9J4WFKdy:SlSWB9vsM3yMPHAIgO8AN/2wK7LUT4wj
                                                                                                                                                                                                            MD5:C3676771EB813B346F58A7B574D0D7B5
                                                                                                                                                                                                            SHA1:A473EF621309E019F29F3DEF95C38593775B8404
                                                                                                                                                                                                            SHA-256:D6D2B4A761C547F1F853AE901AC71AB49FBE825037079C4E0C89DC940AE4A822
                                                                                                                                                                                                            SHA-512:21C3A5D499E6E0427FBF585CA8CC5D99D193C586483AB107C4D8E9F9DC8412021E8E019A314757DAFE1225D2635F6D48E9C54A511709863F22A02449FA201E02
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Shanghai)]} {.. LoadTimeZoneFile Asia/Shanghai..}..set TZData(:Asia/Chungking) $TZData(:Asia/Shanghai)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):369
                                                                                                                                                                                                            Entropy (8bit):4.465596050904646
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2wKr+iDm2OHgoHvZv9tdvjSWV/FSQipPUrKkTD/k5QqRVVFSQOR/UIp:MB862zZmdHgCvZvJvj1Nj+Phkv/YtvjA
                                                                                                                                                                                                            MD5:9541BB43E79AB0C6E8163945B5BFB1BF
                                                                                                                                                                                                            SHA1:C4994420DB8313DECDE19B4B9F6C5DB0126A95A7
                                                                                                                                                                                                            SHA-256:E5B5E6D607A15DA65CB00C92C35A63EAF25F547E64CB34BB419CB8CFC2714B1B
                                                                                                                                                                                                            SHA-512:46F623B3F7CF8A50F97DD812521398EB9100C9CDFB967C18EF1BD112306AAEB3C9CB224424E48611CB8CC21D1DC3D820DD83032D12BC9DF19301CF07786FA664
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Colombo) {.. {-9223372036854775808 19164 0 LMT}.. {-2840159964 19172 0 MMT}.. {-2019705572 19800 0 +0530}.. {-883287000 21600 1 +06}.. {-862639200 23400 1 +0630}.. {-764051400 19800 0 +0530}.. {832962600 23400 0 +0630}.. {846266400 21600 0 +06}.. {1145039400 19800 0 +0530}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):169
                                                                                                                                                                                                            Entropy (8bit):4.786111096226559
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8ntyXHAIgN6KyFvRL/2WFK1S2WFKwBn:SlSWB9vsM3yHtSHAIgMKON/2wKM2wKwB
                                                                                                                                                                                                            MD5:BA575D37459540907A644438071277F8
                                                                                                                                                                                                            SHA1:14CF10D6AABBAF7BAE42B3B9641D8469C206567F
                                                                                                                                                                                                            SHA-256:B3AD560F66EA330E54A147017E6E6AB64452A5255D097B962D540836D7B19EE7
                                                                                                                                                                                                            SHA-512:9CA386EF4D812B00C2E63558B81B273F92BBCA98AF304C9FD6FC166210FC4E2F92B769E1D6FB96B670650DC76EFFAD2FC6E39AE12C24B47EAED4E50A2AFAC2D7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Dhaka)]} {.. LoadTimeZoneFile Asia/Dhaka..}..set TZData(:Asia/Dacca) $TZData(:Asia/Dhaka)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3692
                                                                                                                                                                                                            Entropy (8bit):3.7832279883701254
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:59xu6+RYla5W87rtYV08a7bd+dYV004X7JkX3Q0dzPeP2ua/XAog7jP/xZsNaTvT:8YI5WpVAdVGlkBOLh8X0CkBheIFlR
                                                                                                                                                                                                            MD5:1D6B2CC38669C0F7378D9A576F10C477
                                                                                                                                                                                                            SHA1:09A31E6295D9FC39219DFA4FC598B46F55C41180
                                                                                                                                                                                                            SHA-256:7E577F0F9DA459BA1A325BE95C1FA0DB2C6ECFC1D64CDB73F3ADB09588293BA7
                                                                                                                                                                                                            SHA-512:A0BBD5CE7883C275BF9752C75BA0C9AF0181046D94D27EFC96EC8823C374BADCB69B2B11D2C4497295E5BC25D5790634C69C6E7185F406F2107A8E16044E670F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Damascus) {.. {-9223372036854775808 8712 0 LMT}.. {-1577931912 7200 0 EET}.. {-1568592000 10800 1 EEST}.. {-1554080400 7200 0 EET}.. {-1537142400 10800 1 EEST}.. {-1522630800 7200 0 EET}.. {-1505692800 10800 1 EEST}.. {-1491181200 7200 0 EET}.. {-1474243200 10800 1 EEST}.. {-1459126800 7200 0 EET}.. {-242265600 10800 1 EEST}.. {-228877200 7200 0 EET}.. {-210556800 10800 1 EEST}.. {-197427600 7200 0 EET}.. {-178934400 10800 1 EEST}.. {-165718800 7200 0 EET}.. {-147398400 10800 1 EEST}.. {-134269200 7200 0 EET}.. {-116467200 10800 1 EEST}.. {-102646800 7200 0 EET}.. {-84326400 10800 1 EEST}.. {-71110800 7200 0 EET}.. {-52704000 10800 1 EEST}.. {-39488400 7200 0 EET}.. {-21168000 10800 1 EEST}.. {-7952400 7200 0 EET}.. {10368000 10800 1 EEST}.. {23583600 7200 0 EET}.. {41904000 10800 1 EEST}.. {55119600 7200 0 EET}.. {73526400 10800 1
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):364
                                                                                                                                                                                                            Entropy (8bit):4.412125512631861
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2wKwiDm2OHEmVFnoHv9vX+Yl7UIFckVVFSQiL/FG/UIvy/Ur9i/Ur97:MB862Y2mdHzdCv9P+Y9vvjeQlP9/9VkK
                                                                                                                                                                                                            MD5:B5496A038AC230B9D75AA22BB2BE6BDD
                                                                                                                                                                                                            SHA1:ACFD9C78F803F344272E8E188C41ED969EBADA16
                                                                                                                                                                                                            SHA-256:BFC4562055CC4355E79F9EFAA580A4C6A658285916159A5D390A0CDA96A97E98
                                                                                                                                                                                                            SHA-512:AB05D0176DADC1ED03CC526C372B9827A5FA03459E4F4B4365C6CE4B6FBDA043514A9D3FE2DA747159C5A1BC0E07727E6578A101E42B4DB120AF9624368C5FEA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Dhaka) {.. {-9223372036854775808 21700 0 LMT}.. {-2524543300 21200 0 HMT}.. {-891582800 23400 0 +0630}.. {-872058600 19800 0 +0530}.. {-862637400 23400 0 +0630}.. {-576138600 21600 0 +06}.. {1230746400 21600 0 +06}.. {1245430800 25200 1 +06}.. {1262278800 21600 0 +06}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):235
                                                                                                                                                                                                            Entropy (8bit):4.597480383845617
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2wKCXeSDm2OHnBGeoH1mpvyvScHTU71avScr:MB862qXbmdHnBvC1SyHHq8Hr
                                                                                                                                                                                                            MD5:316DDF860FA234621698EB473E558DB7
                                                                                                                                                                                                            SHA1:35BF955F764555945CF8B314B8E881DAD6CF557B
                                                                                                                                                                                                            SHA-256:8BC2E0D77AC35B6D63E11B820AC45EC23A4195ED773680C600C772FDF4B953F8
                                                                                                                                                                                                            SHA-512:D1A8D5F1DAAB7827BDCBC14506AF8681FD1ED94C6101CC4A3C8CC2A76EA7D3649038069158C539A2007A1B0734FBD87DE120415E07A3F08F44417100C95459F5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Dili) {.. {-9223372036854775808 30140 0 LMT}.. {-1830414140 28800 0 +08}.. {-879152400 32400 0 +09}.. {199897200 28800 0 +08}.. {969120000 32400 0 +09}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):148
                                                                                                                                                                                                            Entropy (8bit):4.97292023820863
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/2WFKQUMXGm2OHvkdoHsQK23NVsRYovV:SlSWB9eg/2wKQUDm2OHvsoHxVNSN
                                                                                                                                                                                                            MD5:861BA4A0A71E6C3F71B90074275FD57C
                                                                                                                                                                                                            SHA1:BC6FC5233340BB19AE4BD0BA563875479AC0A2B9
                                                                                                                                                                                                            SHA-256:3DB174F1568BC23BF467A3DC7BAF8A2A2952B70653D4DE54F4DB391EC50B6925
                                                                                                                                                                                                            SHA-512:B187735E0783F299253D9F93E002AEFF131FCCA50FB3E04CF0545B334B051D5ED978108A47C6957B608F5F93ED4CC3D69751FE0F40413719EE1C0440CD49AC76
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Dubai) {.. {-9223372036854775808 13272 0 LMT}.. {-1577936472 14400 0 +04}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):820
                                                                                                                                                                                                            Entropy (8bit):3.969189280047274
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5we3dJvOt81FCuLqecDngO6jPvTpYy5T4TiFGDr:5BvdJqxiF0uGr
                                                                                                                                                                                                            MD5:9ABD0ECB5F3E738F49CDD1F81C9FF1A4
                                                                                                                                                                                                            SHA1:46B68C7BBD1BE9791B00128A5129AA3668435C93
                                                                                                                                                                                                            SHA-256:550DB44595F59D0F151BE4AF70D6FECE20580AB687EF45DE2A0A75FB2515AC80
                                                                                                                                                                                                            SHA-512:67E2B0EF216D509C4B6DD367519E0A733E54A7CA767D5F7960715E8056E61B7B633C7516D568544F55C9277E90412C1443B822C6EED3341C01F1BD9AA9476FA1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Dushanbe) {.. {-9223372036854775808 16512 0 LMT}.. {-1441168512 18000 0 +05}.. {-1247547600 21600 0 +06}.. {354909600 25200 1 +06}.. {370717200 21600 0 +06}.. {386445600 25200 1 +06}.. {402253200 21600 0 +06}.. {417981600 25200 1 +06}.. {433789200 21600 0 +06}.. {449604000 25200 1 +06}.. {465336000 21600 0 +06}.. {481060800 25200 1 +06}.. {496785600 21600 0 +06}.. {512510400 25200 1 +06}.. {528235200 21600 0 +06}.. {543960000 25200 1 +06}.. {559684800 21600 0 +06}.. {575409600 25200 1 +06}.. {591134400 21600 0 +06}.. {606859200 25200 1 +06}.. {622584000 21600 0 +06}.. {638308800 25200 1 +06}.. {654638400 21600 0 +06}.. {670363200 21600 1 +06}.. {684363600 18000 0 +05}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7597
                                                                                                                                                                                                            Entropy (8bit):3.7170041442081203
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:G3pv/7V6Aj8aZaNlK0UpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYjlBKb0l:G3v/AaaivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                            MD5:F8E4BA3E260452AE13CF234E60149A62
                                                                                                                                                                                                            SHA1:8DDB08E2FDEEF6539EE0C0038B166908BFED16CD
                                                                                                                                                                                                            SHA-256:8CFE85C48FC22033411432F8B75EE4C097A5D84897698CB1AFD5AB51C47FF5A3
                                                                                                                                                                                                            SHA-512:487177411FB7E9F83AB9AAD84B685322B13A85784D4F90BB9C30F57BFAA6A9298E5C4F36C97444DE1117E51F85A62DC639D08B405460D071C2B29C898553E9A3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Famagusta) {.. {-9223372036854775808 8148 0 LMT}.. {-1518920148 7200 0 EET}.. {166572000 10800 1 EEST}.. {182293200 7200 0 EET}.. {200959200 10800 1 EEST}.. {213829200 7200 0 EET}.. {228866400 10800 1 EEST}.. {243982800 7200 0 EET}.. {260316000 10800 1 EEST}.. {276123600 7200 0 EET}.. {291765600 10800 1 EEST}.. {307486800 7200 0 EET}.. {323820000 10800 1 EEST}.. {338936400 7200 0 EET}.. {354664800 10800 1 EEST}.. {370386000 7200 0 EET}.. {386114400 10800 1 EEST}.. {401835600 7200 0 EET}.. {417564000 10800 1 EEST}.. {433285200 7200 0 EET}.. {449013600 10800 1 EEST}.. {465339600 7200 0 EET}.. {481068000 10800 1 EEST}.. {496789200 7200 0 EET}.. {512517600 10800 1 EEST}.. {528238800 7200 0 EET}.. {543967200 10800 1 EEST}.. {559688400 7200 0 EET}.. {575416800 10800 1 EEST}.. {591138000 7200 0 EET}.. {606866400 10800 1 EEST}.. {622587
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8427
                                                                                                                                                                                                            Entropy (8bit):3.7494839792487094
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:NyHSd2XK1GbJFp3gP0nPVl8dcqU/8O8pc1FoMpQ2NpPfM2g1siiVVfIsuDzhsXaP:NyyIgGbJv3dPAD7c1FoMpHu3Ky3p
                                                                                                                                                                                                            MD5:DEB2D261D6885CD83054391D010DE6AD
                                                                                                                                                                                                            SHA1:5779B343F4EB2BC75613C593E2FA3A026857F940
                                                                                                                                                                                                            SHA-256:A1823EDA63434ACF1A37B3A781A783CFEB6BB4CC53ED0469BB685834837F2289
                                                                                                                                                                                                            SHA-512:D024B2D324D981A6792127551B0D466EAFFC5294C84CB5752A71E5267FB2E9162E7EFAED5A5CA3B06BBAD285F62BF955B0EF86DD39307EE5F935FC601F4EEEFA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Gaza) {.. {-9223372036854775808 8272 0 LMT}.. {-2185409872 7200 0 EEST}.. {-933638400 10800 1 EEST}.. {-923097600 7200 0 EEST}.. {-919036800 10800 1 EEST}.. {-857347200 7200 0 EEST}.. {-844300800 10800 1 EEST}.. {-825811200 7200 0 EEST}.. {-812678400 10800 1 EEST}.. {-794188800 7200 0 EEST}.. {-779846400 10800 1 EEST}.. {-762652800 7200 0 EEST}.. {-748310400 10800 1 EEST}.. {-731116800 7200 0 EEST}.. {-682653600 7200 0 EET}.. {-399088800 10800 1 EEST}.. {-386650800 7200 0 EET}.. {-368330400 10800 1 EEST}.. {-355114800 7200 0 EET}.. {-336790800 10800 1 EEST}.. {-323654400 7200 0 EET}.. {-305168400 10800 1 EEST}.. {-292032000 7200 0 EET}.. {-273632400 10800 1 EEST}.. {-260496000 7200 0 EET}.. {-242096400 10800 1 EEST}.. {-228960000 7200 0 EET}.. {-210560400 10800 1 EEST}.. {-197424000 7200 0 EET}.. {-178938000 10800 1 EEST}.. {-16580
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):179
                                                                                                                                                                                                            Entropy (8bit):4.86422571961583
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8qvfXHAIgNtaYFARL/2WFKwHp4WFKdy:SlSWB9vsM3yMPHAIgO8AN/2wKi4wKU
                                                                                                                                                                                                            MD5:1BCCB3578FADE993EE8B2C11EAC06CD8
                                                                                                                                                                                                            SHA1:CAEAB714E014CD5040C44E4603708B97BC0B03D4
                                                                                                                                                                                                            SHA-256:12811A7944B892E3D1C0B4B09057CC1899F28081B3CD47FFD248BA49BA308AF0
                                                                                                                                                                                                            SHA-512:1D791DC0E8F45359366DF33C2C337688D2E0E972A90F038733B840D28585505AEF542DDBAD014C9EA8C252048A588CD017DD67A84545A81EDB7C17E3B2E65092
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Shanghai)]} {.. LoadTimeZoneFile Asia/Shanghai..}..set TZData(:Asia/Harbin) $TZData(:Asia/Shanghai)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8402
                                                                                                                                                                                                            Entropy (8bit):3.7520828858184325
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:fXSd2XK1GbJFp3gP0nPVl8dcqUZ8O8pc1FoMpQ2NpPfM2g1siiVVfIsuDzhsXa4a:fiIgGbJv3dPADPc1FoMpHu3Ky3p
                                                                                                                                                                                                            MD5:6F176787C7FC5764A63719F0041690BA
                                                                                                                                                                                                            SHA1:C292A8CEA597D7FD9E2D071AB7AE93E7ABCA21A5
                                                                                                                                                                                                            SHA-256:732CAA355542C8781C61FC8F5265EBFC59C8CC24E78D01011E1E3256E6B34DC7
                                                                                                                                                                                                            SHA-512:EE8F39A3D65D75E14B59B4D9CCB27894210CA269E82A7AC7F98BE67764688A8895EBB9C1ACEAB4C1B368B4F1BC5AFCB34E8866CEDFD91232926DF47517096513
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Hebron) {.. {-9223372036854775808 8423 0 LMT}.. {-2185410023 7200 0 EEST}.. {-933638400 10800 1 EEST}.. {-923097600 7200 0 EEST}.. {-919036800 10800 1 EEST}.. {-857347200 7200 0 EEST}.. {-844300800 10800 1 EEST}.. {-825811200 7200 0 EEST}.. {-812678400 10800 1 EEST}.. {-794188800 7200 0 EEST}.. {-779846400 10800 1 EEST}.. {-762652800 7200 0 EEST}.. {-748310400 10800 1 EEST}.. {-731116800 7200 0 EEST}.. {-682653600 7200 0 EET}.. {-399088800 10800 1 EEST}.. {-386650800 7200 0 EET}.. {-368330400 10800 1 EEST}.. {-355114800 7200 0 EET}.. {-336790800 10800 1 EEST}.. {-323654400 7200 0 EET}.. {-305168400 10800 1 EEST}.. {-292032000 7200 0 EET}.. {-273632400 10800 1 EEST}.. {-260496000 7200 0 EET}.. {-242096400 10800 1 EEST}.. {-228960000 7200 0 EET}.. {-210560400 10800 1 EEST}.. {-197424000 7200 0 EET}.. {-178938000 10800 1 EEST}.. {-165
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):395
                                                                                                                                                                                                            Entropy (8bit):4.431055857167822
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB862RLmdHneCvhYC5sF/p+zHHviViksF/dMUYPsF/RQ9EsV:5de3vhd5sFR+znv2vsFlM/PsFVsV
                                                                                                                                                                                                            MD5:A49A3D55C1E10A37125C51F9C6363868
                                                                                                                                                                                                            SHA1:7C1B5D44643ADC3F02681F6379E82C3F4512F0C1
                                                                                                                                                                                                            SHA-256:D8A19C70BE5A9AE1E6091DC8FD03D7719110D1F3D78786C91D5BD0949FB5A428
                                                                                                                                                                                                            SHA-512:804C44E51BB9E93B156B0CB4CB125651003B3C42D65334A052BE149734221315CC75D4FBDE34F62DFC102F1A9C968D1C9B573839C7ECBF7397B61BD90E530B20
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Ho_Chi_Minh) {.. {-9223372036854775808 25590 0 LMT}.. {-2004073590 25590 0 PLMT}.. {-1851577590 25200 0 +07}.. {-852105600 28800 0 +08}.. {-782643600 32400 0 +09}.. {-767869200 25200 0 +07}.. {-718095600 28800 0 +08}.. {-457776000 25200 0 +07}.. {-315648000 28800 0 +08}.. {171820800 25200 0 +07}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2226
                                                                                                                                                                                                            Entropy (8bit):4.0055033036300145
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5Ze9l9Pm4yoHtTYJJIX1Zcp6GS0j1SPQpP6gPE8fTZIPNYQGm75st/nQdwi9:DyaoTcwQt6EsQTng
                                                                                                                                                                                                            MD5:26BCBBA28AE34FE3CF7D17EF4C6B69C8
                                                                                                                                                                                                            SHA1:5324DEA8E7965C66650E7B4769EFA1297B508486
                                                                                                                                                                                                            SHA-256:EE9A6997BC1AAD4A8FA95DB312774C3F37FBB895549230C30FC66C02CC170EB6
                                                                                                                                                                                                            SHA-512:54594CD18838B4A8947EBB5BDE2415727CC127CF79AEC98FC0F5D5A32F68EEAF4E079853239DE9F753CE90F18EFD55AE51FC43D64E313666CEA0EF8AC93BF065
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Hong_Kong) {.. {-9223372036854775808 27402 0 LMT}.. {-2056690800 28800 0 HKT}.. {-900910800 32400 1 HKST}.. {-891579600 30600 1 HKWT}.. {-884248200 32400 0 JST}.. {-761209200 28800 0 HKT}.. {-747907200 32400 1 HKST}.. {-728541000 28800 0 HKT}.. {-717049800 32400 1 HKST}.. {-697091400 28800 0 HKT}.. {-683785800 32400 1 HKST}.. {-668061000 28800 0 HKT}.. {-654755400 32400 1 HKST}.. {-636611400 28800 0 HKT}.. {-623305800 32400 1 HKST}.. {-605161800 28800 0 HKT}.. {-591856200 32400 1 HKST}.. {-573712200 28800 0 HKT}.. {-559801800 32400 1 HKST}.. {-541657800 28800 0 HKT}.. {-528352200 32400 1 HKST}.. {-510211800 28800 0 HKT}.. {-498112200 32400 1 HKST}.. {-478762200 28800 0 HKT}.. {-466662600 32400 1 HKST}.. {-446707800 28800 0 HKT}.. {-435213000 32400 1 HKST}.. {-415258200 28800 0 HKT}.. {-403158600 32400 1 HKST}.. {-383808600 28800 0 HKT
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1583
                                                                                                                                                                                                            Entropy (8bit):3.7521760184466206
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5x3LecCvgsFFFKOksF8FpsF71FQnsFNFxhsFlF6sFaFasFZFisF8GF5sFKLFAZsZ:5FqKVx8Cq9f/y2L
                                                                                                                                                                                                            MD5:A77140A0D8C2D3E2993E4BA7CADFB4C6
                                                                                                                                                                                                            SHA1:AE3586264A86D42F578D4B0F7A30C9BE6047EAB1
                                                                                                                                                                                                            SHA-256:CA88A45E954A9854C680B399E69E4858BF5E861FABFADC19D62D97B734B25415
                                                                                                                                                                                                            SHA-512:05EA9D903EEC755F799B7C2399ED933245A5AE3A594648FE37AF1CE7699AE499B4ED159F428D91259D80BC9AF5117F2DA055A506AED94E5281C38B7AFF69C6FE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Hovd) {.. {-9223372036854775808 21996 0 LMT}.. {-2032927596 21600 0 +06}.. {252439200 25200 0 +07}.. {417978000 28800 1 +07}.. {433785600 25200 0 +07}.. {449600400 28800 1 +07}.. {465321600 25200 0 +07}.. {481050000 28800 1 +07}.. {496771200 25200 0 +07}.. {512499600 28800 1 +07}.. {528220800 25200 0 +07}.. {543949200 28800 1 +07}.. {559670400 25200 0 +07}.. {575398800 28800 1 +07}.. {591120000 25200 0 +07}.. {606848400 28800 1 +07}.. {622569600 25200 0 +07}.. {638298000 28800 1 +07}.. {654624000 25200 0 +07}.. {670352400 28800 1 +07}.. {686073600 25200 0 +07}.. {701802000 28800 1 +07}.. {717523200 25200 0 +07}.. {733251600 28800 1 +07}.. {748972800 25200 0 +07}.. {764701200 28800 1 +07}.. {780422400 25200 0 +07}.. {796150800 28800 1 +07}.. {811872000 25200 0 +07}.. {828205200 28800 1 +07}.. {843926400 25200 0 +07}.. {859654800
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2089
                                                                                                                                                                                                            Entropy (8bit):3.7296034934492694
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5PZy4DdOKStci4KjXoYjoSvfQJWE00dtT43kgiTskNrrBizhzRBqY3M:Py2/svfraBGfgP
                                                                                                                                                                                                            MD5:C9F7AC464970567E5C38CB01ED2297AE
                                                                                                                                                                                                            SHA1:453718BACCAE3FACD761AF22CA5875185478ADDD
                                                                                                                                                                                                            SHA-256:61BAAAD6315FFBDAED6F266880165B06ECCAF72F660B7FB01C8B654F3952D68E
                                                                                                                                                                                                            SHA-512:72044EFAE262CC12974F2DE2AAF06AC4C31BE73071ACD53DDC6B8D8BFC6FBDF937EC03DC881901F730659BDE662FBCFC76C57B2C086DAA97F160530464FBA7C6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Irkutsk) {.. {-9223372036854775808 25025 0 LMT}.. {-2840165825 25025 0 IMT}.. {-1575874625 25200 0 +07}.. {-1247554800 28800 0 +09}.. {354902400 32400 1 +09}.. {370710000 28800 0 +08}.. {386438400 32400 1 +09}.. {402246000 28800 0 +08}.. {417974400 32400 1 +09}.. {433782000 28800 0 +08}.. {449596800 32400 1 +09}.. {465328800 28800 0 +08}.. {481053600 32400 1 +09}.. {496778400 28800 0 +08}.. {512503200 32400 1 +09}.. {528228000 28800 0 +08}.. {543952800 32400 1 +09}.. {559677600 28800 0 +08}.. {575402400 32400 1 +09}.. {591127200 28800 0 +08}.. {606852000 32400 1 +09}.. {622576800 28800 0 +08}.. {638301600 32400 1 +09}.. {654631200 28800 0 +08}.. {670356000 25200 0 +08}.. {670359600 28800 1 +08}.. {686084400 25200 0 +07}.. {695761200 28800 0 +09}.. {701805600 32400 1 +09}.. {717530400 28800 0 +08}.. {733255200 32400 1 +09}.. {748
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):187
                                                                                                                                                                                                            Entropy (8bit):4.9013773460609
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV0XaDovXHAIgoq3XRFvHRL/2WFK4HB/8QaqXKv:SlSWB9vsM3ymQa2HAIgoQ/HN/2wK4HJa
                                                                                                                                                                                                            MD5:8A92C690BE27A69D122BFF51479B7B56
                                                                                                                                                                                                            SHA1:52DB64587A347F34153A51788BDE8C349D966575
                                                                                                                                                                                                            SHA-256:1F77C4BD27574E1D2066885DEF01806A02D3E444424A219A8EC5C114F89665E5
                                                                                                                                                                                                            SHA-512:FEDF57C4862B6792A789F339EB1027EC8A8472B01B7D1D0814C419850B9AC03A7B454FDB04D8BECE166E9A8BCAA58B0B461007A6C824B30B1080991A1DB49CCA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Istanbul)]} {.. LoadTimeZoneFile Europe/Istanbul..}..set TZData(:Asia/Istanbul) $TZData(:Europe/Istanbul)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):370
                                                                                                                                                                                                            Entropy (8bit):4.4733192761103515
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2wKcrJfDm2OHATJeoHMaSYov/YSZkc5q/MVSSFFWSyvScH+dMVSSFL+:MB862EJLmdHjCEdOc5aMxaSyHHaMxF6P
                                                                                                                                                                                                            MD5:C689A1AA9FFE535AEB3AD3D7EDE55172
                                                                                                                                                                                                            SHA1:0520FC9A4619FB555A79C5DF2AE82422BF2C5EDA
                                                                                                                                                                                                            SHA-256:2F39D9F93761B85C254F458317A7DE2B4184BE9459F2193A85C08662E801269A
                                                                                                                                                                                                            SHA-512:C1034FB2FCFEF201C5362AF21B048B6637A824C5C93D75854CF3807892C772CD4376533E58BFF8D8726F531F43CB231365B8012EBD3C1BECED865D3CD2D6673D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Jakarta) {.. {-9223372036854775808 25632 0 LMT}.. {-3231299232 25632 0 BMT}.. {-1451719200 26400 0 +0720}.. {-1172906400 27000 0 +0730}.. {-876641400 32400 0 +09}.. {-766054800 27000 0 +0730}.. {-683883000 28800 0 +08}.. {-620812800 27000 0 +0730}.. {-189415800 25200 0 WIB}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):213
                                                                                                                                                                                                            Entropy (8bit):4.834345288972067
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2wKcaDm2OHG4YoH1kcfvScHVowkVcr2CV4zvhyov:MB862PmdHNYC6cfHHVop2NVkoov
                                                                                                                                                                                                            MD5:2CB3A13FCC48F8C4457E001FC309918B
                                                                                                                                                                                                            SHA1:83174176815CB93D216B5BC532C120EC8AC433CF
                                                                                                                                                                                                            SHA-256:761C1E80FEBF46D6D6215CEBF211F121974156D9BCE2FB4258C1074C6ED2CE22
                                                                                                                                                                                                            SHA-512:65009020AB9FEC2F8158A4851A78B71127F9B262DDD1472583942E19B7C086304F54BC8DAE5A40BD1448BCAEDA0FDBACCD19400E10FFA0357E324535F9036EF0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Jayapura) {.. {-9223372036854775808 33768 0 LMT}.. {-1172913768 32400 0 +09}.. {-799491600 34200 0 +0930}.. {-189423000 32400 0 WIT}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8135
                                                                                                                                                                                                            Entropy (8bit):3.770028446231146
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:GKfnxFAEX/nPVl8diAg9oEhH20AHz7LzdWhYbBJPXuVhKaM76Rmg4DLeEcNptv5C:7ffBvPAzF0AHzPzdD1+XBRF0
                                                                                                                                                                                                            MD5:884227D48C92BA6C519BFE571D4F1037
                                                                                                                                                                                                            SHA1:21F8977816C2B439686A50D353B836A6D132A946
                                                                                                                                                                                                            SHA-256:0BDC2C693134199C2ECD374CC01468813DB29DF47422C706A3EA2BE5ECCA177A
                                                                                                                                                                                                            SHA-512:8A09F1FE11DAD203501A16FE6A2CAEC969FE3553B456B8BD1997E55B3EE430B2BB4B54F7D87C5E99931FD96E7C769CAA618C777EBD23FBD1E1A0F57409422914
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Jerusalem) {.. {-9223372036854775808 8454 0 LMT}.. {-2840149254 8440 0 JMT}.. {-1641003640 7200 0 IST}.. {-933638400 10800 1 IDT}.. {-923097600 7200 0 IST}.. {-919036800 10800 1 IDT}.. {-857347200 7200 0 IST}.. {-844300800 10800 1 IDT}.. {-825811200 7200 0 IST}.. {-812678400 10800 1 IDT}.. {-794188800 7200 0 IST}.. {-779846400 10800 1 IDT}.. {-762652800 7200 0 IST}.. {-748310400 10800 1 IDT}.. {-731116800 7200 0 IST}.. {-681955200 14400 1 IDDT}.. {-673228800 10800 1 IDT}.. {-667958400 7200 0 IST}.. {-652320000 10800 1 IDT}.. {-636422400 7200 0 IST}.. {-622080000 10800 1 IDT}.. {-608947200 7200 0 IST}.. {-591840000 10800 1 IDT}.. {-572486400 7200 0 IST}.. {-558576000 10800 1 IDT}.. {-542851200 7200 0 IST}.. {-527731200 10800 1 IDT}.. {-514425600 7200 0 IST}.. {-490838400 10800 1 IDT}.. {-482976000 7200 0 IST}.. {-459388800 10800 1 I
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):180
                                                                                                                                                                                                            Entropy (8bit):4.8546989169864085
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/2WFKTtNMXGm2OHodFxsYoHvgVHURRNVsRYovFFFkdj/cXHF:SlSWB9eg/2wKTPDm2OHoH+YoHvgVHURA
                                                                                                                                                                                                            MD5:9BD9B21661C235C0794078EC98978D3B
                                                                                                                                                                                                            SHA1:3D854780F49D0E5F5A190DC9367C7406127C5E4D
                                                                                                                                                                                                            SHA-256:A59C95C038F2E945D685D96FA9B859CE82A643A1B7F56EB36B2C809DE91CD4BA
                                                                                                                                                                                                            SHA-512:A76E99CF03DA8897F0A210A98DB79E4CD60070F2BE363D0D0960D9882919F9B49978FA55BB2500F1648ADD4080730CAD85BAFF61D885A9EAD394AC04C850F6BA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Kabul) {.. {-9223372036854775808 16608 0 LMT}.. {-2524538208 14400 0 +04}.. {-788932800 16200 0 +0430}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2060
                                                                                                                                                                                                            Entropy (8bit):3.788131608921229
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5+SeWI/2kkWk7YFpR2kHmxCcUdBbcHDLV2vpXt25A0UeRr9ydzkMfF6USRWk9UuV:5i/2ZsFLrcZwvJt2F+doTr9Q3G80
                                                                                                                                                                                                            MD5:390F39934F095F89358B73D056D90264
                                                                                                                                                                                                            SHA1:6B57CE5346B50ED88BFBB6BC57F834FB3F564905
                                                                                                                                                                                                            SHA-256:6E0278E389072437BC07A5032CD58E9E5B1B2BDB20918632C422EFA97BC43ABF
                                                                                                                                                                                                            SHA-512:6C54D94E95D73030F2FFCF8D130494CBD79FB1CEB9B59ADE0743C10F02557C3DD59CC6274B262A7E29C2D4C35DDA4B6A9A0398C661F5BD40F3B92181192B9577
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Kamchatka) {.. {-9223372036854775808 38076 0 LMT}.. {-1487759676 39600 0 +11}.. {-1247569200 43200 0 +13}.. {354888000 46800 1 +13}.. {370695600 43200 0 +12}.. {386424000 46800 1 +13}.. {402231600 43200 0 +12}.. {417960000 46800 1 +13}.. {433767600 43200 0 +12}.. {449582400 46800 1 +13}.. {465314400 43200 0 +12}.. {481039200 46800 1 +13}.. {496764000 43200 0 +12}.. {512488800 46800 1 +13}.. {528213600 43200 0 +12}.. {543938400 46800 1 +13}.. {559663200 43200 0 +12}.. {575388000 46800 1 +13}.. {591112800 43200 0 +12}.. {606837600 46800 1 +13}.. {622562400 43200 0 +12}.. {638287200 46800 1 +13}.. {654616800 43200 0 +12}.. {670341600 39600 0 +12}.. {670345200 43200 1 +12}.. {686070000 39600 0 +11}.. {695746800 43200 0 +13}.. {701791200 46800 1 +13}.. {717516000 43200 0 +12}.. {733240800 46800 1 +13}.. {748965600 43200 0 +12}.. {764
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):457
                                                                                                                                                                                                            Entropy (8bit):4.396286144160272
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB862dmdH35Cy6DvjeQXvjKEn6vNEhFc0bkTfb2iWToN1:5de3IjjeQ/jKE6vNNa8
                                                                                                                                                                                                            MD5:DF604BCD42A3C1E6BABD0E4FF5764CA3
                                                                                                                                                                                                            SHA1:984111F3A75EE7D8760AA2B839010545AF8EE359
                                                                                                                                                                                                            SHA-256:4E7F7ACAE8B4018A835328744F680C8054771805BB0BB07678A09737963C090D
                                                                                                                                                                                                            SHA-512:690AC3FC7CA3C66AA70F17E38C6B43FFACAB3F86040C3BA94FBFF80AC8C1AECF8192E503282109DABF3228F8DC73C732F1041C80455B8B26BDB25C4C32FA286A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Karachi) {.. {-9223372036854775808 16092 0 LMT}.. {-1988166492 19800 0 +0530}.. {-862637400 23400 1 +0630}.. {-764145000 19800 0 +0530}.. {-576135000 18000 0 +05}.. {38775600 18000 0 PKT}.. {1018119600 21600 1 PKST}.. {1033840800 18000 0 PKT}.. {1212260400 21600 1 PKST}.. {1225476000 18000 0 PKT}.. {1239735600 21600 1 PKST}.. {1257012000 18000 0 PKT}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):174
                                                                                                                                                                                                            Entropy (8bit):4.967143524972358
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8s4YkyXHAIgNrYOARL/2WFKu3e2WFKjov:SlSWB9vsM3yMGSHAIgvAN/2wKulwKjy
                                                                                                                                                                                                            MD5:259662F35AA09A891C2DDF8FCFECD6F0
                                                                                                                                                                                                            SHA1:DBB3A363A34C33F0B6B0D677E43C2985E2BAF976
                                                                                                                                                                                                            SHA-256:7B2251F0A41CBADF45D69F24604834167B14D8D33B510E635719AB404CABBCE2
                                                                                                                                                                                                            SHA-512:CD7E514555D58985C774535556B66542EFC5FB7CD5891F42FE21B591612CB7EBD4B41E96593E26E9283BA1B01EF3BE0FDFAE871F5EF6ADF2286AF1E479DCB44B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Urumqi)]} {.. LoadTimeZoneFile Asia/Urumqi..}..set TZData(:Asia/Kashgar) $TZData(:Asia/Urumqi)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):185
                                                                                                                                                                                                            Entropy (8bit):4.896398105471451
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/2WFKXIi7hvXMXGm2OHF+VT5oHsQKwMTXvv6Q6zRk8P4VvW/:SlSWB9eg/2wKYghfDm2OH0T5oHxNMzv8
                                                                                                                                                                                                            MD5:7AC6429D2A08372C71C61B4521246FEC
                                                                                                                                                                                                            SHA1:6E50F5AD1018398491453D751F8B717B618EF46E
                                                                                                                                                                                                            SHA-256:F0A0816E62036637F75081CBF17A1E6B8FBC2D86AEC3CD2E234BBBDD6EC9F109
                                                                                                                                                                                                            SHA-512:A5389A318896ABCAFE419262F6B8CA86C917788F1E2AFBC8CB1C074A52870E7A92C9F6F7D79DDE4AB0D267D870D3CCD69B3FC5FD57520352EFE36C583B493FB9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Kathmandu) {.. {-9223372036854775808 20476 0 LMT}.. {-1577943676 19800 0 +0530}.. {504901800 20700 0 +0545}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):184
                                                                                                                                                                                                            Entropy (8bit):4.8363583658476745
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8yIi7V5XHAIgN1AIilvWARL/2WFKSiZ1/2WFKXIi7y:SlSWB9vsM3y7gVJHAIg5QOAN/2wKSg15
                                                                                                                                                                                                            MD5:4CCC96293A33113D9ADC4130DCD19CBA
                                                                                                                                                                                                            SHA1:7BAB4B8DD6BB415A2FC86D9AB36BE2A893C03153
                                                                                                                                                                                                            SHA-256:9ACC9586B6F8B53BFE8B242283A434A9A9633D60559EBFDEE263B4C8915D50CA
                                                                                                                                                                                                            SHA-512:644E1777E01C15A728E30526F131462FCE50476A8FEDA9B99F41D95013BB8833A79437E75AA2025E2FD2E253B9AD40709DEF77E1F0C73DAAE7A9CF886A175A03
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Kathmandu)]} {.. LoadTimeZoneFile Asia/Kathmandu..}..set TZData(:Asia/Katmandu) $TZData(:Asia/Kathmandu)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2119
                                                                                                                                                                                                            Entropy (8bit):3.707911838150672
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5No6r1gIgWH/lt0irzEzCSCItWiIrW+rDQk9CVhyFYkRDhUBAc6l:r5PhtjLiII2JBC6c6l
                                                                                                                                                                                                            MD5:D7B394A9662D60D01781005FE73CC9E8
                                                                                                                                                                                                            SHA1:50B5EBD02596DC45D1F69358C5B69DD3058905FC
                                                                                                                                                                                                            SHA-256:33203D7FB7F3D1F848640ECE0642A2305E1863B4D47413075E2E7E40BD7418E7
                                                                                                                                                                                                            SHA-512:055EBA420F2F6049E803796ACCA263264B9E585E5312A86B8DF7B409C5F1CB1810F3AEDACD66CCF4605E55198947D263C240486C2A4D453D23C89802F0C66BBA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Khandyga) {.. {-9223372036854775808 32533 0 LMT}.. {-1579424533 28800 0 +08}.. {-1247558400 32400 0 +10}.. {354898800 36000 1 +10}.. {370706400 32400 0 +09}.. {386434800 36000 1 +10}.. {402242400 32400 0 +09}.. {417970800 36000 1 +10}.. {433778400 32400 0 +09}.. {449593200 36000 1 +10}.. {465325200 32400 0 +09}.. {481050000 36000 1 +10}.. {496774800 32400 0 +09}.. {512499600 36000 1 +10}.. {528224400 32400 0 +09}.. {543949200 36000 1 +10}.. {559674000 32400 0 +09}.. {575398800 36000 1 +10}.. {591123600 32400 0 +09}.. {606848400 36000 1 +10}.. {622573200 32400 0 +09}.. {638298000 36000 1 +10}.. {654627600 32400 0 +09}.. {670352400 28800 0 +09}.. {670356000 32400 1 +09}.. {686080800 28800 0 +08}.. {695757600 32400 0 +10}.. {701802000 36000 1 +10}.. {717526800 32400 0 +09}.. {733251600 36000 1 +10}.. {748976400 32400 0 +09}.. {7647
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):336
                                                                                                                                                                                                            Entropy (8bit):4.614218930153471
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2wKvhfDm2OHEX3gYoHrXdUvvYbQLpUFdvjSVVFJLNsR/QFckVVFJLLW:MB8623tmdHNYCDWXYbQtUTvjAJBs50vs
                                                                                                                                                                                                            MD5:248F1B5A26455000C936CE8BC02C1A0B
                                                                                                                                                                                                            SHA1:0C3F8CD4E038B113E5238AC52652809B6CA27999
                                                                                                                                                                                                            SHA-256:6D464564ED2EFC9DADA1586D4FC99FE333726D2BE15A00E30C2391F588896463
                                                                                                                                                                                                            SHA-512:AF36B0B3D410305ED504726C87265ACCAF5577A9B5DD7E7DAF135420E356C651287873197431B65B5317B4BA2009274288E4F101AC1274045A8D99E2414AB132
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Kolkata) {.. {-9223372036854775808 21208 0 LMT}.. {-3645237208 21200 0 HMT}.. {-3155694800 19270 0 MMT}.. {-2019705670 19800 0 IST}.. {-891581400 23400 1 +0630}.. {-872058600 19800 0 IST}.. {-862637400 23400 1 +0630}.. {-764145000 19800 0 IST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2062
                                                                                                                                                                                                            Entropy (8bit):3.7086418466382605
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5Ote2CoXJfsFN/3sFrOksF/sF7IyksF7FRZsFLsFTsFcsFk73sFK/XCFKTipnFEw:5B40yVRB7VfXucydm46I/CTxwh
                                                                                                                                                                                                            MD5:A59F7FFD0C3EBAD47EC5F2B89EBBD9FA
                                                                                                                                                                                                            SHA1:ACB94E28E0CF7C6606086267CEA1F63A3E755F56
                                                                                                                                                                                                            SHA-256:53B8D5E7FB1BD67FECE66A933D9BDBB773F14A8C04D316A2A1B00EC6DBC151DD
                                                                                                                                                                                                            SHA-512:7B3886B9D0A793CCEEDB2B190523922CFEBE5C82A5201C9EFA30CA4C7F63FB75C998CC7E1BD48D5D489F16E36FC0C22BD954CB7D321B3C09B36B60629C4C9F7E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Krasnoyarsk) {.. {-9223372036854775808 22286 0 LMT}.. {-1577513486 21600 0 +06}.. {-1247551200 25200 0 +08}.. {354906000 28800 1 +08}.. {370713600 25200 0 +07}.. {386442000 28800 1 +08}.. {402249600 25200 0 +07}.. {417978000 28800 1 +08}.. {433785600 25200 0 +07}.. {449600400 28800 1 +08}.. {465332400 25200 0 +07}.. {481057200 28800 1 +08}.. {496782000 25200 0 +07}.. {512506800 28800 1 +08}.. {528231600 25200 0 +07}.. {543956400 28800 1 +08}.. {559681200 25200 0 +07}.. {575406000 28800 1 +08}.. {591130800 25200 0 +07}.. {606855600 28800 1 +08}.. {622580400 25200 0 +07}.. {638305200 28800 1 +08}.. {654634800 25200 0 +07}.. {670359600 21600 0 +07}.. {670363200 25200 1 +07}.. {686088000 21600 0 +06}.. {695764800 25200 0 +08}.. {701809200 28800 1 +08}.. {717534000 25200 0 +07}.. {733258800 28800 1 +08}.. {748983600 25200 0 +07}.. {7
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):188
                                                                                                                                                                                                            Entropy (8bit):4.956557779400841
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq801c3vXHAIgNtK1tyHRL/2WFK1NFWFKf1z:SlSWB9vsM3yUgHAIgWv6N/2wK1NFwKf9
                                                                                                                                                                                                            MD5:E70767DA85A7E1FA9395FF0B16CFE5CE
                                                                                                                                                                                                            SHA1:3F78034F166CFC80B54E56AF289C7700A7E4AA5C
                                                                                                                                                                                                            SHA-256:056D352DDCFEC155375430FFF3C8743ED5C9B51B866A099E97E12CC381071F50
                                                                                                                                                                                                            SHA-512:FEDC854FB043AA79F132827F98F8983E480727FAA039CF2FB5B82611E724312A4F3F006EE58707F12B0AA90F5872E17F76E2A040CFB3A90D017C5CF92E52DA0A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Singapore)]} {.. LoadTimeZoneFile Asia/Singapore..}..set TZData(:Asia/Kuala_Lumpur) $TZData(:Asia/Singapore)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):669
                                                                                                                                                                                                            Entropy (8bit):4.074079100812583
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2wKPLBDm2OHXoH3UTdMVSSFVM5qGeCiKaFzsBRcerUNwGvULhMXeiCs:MB862HL1mdHXC3UBMxJJo9rphTXUzHHF
                                                                                                                                                                                                            MD5:489E706324960E86B6E174D913C72E02
                                                                                                                                                                                                            SHA1:C7D77482C0D41F3426FC269B3B6C0575EF0E8C7E
                                                                                                                                                                                                            SHA-256:6E35E560675B0B5322474900D4EC8326C504788C1F82E533B09785DEEFF092DF
                                                                                                                                                                                                            SHA-512:5CEFD44656C041E59A16481E042EA914E7C003BDE6ADF5F49B57052E91F4F732A91A244BD8BC09EF5DC2640D3210DEE53882717C5C4CBD85CCE44A93B028E9C3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Kuching) {.. {-9223372036854775808 26480 0 LMT}.. {-1383463280 27000 0 +0730}.. {-1167636600 28800 0 +08}.. {-1082448000 30000 1 +08}.. {-1074586800 28800 0 +08}.. {-1050825600 30000 1 +08}.. {-1042964400 28800 0 +08}.. {-1019289600 30000 1 +08}.. {-1011428400 28800 0 +08}.. {-987753600 30000 1 +08}.. {-979892400 28800 0 +08}.. {-956217600 30000 1 +08}.. {-948356400 28800 0 +08}.. {-924595200 30000 1 +08}.. {-916734000 28800 0 +08}.. {-893059200 30000 1 +08}.. {-885198000 28800 0 +08}.. {-879667200 32400 0 +09}.. {-767005200 28800 0 +08}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):173
                                                                                                                                                                                                            Entropy (8bit):4.877362838821003
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8t14XHAIgNsM13oOARL/2WFKdQWFK81Fn:SlSWB9vsM3yN14HAIgaM1YOAN/2wKdQ6
                                                                                                                                                                                                            MD5:EA1DB4B80CC74CBA024B9BF3734B31F2
                                                                                                                                                                                                            SHA1:D8131C093BCA3B378BEC606CFEB56A40CB4E246F
                                                                                                                                                                                                            SHA-256:8E0C60A9AA64FB8602EDC35311F7436B04853970A21C1F6C871494A09AAD5787
                                                                                                                                                                                                            SHA-512:3B57C9CCC16AA4FE71D275D5EC6A7BC1838841023EE4408158362A7E13E7F1B345F7D95006BC8D2FC270158864E286A1A9364C792F679D5803BD82148399C199
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Riyadh)]} {.. LoadTimeZoneFile Asia/Riyadh..}..set TZData(:Asia/Kuwait) $TZData(:Asia/Riyadh)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):169
                                                                                                                                                                                                            Entropy (8bit):4.781739054385376
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8PWXHAIgNz+NOARL/2WFKf+WFKkvn:SlSWB9vsM3yOHAIg1AN/2wKGwKmn
                                                                                                                                                                                                            MD5:55DAE27AEAA74FE822338C20B6CDFF68
                                                                                                                                                                                                            SHA1:F00EB827DC29EB2063B3A0EDBC39856637C55F33
                                                                                                                                                                                                            SHA-256:4308D741C83B263C7C9FB8EC692A7B7B502135E407B265B12EA7EF92523455C0
                                                                                                                                                                                                            SHA-512:398EE6015C58BDBBEAB49B74833B938FD84DE1AC6D3B8D095CE772ECA980D9E93F4EBFFFFCEAE7F91E287C8CE4F94B1A078D8E1460C352B7C2018F99915838FF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Macau)]} {.. LoadTimeZoneFile Asia/Macau..}..set TZData(:Asia/Macao) $TZData(:Asia/Macau)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2217
                                                                                                                                                                                                            Entropy (8bit):3.9638741177777868
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5ReCX8Iv3nhPHCvzncCHg9PHjZzH+0HDHN1aHhHNaezHBjHeHsH65H18HDH983lY:5d8u3hfCTcaOrh6qn151Wf3Bogp+nlC
                                                                                                                                                                                                            MD5:B184E7403CB7168607D2C9E158F86A3B
                                                                                                                                                                                                            SHA1:48B003B8F822BE979FBCB08CBDBFFC617BCF99DB
                                                                                                                                                                                                            SHA-256:FBCB92CECB1CB0BC284ADC30D70C5F57B3AFC992136A0D898ABC64490BB700FB
                                                                                                                                                                                                            SHA-512:D8C5C67CAEB7C670B7BD1DACC1203C4DEE4DDB16A780F502C4440997CFCFF869E86842EF87C2CD0E0B942941C02A6BC3BDAB7CEAD78B026B68F4A031173400C8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Macau) {.. {-9223372036854775808 27250 0 LMT}.. {-2056692850 28800 0 CST}.. {-884509200 32400 0 +09}.. {-873280800 36000 1 +09}.. {-855918000 32400 0 +09}.. {-841744800 36000 1 +09}.. {-828529200 32400 0 +10}.. {-765363600 28800 0 CT}.. {-747046800 32400 1 CDT}.. {-733827600 28800 0 CST}.. {-716461200 32400 1 CDT}.. {-697021200 28800 0 CST}.. {-683715600 32400 1 CDT}.. {-667990800 28800 0 CST}.. {-654771600 32400 1 CDT}.. {-636627600 28800 0 CST}.. {-623322000 32400 1 CDT}.. {-605178000 28800 0 CST}.. {-591872400 32400 1 CDT}.. {-573642000 28800 0 CST}.. {-559818000 32400 1 CDT}.. {-541674000 28800 0 CST}.. {-528368400 32400 1 CDT}.. {-510224400 28800 0 CST}.. {-498128400 32400 1 CDT}.. {-478774800 28800 0 CST}.. {-466678800 32400 1 CDT}.. {-446720400 28800 0 CST}.. {-435229200 32400 1 CDT}.. {-415258200 28800 0 CST}.. {-403158600
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2088
                                                                                                                                                                                                            Entropy (8bit):3.7643610103361134
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5he9dbbv+OC+jsuwltZQONEa2Ggf3augO8UoxLyHdX/CX6bW4Bv/7NKx/y:5wv+0j6lua2Gg/3gO8UoOZU2Wc/pKo
                                                                                                                                                                                                            MD5:F62A89F441C9C17EB99F64223C815651
                                                                                                                                                                                                            SHA1:408C38A79E056FF9B03D0DA85114DC015CB66938
                                                                                                                                                                                                            SHA-256:0C6EEEB7975A95C2B0678D137E6A735238D244A37FA11078050051511DE499FE
                                                                                                                                                                                                            SHA-512:55DC72546BDC26450D5318E9D2819E32A91C27D06A7AF5432BD50F8722C69984BBAA8599055A824D2935D919F0C0AA357687DD9B47F49F213EEE21AF7458FE17
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Magadan) {.. {-9223372036854775808 36192 0 LMT}.. {-1441188192 36000 0 +10}.. {-1247565600 39600 0 +12}.. {354891600 43200 1 +12}.. {370699200 39600 0 +11}.. {386427600 43200 1 +12}.. {402235200 39600 0 +11}.. {417963600 43200 1 +12}.. {433771200 39600 0 +11}.. {449586000 43200 1 +12}.. {465318000 39600 0 +11}.. {481042800 43200 1 +12}.. {496767600 39600 0 +11}.. {512492400 43200 1 +12}.. {528217200 39600 0 +11}.. {543942000 43200 1 +12}.. {559666800 39600 0 +11}.. {575391600 43200 1 +12}.. {591116400 39600 0 +11}.. {606841200 43200 1 +12}.. {622566000 39600 0 +11}.. {638290800 43200 1 +12}.. {654620400 39600 0 +11}.. {670345200 36000 0 +11}.. {670348800 39600 1 +11}.. {686073600 36000 0 +10}.. {695750400 39600 0 +12}.. {701794800 43200 1 +12}.. {717519600 39600 0 +11}.. {733244400 43200 1 +12}.. {748969200 39600 0 +11}.. {76469
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):243
                                                                                                                                                                                                            Entropy (8bit):4.737440985553183
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2wK5XDm2OHUVoHxYQTLQTvj1kc3gEpHkH8vScHr0:MB862hTmdHsCLTI6cQe7HHA
                                                                                                                                                                                                            MD5:9116C0B70AB33EC49F933EAE0238FD4B
                                                                                                                                                                                                            SHA1:BA390E8FBEAF5EA6E861AFC5A51CD4DF0B422461
                                                                                                                                                                                                            SHA-256:30D8AB00E32ECE51442C0310E650D89D6989E0809600EE334CB10C506D84BF9D
                                                                                                                                                                                                            SHA-512:499E60E8CBDA72226BCB4E241020E62B6F88E7D3E4329D260A6536EF87C02D7D61FD1BECC47D4FF308B4EB5D3E7FFBE2EC1C96FE2DEDC09DD1D973421C5FFE1E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Makassar) {.. {-9223372036854775808 28656 0 LMT}.. {-1577951856 28656 0 MMT}.. {-1172908656 28800 0 +08}.. {-880272000 32400 0 +09}.. {-766054800 28800 0 WITA}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):421
                                                                                                                                                                                                            Entropy (8bit):4.48495488773916
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB862GjmdHnCTZBCvEo6AwoucQzy4orjAbomAtoNv:5GjeCVwvB6AduXzylHAMmAa9
                                                                                                                                                                                                            MD5:0FBF0ED252638DF31826C33EB3FFBFE2
                                                                                                                                                                                                            SHA1:3496E4A5251A9BDF3AA4368297140780B6DBF66D
                                                                                                                                                                                                            SHA-256:070D61A0E39643A700ABA89A8A4BE5733BA456958966098405E11ECDFA854D76
                                                                                                                                                                                                            SHA-512:2A40E14964B357809E596DF88D8C4141ED78664BACA0A7724A7CA837EF427DC2B07C48D9DBE5787FAB0015673F5BDE002223D489334C5B91B74EEC5507A14B78
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Manila) {.. {-9223372036854775808 -57360 0 LMT}.. {-3944621040 29040 0 LMT}.. {-2229321840 28800 0 PST}.. {-1046678400 32400 1 PDT}.. {-1038733200 28800 0 PST}.. {-873273600 32400 0 JST}.. {-794221200 28800 0 PST}.. {-496224000 32400 1 PDT}.. {-489315600 28800 0 PST}.. {259344000 32400 1 PDT}.. {275151600 28800 0 PST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):170
                                                                                                                                                                                                            Entropy (8bit):4.805992552335358
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8DeXHAIgN6S7ARL/2WFKvE+H+WFKQ3n:SlSWB9vsM3yj+HAIgMS7AN/2wKLewKQ3
                                                                                                                                                                                                            MD5:8AEB5C3E81069F884A370714E8013F1F
                                                                                                                                                                                                            SHA1:4E3DD4A84627E75E84726C0CBA72CA6801280C2B
                                                                                                                                                                                                            SHA-256:011B7DE1C9F7EC241B224BC864D8AE66ACB433FBC8AD939E4DBEB12BE6390243
                                                                                                                                                                                                            SHA-512:50B1DE2615AE9B4781505DC709F9D07F6221D4E6D7B61D7BDA682377EAD9807F47FF0E933B79823D0DFD9F3647A82CFC28FB41FBB2226ED1D08B76F86FEB45DC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Dubai)]} {.. LoadTimeZoneFile Asia/Dubai..}..set TZData(:Asia/Muscat) $TZData(:Asia/Dubai)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7625
                                                                                                                                                                                                            Entropy (8bit):3.7113086720696398
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:R3pv/7V6Aj8aZaNlKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYjlBKb0l:R3v/AauivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                            MD5:2ADD0DFC1F133E4D044727234251A3DC
                                                                                                                                                                                                            SHA1:0D1502986258349E384017BA6CB8FA0AC424638C
                                                                                                                                                                                                            SHA-256:3C3E4844C70D361893EF022D6C3C8E38B243E91D40C5A726C924355476816F25
                                                                                                                                                                                                            SHA-512:70CDD53E7E44EDABF653A4F92EECBF5BB20A31DA95D65209D1CADE7DD9FC68946B8EC8829C28AE00BE5F42AAB545B9282CBBCFC5834437D6A94A179BF4FE0141
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Nicosia) {.. {-9223372036854775808 8008 0 LMT}.. {-1518920008 7200 0 EET}.. {166572000 10800 1 EEST}.. {182293200 7200 0 EET}.. {200959200 10800 1 EEST}.. {213829200 7200 0 EET}.. {228866400 10800 1 EEST}.. {243982800 7200 0 EET}.. {260316000 10800 1 EEST}.. {276123600 7200 0 EET}.. {291765600 10800 1 EEST}.. {307486800 7200 0 EET}.. {323820000 10800 1 EEST}.. {338936400 7200 0 EET}.. {354664800 10800 1 EEST}.. {370386000 7200 0 EET}.. {386114400 10800 1 EEST}.. {401835600 7200 0 EET}.. {417564000 10800 1 EEST}.. {433285200 7200 0 EET}.. {449013600 10800 1 EEST}.. {465339600 7200 0 EET}.. {481068000 10800 1 EEST}.. {496789200 7200 0 EET}.. {512517600 10800 1 EEST}.. {528238800 7200 0 EET}.. {543967200 10800 1 EEST}.. {559688400 7200 0 EET}.. {575416800 10800 1 EEST}.. {591138000 7200 0 EET}.. {606866400 10800 1 EEST}.. {62258760
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2063
                                                                                                                                                                                                            Entropy (8bit):3.718004112421892
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:526enddzXJfsFN/3sFrOksF/sF7IyksF7FRZsFLsFTsFcsFk73sFK/XCFKTipnFf:5l40yVRB7VfXucydm46I/CTxwf
                                                                                                                                                                                                            MD5:513B6A2AF76DAED9002C037BEC99862F
                                                                                                                                                                                                            SHA1:82D1C47BDF46B8B901C35BACACE8595C093BF5F2
                                                                                                                                                                                                            SHA-256:96A445D47D834C28480D1E2036ECA4962B35AFA494C219065D4879F71C1830DB
                                                                                                                                                                                                            SHA-512:2FE5AF4FA9D6AAB4FBD8E354789B82D39FA1B52394D3A0ABFBC6A30A531E0B7429A3D9AC7835A2843A6E9859E0255565F151FDFC87004ACB4EBD1AAD40BDA8A4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Novokuznetsk) {.. {-9223372036854775808 20928 0 LMT}.. {-1441259328 21600 0 +06}.. {-1247551200 25200 0 +08}.. {354906000 28800 1 +08}.. {370713600 25200 0 +07}.. {386442000 28800 1 +08}.. {402249600 25200 0 +07}.. {417978000 28800 1 +08}.. {433785600 25200 0 +07}.. {449600400 28800 1 +08}.. {465332400 25200 0 +07}.. {481057200 28800 1 +08}.. {496782000 25200 0 +07}.. {512506800 28800 1 +08}.. {528231600 25200 0 +07}.. {543956400 28800 1 +08}.. {559681200 25200 0 +07}.. {575406000 28800 1 +08}.. {591130800 25200 0 +07}.. {606855600 28800 1 +08}.. {622580400 25200 0 +07}.. {638305200 28800 1 +08}.. {654634800 25200 0 +07}.. {670359600 21600 0 +07}.. {670363200 25200 1 +07}.. {686088000 21600 0 +06}.. {695764800 25200 0 +08}.. {701809200 28800 1 +08}.. {717534000 25200 0 +07}.. {733258800 28800 1 +08}.. {748983600 25200 0 +07}.. {
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2121
                                                                                                                                                                                                            Entropy (8bit):3.714792994893581
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:52sve20ruXJfsFN/3sFrOksF/sF7IyksF7FRZsFLsFTsFcsFk73sFK/XCFKTipnF:5Hc40yVRB7VfXu0TKmtTTDOWQ
                                                                                                                                                                                                            MD5:AC8C8D768503C8334A9FBAEF4C3A9CAB
                                                                                                                                                                                                            SHA1:CA10BB99E2D7AB329229759BD4801068A3AEB6D5
                                                                                                                                                                                                            SHA-256:EF799077291F6B3B19E0AEC88F224BB592FAAD09D30740F2376D3D20F2169639
                                                                                                                                                                                                            SHA-512:34049B1AC4254F999C3E5AD8CB31ABF88AC2D972E20E19927F33CC59935354F92125A0342A413E64227E8AE29DDFC2FFE5F67AE538C89D8EBAD7FCA889321DFA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Novosibirsk) {.. {-9223372036854775808 19900 0 LMT}.. {-1579476700 21600 0 +06}.. {-1247551200 25200 0 +08}.. {354906000 28800 1 +08}.. {370713600 25200 0 +07}.. {386442000 28800 1 +08}.. {402249600 25200 0 +07}.. {417978000 28800 1 +08}.. {433785600 25200 0 +07}.. {449600400 28800 1 +08}.. {465332400 25200 0 +07}.. {481057200 28800 1 +08}.. {496782000 25200 0 +07}.. {512506800 28800 1 +08}.. {528231600 25200 0 +07}.. {543956400 28800 1 +08}.. {559681200 25200 0 +07}.. {575406000 28800 1 +08}.. {591130800 25200 0 +07}.. {606855600 28800 1 +08}.. {622580400 25200 0 +07}.. {638305200 28800 1 +08}.. {654634800 25200 0 +07}.. {670359600 21600 0 +07}.. {670363200 25200 1 +07}.. {686088000 21600 0 +06}.. {695764800 25200 0 +08}.. {701809200 28800 1 +08}.. {717534000 25200 0 +07}.. {733258800 28800 1 +08}.. {738090000 25200 0 +07}.. {7
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2055
                                                                                                                                                                                                            Entropy (8bit):3.6912374223526396
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5abexPvO1FMnFP1FCnFHnFKqenFdDnFQgOnFxjPnFITnFonFJynFAT4TBThSv0FP:5asvjdqxph01NSvPETKmtTTDO0
                                                                                                                                                                                                            MD5:3E06B20B0B62AA09FA03082FAEE4FD62
                                                                                                                                                                                                            SHA1:8886EC80528ECA13D3364138BFFE92F881768169
                                                                                                                                                                                                            SHA-256:2605CD1E26E4AB48BCB4399BB5B17BAD115A47F87BA3DD54B55BB50C3FE82606
                                                                                                                                                                                                            SHA-512:04C1B6A898D12C8EA1B0B2F6665C870434061C63CC8F7A067BFC708E9828BA2E60104B82E2025E42D51DA2F485890C4D34EC0341EF466A7942649BE64F5EEE17
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Omsk) {.. {-9223372036854775808 17610 0 LMT}.. {-1582088010 18000 0 +05}.. {-1247547600 21600 0 +07}.. {354909600 25200 1 +07}.. {370717200 21600 0 +06}.. {386445600 25200 1 +07}.. {402253200 21600 0 +06}.. {417981600 25200 1 +07}.. {433789200 21600 0 +06}.. {449604000 25200 1 +07}.. {465336000 21600 0 +06}.. {481060800 25200 1 +07}.. {496785600 21600 0 +06}.. {512510400 25200 1 +07}.. {528235200 21600 0 +06}.. {543960000 25200 1 +07}.. {559684800 21600 0 +06}.. {575409600 25200 1 +07}.. {591134400 21600 0 +06}.. {606859200 25200 1 +07}.. {622584000 21600 0 +06}.. {638308800 25200 1 +07}.. {654638400 21600 0 +06}.. {670363200 18000 0 +06}.. {670366800 21600 1 +06}.. {686091600 18000 0 +05}.. {695768400 21600 0 +07}.. {701812800 25200 1 +07}.. {717537600 21600 0 +06}.. {733262400 25200 1 +07}.. {748987200 21600 0 +06}.. {76471200
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1664
                                                                                                                                                                                                            Entropy (8bit):3.708603813141953
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:53PvalvNhQQvmRKqv0fvzQIovWdvEGvDaDv7w9hYwr:JHaBNKs6b03zB0WJEuDa77w9hYA
                                                                                                                                                                                                            MD5:A3BD0C15642AE4F001F98F8E060E8374
                                                                                                                                                                                                            SHA1:366F3C7FD4000AC23B79AB0FF4429371ED323B81
                                                                                                                                                                                                            SHA-256:933BBCD7AE0BF59A5B4A6E0EF74C237FEEDC42E6A3AEB2158131AA70FBA6FE47
                                                                                                                                                                                                            SHA-512:16D8692D3EA96D3594E6220A6989BBFBB926A66EEBEB240C4DC68BE75C69C5206659D9D341D92AE6128928FD38A5F45B445621CBBBA4E4BA8C34C3AC52BF3C08
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Oral) {.. {-9223372036854775808 12324 0 LMT}.. {-1441164324 10800 0 +03}.. {-1247540400 18000 0 +05}.. {354913200 21600 1 +06}.. {370720800 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 14400 0 +04}.. {606866400 18000 1 +04}.. {622591200 14400 0 +04}.. {638316000 18000 1 +04}.. {654645600 14400 0 +04}.. {670370400 18000 1 +04}.. {686095200 14400 0 +04}.. {701816400 14400 0 +04}.. {701820000 18000 1 +04}.. {717544800 14400 0 +04}.. {733269600 18000 1 +04}.. {74899440
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):180
                                                                                                                                                                                                            Entropy (8bit):4.958543249401788
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8VLYO5YFfXHAIgN8ELYOJARL/2WFKeHKLNM0WFKELt:SlSWB9vsM3y1LePHAIgKELtAN/2wKTNg
                                                                                                                                                                                                            MD5:EBF01E229CC41EB8B27650A3D668EDC1
                                                                                                                                                                                                            SHA1:33E1B252C1B45EAE326FCF8CC7C80C78A46F7E8D
                                                                                                                                                                                                            SHA-256:DCEE88876D00396918F43DECA421B6C9B02F84B5866A2CE16E641B814B390A9F
                                                                                                                                                                                                            SHA-512:80840600F37A256B8FD9933760FBAE7C13DE1E24EFD970E47BE8DEC731DFABF6D6FB76999BEEC775FF8C8B8719E94788ED7EEB04376A34C827ACB443F720F7E3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Bangkok)]} {.. LoadTimeZoneFile Asia/Bangkok..}..set TZData(:Asia/Phnom_Penh) $TZData(:Asia/Bangkok)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):369
                                                                                                                                                                                                            Entropy (8bit):4.492596995768464
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2wKT5PDm2OHUeoH99xV/1kc5k/MVSSFFCLkvScH+dMVSSFL1CnF4mMz:MB862L5bmdHFCRV/6c5kMxGLkHHaMxFn
                                                                                                                                                                                                            MD5:9ADB1A9E41A143A06116E24EA0A53D90
                                                                                                                                                                                                            SHA1:6E50B549E1A705C0090BD5EDE26F7DED78CDF71A
                                                                                                                                                                                                            SHA-256:AC8370AEDF5FE3FE1E80710CE117DEE23815BE377D418E4B4F3259A1930E8DBF
                                                                                                                                                                                                            SHA-512:92790B20B960AC518AB2E18F902C6E0BA887F268909F5571CAC1068F5E719CCF6943AE6902DA1B683E170658B5E7BE06C6A187C1C0A652DD052D5BD0B2A7B84D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Pontianak) {.. {-9223372036854775808 26240 0 LMT}.. {-1946186240 26240 0 PMT}.. {-1172906240 27000 0 +0730}.. {-881220600 32400 0 +09}.. {-766054800 27000 0 +0730}.. {-683883000 28800 0 +08}.. {-620812800 27000 0 +0730}.. {-189415800 28800 0 WITA}.. {567964800 25200 0 WIB}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):273
                                                                                                                                                                                                            Entropy (8bit):4.709411633376997
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2wK8cE4SDm2OHnNoH9Aw8vmVuT0vjLtcjviov:MB8620cExmdHnNCGv2Ezv
                                                                                                                                                                                                            MD5:727BBC1A1662B500F616F544A484F213
                                                                                                                                                                                                            SHA1:93C1D902D9D4AA4197C7D16C61FB784AC01D0DE5
                                                                                                                                                                                                            SHA-256:29BA17F756F5C0BBA30FEBF44E620504D04921C832BD1CB56E1B60EF288B57DF
                                                                                                                                                                                                            SHA-512:C3C91E2F180109FF33E6491722F679A1B8DCE8CD31DE006D7FF2CBE270C008E927507C953641D28EE77D139BBEA54DEA1B7DBD6C30B208DDAB1B58756C32AC02
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Pyongyang) {.. {-9223372036854775808 30180 0 LMT}.. {-1948782180 30600 0 KST}.. {-1830414600 32400 0 JST}.. {-768646800 32400 0 KST}.. {1439564400 30600 0 KST}.. {1525446000 32400 0 KST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):176
                                                                                                                                                                                                            Entropy (8bit):4.851251407399968
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/2WFKK3ovXMXGm2OHPFV4YoHsQKb3VvVsRYovFFF3FRVGsWr:SlSWB9eg/2wKK3yXDm2OHoYoHxcvSNFS
                                                                                                                                                                                                            MD5:CBA9635133F88AD3B27E23B95430C27C
                                                                                                                                                                                                            SHA1:5E41232EC03BBC71B522F58CB2D05E6BFFFF1A75
                                                                                                                                                                                                            SHA-256:18CCA69F933795CE3F7DB31506EFC063E6CE1DFDCAB32AA387C398456D7F7E1F
                                                                                                                                                                                                            SHA-512:D7C43F1F9ADA54C914ADB3CB2C9063EB7044089CFC7755ACFD08828CDEBA3C116AE2BE916ABE5D561E63699B921BC52636DD0BBC2C4304F813616D320D7DDAAF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Qatar) {.. {-9223372036854775808 12368 0 LMT}.. {-1577935568 14400 0 +04}.. {76190400 10800 0 +03}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1668
                                                                                                                                                                                                            Entropy (8bit):3.7299735983334195
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5DwvalvNhQQvmRKqv0fvzQIovWdvEGvDaDvs5vZlovKWyvNSvTqvIQvyovklvqQA:BMaBNKs6b03zB0WJEuDa7sFZiKWaN6TE
                                                                                                                                                                                                            MD5:F5DBE4E72FA5AB0019CC98C8E21EC86E
                                                                                                                                                                                                            SHA1:27ECB901AA07C18EA7F38235E8EFE0B1635FEFBC
                                                                                                                                                                                                            SHA-256:4191629B874C988291E8FD13E675A3ED685D677F6541313975FC4610E47F1DCD
                                                                                                                                                                                                            SHA-512:D5EFD4EFFFFE2E41909AEB7B67BD1FA6FAF4B8E9AC645518D5B33BD1B3C5084F59D47D4ED052E0D4B9F9989BDDBA3AECB3D1E67F5237914D24C01F9C95242396
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Qostanay) {.. {-9223372036854775808 15268 0 LMT}.. {-1441167268 14400 0 +04}.. {-1247544000 18000 0 +05}.. {354913200 21600 1 +06}.. {370720800 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 14400 0 +04}.. {670370400 18000 1 +04}.. {686095200 14400 0 +04}.. {695772000 18000 0 +05}.. {701816400 21600 1 +05}.. {717541200 18000 0 +05}.. {733266000 21600 1 +05}.. {7489
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1670
                                                                                                                                                                                                            Entropy (8bit):3.734572151642808
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5NvalvNhQQvmRKqv0fvzQIovWdvEGvDaDvs5vZlovKWgvNSvTqvIQvyovklvqQX0:TaBNKs6b03zB0WJEuDa7sFZiKWcN6Tir
                                                                                                                                                                                                            MD5:026EC6E479EC006C4398288362254680
                                                                                                                                                                                                            SHA1:24AD03DD21DA394B3423D27211955BFD694F8E73
                                                                                                                                                                                                            SHA-256:CD6B067AA3EF6935B4E89CA36E6A03FCB97F1E0EE61A7B5D46C06BF4DE140774
                                                                                                                                                                                                            SHA-512:023AC55E118F13A31CE996C7BA155C90D47DEB6C223EEB3C0EE7B702871FF0CCA13CDF61D65FDDABE41B888CD7A74274AA5730059CC5688F8ED4DDBF8FE4ECA4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Qyzylorda) {.. {-9223372036854775808 15712 0 LMT}.. {-1441167712 14400 0 +04}.. {-1247544000 18000 0 +05}.. {354913200 21600 1 +06}.. {370720800 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 14400 0 +04}.. {670370400 18000 1 +04}.. {701812800 18000 0 +05}.. {701816400 21600 1 +05}.. {717541200 18000 0 +05}.. {733266000 21600 1 +05}.. {748990800 18000 0 +05}.. {764
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):174
                                                                                                                                                                                                            Entropy (8bit):4.812955128020714
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8nv3vXHAIgNnDA6RL/2WFK02KQMFfh4WFKsyn:SlSWB9vsM3yHvPHAIg15N/2wK0GEJ4wy
                                                                                                                                                                                                            MD5:BD3F294F1EDDD21467E980C9F5A0E7DE
                                                                                                                                                                                                            SHA1:11A3FC3E4489C18BDF9BFFB4C44615559D9DD99D
                                                                                                                                                                                                            SHA-256:E4D2C38D8E7377A528291A88129CDAC40CA4D40A5F1CD8ADB98228527556906E
                                                                                                                                                                                                            SHA-512:FA5FD600627793EABB83C1066BE246A47BCCE1FC57830596B9C0CDE8901B949AF178ABDE876C3B73CC3751312E8A4C03C390888B0B5A9669F511344143F83073
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Yangon)]} {.. LoadTimeZoneFile Asia/Yangon..}..set TZData(:Asia/Rangoon) $TZData(:Asia/Yangon)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):148
                                                                                                                                                                                                            Entropy (8bit):4.973311159904374
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/2WFK814PMXGm2OHFukeoHqUi9VssWYcv:SlSWB9eg/2wK81GDm2OHF7eoHvi9V1Wr
                                                                                                                                                                                                            MD5:AD3236CFF141732831732357AB181EE3
                                                                                                                                                                                                            SHA1:EAF51A63898A2048EA5FBE9BA4C001EEE37FFDB2
                                                                                                                                                                                                            SHA-256:411E31D09FFA48E44169C42661AE2F7FC142460BCAA216837D8C4740983CA7BD
                                                                                                                                                                                                            SHA-512:6CA2D89C02568580786BE98A863453ADCF4D21CAC52E5B44C4F7A05E76D29AEB3E28E353D6FB758BB553DBC8F35389462B388F61E94C68F5DB50A3E8C429336D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Riyadh) {.. {-9223372036854775808 11212 0 LMT}.. {-719636812 10800 0 +03}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):188
                                                                                                                                                                                                            Entropy (8bit):4.946090704619887
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8I65eV5XHAIgN2h6560ARL/2WFKwJ6h4WFK365ey:SlSWB9vsM3yJAVJHAIgA4k0AN/2wKl4i
                                                                                                                                                                                                            MD5:0766480A295525EE5D65F1ED32094858
                                                                                                                                                                                                            SHA1:7A2D68E1009DDD809A4A700931456C617DCD343A
                                                                                                                                                                                                            SHA-256:C695981A0DF691C3F4509999FBC52858ADC75024CCCBDEFBE1094FED17E809E4
                                                                                                                                                                                                            SHA-512:A21536FB61A64E953E8D6414FF0AEF1BC7E68A33C5DCF7090517A91FC449B96A93A4FBDF2C00682540D1193FDB29603349F5BDB455FD90045FDBCA61247A9860
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Ho_Chi_Minh)]} {.. LoadTimeZoneFile Asia/Ho_Chi_Minh..}..set TZData(:Asia/Saigon) $TZData(:Asia/Ho_Chi_Minh)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2117
                                                                                                                                                                                                            Entropy (8bit):3.7276904131666577
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5q+3Vv+0j6lua2Gg/3gO8UoflcXRDhUBAc+:YxIa2GOT8tiXBC6c+
                                                                                                                                                                                                            MD5:295D51B8FBBE890C97637687B8F32322
                                                                                                                                                                                                            SHA1:7BB72B0EC783898DDF625D275E3BBB964D1693FB
                                                                                                                                                                                                            SHA-256:D7D0EA5CEF908442AB0D777A4B097BED18540CD5280FF63F33DD989E27E72908
                                                                                                                                                                                                            SHA-512:9B3E3BA01EAE38A00B0EE8A8FB17191CB4ED2EE9E46AE06403BA8C1193804764C86599840DC03E0C6A631456E1BE2BC560BDF6CF0450068EF78A6E494041326C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Sakhalin) {.. {-9223372036854775808 34248 0 LMT}.. {-2031039048 32400 0 +09}.. {-768560400 39600 0 +12}.. {354891600 43200 1 +12}.. {370699200 39600 0 +11}.. {386427600 43200 1 +12}.. {402235200 39600 0 +11}.. {417963600 43200 1 +12}.. {433771200 39600 0 +11}.. {449586000 43200 1 +12}.. {465318000 39600 0 +11}.. {481042800 43200 1 +12}.. {496767600 39600 0 +11}.. {512492400 43200 1 +12}.. {528217200 39600 0 +11}.. {543942000 43200 1 +12}.. {559666800 39600 0 +11}.. {575391600 43200 1 +12}.. {591116400 39600 0 +11}.. {606841200 43200 1 +12}.. {622566000 39600 0 +11}.. {638290800 43200 1 +12}.. {654620400 39600 0 +11}.. {670345200 36000 0 +11}.. {670348800 39600 1 +11}.. {686073600 36000 0 +10}.. {695750400 39600 0 +12}.. {701794800 43200 1 +12}.. {717519600 39600 0 +11}.. {733244400 43200 1 +12}.. {748969200 39600 0 +11}.. {76469
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):879
                                                                                                                                                                                                            Entropy (8bit):3.9460497720710506
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5t8eZd7QvalvNhQQvmRKqvzQfv7PQIovWxrvEGvDWdDvs5v/RlovKT10Sv6r:5MvalvNhQQvmRKqv0fvzQIovWdvEGvDO
                                                                                                                                                                                                            MD5:10A758996B0DF756E520541BEA9B7D75
                                                                                                                                                                                                            SHA1:137E5FD4E00CFA4B3939EF11868862B7F93D87CD
                                                                                                                                                                                                            SHA-256:35E4B905723891281D9A6A0A1FD3760A3A48136E1419C686BE31ACE83BF7AA9D
                                                                                                                                                                                                            SHA-512:7E32661731EAB2ED8C387533ACCB4853F5B6225BAC11E93247E7B06D7AA856E6A665F63718BFE395CFD00F80A4C16789D7097FFA8DAD88B1D707BF9C155C1D4C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Samarkand) {.. {-9223372036854775808 16073 0 LMT}.. {-1441168073 14400 0 +04}.. {-1247544000 18000 0 +05}.. {354913200 21600 1 +06}.. {370720800 21600 0 +06}.. {386445600 18000 0 +05}.. {386449200 21600 1 +05}.. {402256800 18000 0 +05}.. {417985200 21600 1 +05}.. {433792800 18000 0 +05}.. {449607600 21600 1 +05}.. {465339600 18000 0 +05}.. {481064400 21600 1 +05}.. {496789200 18000 0 +05}.. {512514000 21600 1 +05}.. {528238800 18000 0 +05}.. {543963600 21600 1 +05}.. {559688400 18000 0 +05}.. {575413200 21600 1 +05}.. {591138000 18000 0 +05}.. {606862800 21600 1 +05}.. {622587600 18000 0 +05}.. {638312400 21600 1 +05}.. {654642000 18000 0 +05}.. {670366800 21600 1 +05}.. {686091600 18000 0 +05}.. {694206000 18000 0 +05}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):985
                                                                                                                                                                                                            Entropy (8bit):4.121802167517286
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5AemgvHzF+zg2c+z3NGmJhIUfqII8yHg/zoD:5F/nfWUBISHg/G
                                                                                                                                                                                                            MD5:A1DE6975DEA70D7241B5B3C43E1EA3AA
                                                                                                                                                                                                            SHA1:35EE563A2BCA77C761F7E878997763EA8D258040
                                                                                                                                                                                                            SHA-256:C4F82C94650572FE4D03BC1FE54CED8F4BF55DFBEE855D52DE3EA6378240AF93
                                                                                                                                                                                                            SHA-512:1639B0609115DBEA6A381986A732A5CA1523952AEF84843B4D714D5B2FF40B16C4166D8D60D31D4FC2C2BA34DED1F6DB39474336195603562265BDBF71687696
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Seoul) {.. {-9223372036854775808 30472 0 LMT}.. {-1948782472 30600 0 KST}.. {-1830414600 32400 0 JST}.. {-767350800 32400 0 KST}.. {-681210000 36000 1 KDT}.. {-672228000 32400 0 KST}.. {-654771600 36000 1 KDT}.. {-640864800 32400 0 KST}.. {-623408400 36000 1 KDT}.. {-609415200 32400 0 KST}.. {-588848400 36000 1 KDT}.. {-577965600 32400 0 KST}.. {-498128400 30600 0 KST}.. {-462702600 34200 1 KDT}.. {-451733400 30600 0 KST}.. {-429784200 34200 1 KDT}.. {-418296600 30600 0 KST}.. {-399544200 34200 1 KDT}.. {-387451800 30600 0 KST}.. {-368094600 34200 1 KDT}.. {-356002200 30600 0 KST}.. {-336645000 34200 1 KDT}.. {-324552600 30600 0 KST}.. {-305195400 34200 1 KDT}.. {-293103000 30600 0 KST}.. {-264933000 32400 0 KST}.. {547578000 36000 1 KDT}.. {560883600 32400 0 KST}.. {579027600 36000 1 KDT}.. {592333200 32400 0 KST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):981
                                                                                                                                                                                                            Entropy (8bit):4.16042656890735
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5Te3vvZJzHjwH6kHp7FH32AzHjZBHNHlQHuHxmHUjH6zHj2HBHeC:5ovZZO7lLpT24
                                                                                                                                                                                                            MD5:A266AA43A84FD5E4890BC77AA4E240D0
                                                                                                                                                                                                            SHA1:CD88C5D451CD7D3F50C9B36FDD47C84D20377441
                                                                                                                                                                                                            SHA-256:3AABB42D9EFE95D906B7F34640E7815919A1A20979EBB6EC1527FCAA3B09B22A
                                                                                                                                                                                                            SHA-512:13AE48F58C9AF24002F0FE4F28BF96B10EE0ED293E0DE9D29BCEBAAE102B2EA818F42CA4069544A254C95444A48604EC57E6AB2BEBDA4B5E72C82B49E61AD0A0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Shanghai) {.. {-9223372036854775808 29143 0 LMT}.. {-2177481943 28800 0 CST}.. {-1600675200 32400 1 CDT}.. {-1585904400 28800 0 CST}.. {-933667200 32400 1 CDT}.. {-922093200 28800 0 CST}.. {-908870400 32400 1 CDT}.. {-888829200 28800 0 CST}.. {-881049600 32400 1 CDT}.. {-767869200 28800 0 CST}.. {-745833600 32400 1 CDT}.. {-733827600 28800 0 CST}.. {-716889600 32400 1 CDT}.. {-699613200 28800 0 CST}.. {-683884800 32400 1 CDT}.. {-670669200 28800 0 CST}.. {-652348800 32400 1 CDT}.. {-650016000 28800 0 CST}.. {515527200 32400 1 CDT}.. {527014800 28800 0 CST}.. {545162400 32400 1 CDT}.. {558464400 28800 0 CST}.. {577216800 32400 1 CDT}.. {589914000 28800 0 CST}.. {608666400 32400 1 CDT}.. {621968400 28800 0 CST}.. {640116000 32400 1 CDT}.. {653418000 28800 0 CST}.. {671565600 32400 1 CDT}.. {684867600 28800 0 CST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):372
                                                                                                                                                                                                            Entropy (8bit):4.436676898144829
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2wKfbSDm2OHxdoHvm5vWOb/MVSYyF/3MesF5XJSx0dMVSSFF8kvScHS:MB862nbGmdHDCvsvDTMsF/CFDMx/HHbe
                                                                                                                                                                                                            MD5:C3D13D921E4C6E475910E5080B761C32
                                                                                                                                                                                                            SHA1:8C5AE73C4098D03908E5D567FD7C4D827601D718
                                                                                                                                                                                                            SHA-256:05C76B58A4E356FD358E24FBC71FAE98DCB18C441C8D8CBB13A18D4F6E406062
                                                                                                                                                                                                            SHA-512:3A620597469D31577ECAAA098C95C244F0C288ABACE9E8964D8641154C1893967EFBD7211A41751D0D4CC1B0B9A2286F11738EFB7D01F110A4826BBE1844A2EA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Singapore) {.. {-9223372036854775808 24925 0 LMT}.. {-2177477725 24925 0 SMT}.. {-2038200925 25200 0 +07}.. {-1167634800 26400 1 +0720}.. {-1073028000 26400 0 +0720}.. {-894180000 27000 0 +0730}.. {-879665400 32400 0 +09}.. {-767005200 27000 0 +0730}.. {378664200 28800 0 +08}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2064
                                                                                                                                                                                                            Entropy (8bit):3.7913177223006698
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5HJeidmbv+OC+jsuwltZQONEa2Ggf3augO8UoxLyHdX/CX6bW4Bv/7NKxwy:5HSv+0j6lua2Gg/3gO8UoOZU2Wc/pKf
                                                                                                                                                                                                            MD5:B4FA38E884A85F6BD47C8BB02BB0500C
                                                                                                                                                                                                            SHA1:1DD135B79CC0D81C048D7B2C6BE0CF71171DD19E
                                                                                                                                                                                                            SHA-256:705D6D8360C2DCD51E909E39E1910FE876145220D151031612DA36B247207395
                                                                                                                                                                                                            SHA-512:2D32AAAF1BCC865B5F2810BFE0FB82BE98140BB5F2ECA1DA7FD148A3074DA127B81242F17B8BA9C9E259B61CBB123FD1513CCE6A85C8D7679ADFC0D689B552BB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Srednekolymsk) {.. {-9223372036854775808 36892 0 LMT}.. {-1441188892 36000 0 +10}.. {-1247565600 39600 0 +12}.. {354891600 43200 1 +12}.. {370699200 39600 0 +11}.. {386427600 43200 1 +12}.. {402235200 39600 0 +11}.. {417963600 43200 1 +12}.. {433771200 39600 0 +11}.. {449586000 43200 1 +12}.. {465318000 39600 0 +11}.. {481042800 43200 1 +12}.. {496767600 39600 0 +11}.. {512492400 43200 1 +12}.. {528217200 39600 0 +11}.. {543942000 43200 1 +12}.. {559666800 39600 0 +11}.. {575391600 43200 1 +12}.. {591116400 39600 0 +11}.. {606841200 43200 1 +12}.. {622566000 39600 0 +11}.. {638290800 43200 1 +12}.. {654620400 39600 0 +11}.. {670345200 36000 0 +11}.. {670348800 39600 1 +11}.. {686073600 36000 0 +10}.. {695750400 39600 0 +12}.. {701794800 43200 1 +12}.. {717519600 39600 0 +11}.. {733244400 43200 1 +12}.. {748969200 39600 0 +11}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1344
                                                                                                                                                                                                            Entropy (8bit):4.062084847879695
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5X2eIvZPzGzHjZBHNHlQHKn3HnHNd9HiHkHBHaHLHMtyH9Qm+zHFOzHZ32HZvHiR:5Xi1ypBvt1mwO3Kq46T
                                                                                                                                                                                                            MD5:AECA800C8F2A679D0B19E5BB90AFD858
                                                                                                                                                                                                            SHA1:2C7DCEB709F9A4312C511971FE1E6A9DC1FBD0E8
                                                                                                                                                                                                            SHA-256:389C9D3EE2970665D0D8C5CB61B8B790C5FBDDC0DF0BF2B9753046F5953A477F
                                                                                                                                                                                                            SHA-512:C2D6BB4FEB5848D0704647D26F94C0BD8CD7E834AA2187EC9C877E80157E9CC225BBA3BECEE0148894C8639105D292AB50EE95830992BF357C632ACF001E020F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Taipei) {.. {-9223372036854775808 29160 0 LMT}.. {-2335248360 28800 0 CST}.. {-1017820800 32400 0 JST}.. {-766224000 28800 0 CST}.. {-745833600 32400 1 CDT}.. {-733827600 28800 0 CST}.. {-716889600 32400 1 CDT}.. {-699613200 28800 0 CST}.. {-683884800 32400 1 CDT}.. {-670669200 28800 0 CST}.. {-652348800 32400 1 CDT}.. {-639133200 28800 0 CST}.. {-620812800 32400 1 CDT}.. {-607597200 28800 0 CST}.. {-589276800 32400 1 CDT}.. {-576061200 28800 0 CST}.. {-562924800 32400 1 CDT}.. {-541760400 28800 0 CST}.. {-528710400 32400 1 CDT}.. {-510224400 28800 0 CST}.. {-497174400 32400 1 CDT}.. {-478688400 28800 0 CST}.. {-465638400 32400 1 CDT}.. {-449830800 28800 0 CST}.. {-434016000 32400 1 CDT}.. {-418208400 28800 0 CST}.. {-402480000 32400 1 CDT}.. {-386672400 28800 0 CST}.. {-370944000 32400 1 CDT}.. {-355136400 28800 0 CST}.. {-3394080
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):878
                                                                                                                                                                                                            Entropy (8bit):3.9280321712564845
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5geQqdNRvOt81FCuLqecDngO6jPvTpYy5T4TXvKT10Sv6r:5+EvdJqxiF0rvK50Sv6r
                                                                                                                                                                                                            MD5:DB59DB8E401E12917B7367D5604D3DE6
                                                                                                                                                                                                            SHA1:7CC7C5C1DB551BD381B833C81746201D36BC59A9
                                                                                                                                                                                                            SHA-256:4445F3F892C7267A6867009CC1A3F0B0548D0240408375A9D15360B28993C2A9
                                                                                                                                                                                                            SHA-512:2C7AE63C408A9F06F973AAC16845E1DBE92D15A421BBBE420914F21155AD5E57CD058D7E4427E43185E023D2FF475EBF9D74003ECEF004FF4E5F9D5681ADFB80
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Tashkent) {.. {-9223372036854775808 16631 0 LMT}.. {-1441168631 18000 0 +05}.. {-1247547600 21600 0 +06}.. {354909600 25200 1 +06}.. {370717200 21600 0 +06}.. {386445600 25200 1 +06}.. {402253200 21600 0 +06}.. {417981600 25200 1 +06}.. {433789200 21600 0 +06}.. {449604000 25200 1 +06}.. {465336000 21600 0 +06}.. {481060800 25200 1 +06}.. {496785600 21600 0 +06}.. {512510400 25200 1 +06}.. {528235200 21600 0 +06}.. {543960000 25200 1 +06}.. {559684800 21600 0 +06}.. {575409600 25200 1 +06}.. {591134400 21600 0 +06}.. {606859200 25200 1 +06}.. {622584000 21600 0 +06}.. {638308800 25200 1 +06}.. {654638400 21600 0 +06}.. {670363200 18000 0 +05}.. {670366800 21600 1 +05}.. {686091600 18000 0 +05}.. {694206000 18000 0 +05}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1729
                                                                                                                                                                                                            Entropy (8bit):3.6815162494646034
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5yBeqvIdZlykbocXcwJUE5iu8JmFebARoc9lVNk7/9bq8dq16b3C9UPqUsx9Ul4N:5MmsUf8mFpNWFnytO6VnYK
                                                                                                                                                                                                            MD5:C376C9ED66F6CC011E063D3E8E0DCED1
                                                                                                                                                                                                            SHA1:13C6345F8CB0EC79FE7C78B156C5737BCB66E49E
                                                                                                                                                                                                            SHA-256:B637BB0E49144C717E99E93540CB2C4D3695D63B91FE42547F2F0AA006498693
                                                                                                                                                                                                            SHA-512:FD60192CBEDC91C5D6B3B5E6F19DEDCAE14DCF48DCAE6D4865A8F0BBDC01CBF8DAAE92C4C46C353AF5B3EEE36CCC87B23F193DDF221132F5404C42507B708364
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Tbilisi) {.. {-9223372036854775808 10751 0 LMT}.. {-2840151551 10751 0 TBMT}.. {-1441162751 10800 0 +03}.. {-405140400 14400 0 +04}.. {354916800 18000 1 +04}.. {370724400 14400 0 +04}.. {386452800 18000 1 +04}.. {402260400 14400 0 +04}.. {417988800 18000 1 +04}.. {433796400 14400 0 +04}.. {449611200 18000 1 +04}.. {465343200 14400 0 +04}.. {481068000 18000 1 +04}.. {496792800 14400 0 +04}.. {512517600 18000 1 +04}.. {528242400 14400 0 +04}.. {543967200 18000 1 +04}.. {559692000 14400 0 +04}.. {575416800 18000 1 +04}.. {591141600 14400 0 +04}.. {606866400 18000 1 +04}.. {622591200 14400 0 +04}.. {638316000 18000 1 +04}.. {654645600 14400 0 +04}.. {670370400 10800 0 +03}.. {670374000 14400 1 +03}.. {686098800 10800 0 +03}.. {694213200 10800 0 +03}.. {701816400 14400 1 +03}.. {717537600 10800 0 +03}.. {733266000 14400 1 +03}.. {748
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2354
                                                                                                                                                                                                            Entropy (8bit):3.666553647637418
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5Z2eendFalxbr1p4USUcESUUxSuEqzSUUongA3jJW3eY37U8uuZrc3cNWH1/ANzx:54G9SOSWzx1qcK83kv3OR0xV1ox
                                                                                                                                                                                                            MD5:A7A174A14E51E0ACD7092D2A5AA50F99
                                                                                                                                                                                                            SHA1:69ADDDDB68084B90819AD49A5230D5B0E1A9CD85
                                                                                                                                                                                                            SHA-256:25870503A8A679DA13B98117BD473EAA0C79B094B85D3AD50629FF0946D5EACE
                                                                                                                                                                                                            SHA-512:1ECFB558B13C94BDC848E7BBBB0CA1BB854BB12E112EBF306045EC14F00CE3E3C2DA51EBA8AF2D63C95D71B945647C3D9E9881158FE128DEBE940A742C4BFEB1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Tehran) {.. {-9223372036854775808 12344 0 LMT}.. {-1704165944 12344 0 TMT}.. {-1090466744 12600 0 +0330}.. {227820600 16200 1 +0330}.. {246227400 14400 0 +04}.. {259617600 18000 1 +04}.. {271108800 14400 0 +04}.. {283982400 12600 0 +0330}.. {296598600 16200 1 +0330}.. {306531000 12600 0 +0330}.. {322432200 16200 1 +0330}.. {338499000 12600 0 +0330}.. {673216200 16200 1 +0330}.. {685481400 12600 0 +0330}.. {701209800 16200 1 +0330}.. {717103800 12600 0 +0330}.. {732745800 16200 1 +0330}.. {748639800 12600 0 +0330}.. {764281800 16200 1 +0330}.. {780175800 12600 0 +0330}.. {795817800 16200 1 +0330}.. {811711800 12600 0 +0330}.. {827353800 16200 1 +0330}.. {843247800 12600 0 +0330}.. {858976200 16200 1 +0330}.. {874870200 12600 0 +0330}.. {890512200 16200 1 +0330}.. {906406200 12600 0 +0330}.. {922048200 16200 1 +0330}.. {937942200 12600
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):184
                                                                                                                                                                                                            Entropy (8bit):4.876713308636272
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq85zFFfXHAIgN0AzFFVHRL/2WFK+TT52WFKYzFgn:SlSWB9vsM3yZbPHAIgCAXRN/2wKsswKR
                                                                                                                                                                                                            MD5:40B15013485EE2138A3DCB915F9121E7
                                                                                                                                                                                                            SHA1:3ADBE38686C7CA1FDE3DDD12BE908F39BFD1E228
                                                                                                                                                                                                            SHA-256:07537A30E6236D9E334DAFD5C4D352D25FDEF95D6DC7496F5D93EFAB74D9EBB1
                                                                                                                                                                                                            SHA-512:DA3B7B44B3BEF07CA8AA5253BF684A838181D8A15D7CCF0447A6B5F5BAE28D155CF65BCFB6286EB36C0B9F4FDD1FE862A3297ADB6FC33532B9F766334283D725
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Jerusalem)]} {.. LoadTimeZoneFile Asia/Jerusalem..}..set TZData(:Asia/Tel_Aviv) $TZData(:Asia/Jerusalem)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):176
                                                                                                                                                                                                            Entropy (8bit):4.906503135441824
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8kNZ4WXHAIgNqFNKARL/2WFK9Z752WFKvNZovn:SlSWB9vsM3ykZ42HAIgc3KAN/2wKf126
                                                                                                                                                                                                            MD5:081862B6FB33389BEC9B0E6B500AA342
                                                                                                                                                                                                            SHA1:AF9467BB87C4C28921DF62A87B81223052F9FF4A
                                                                                                                                                                                                            SHA-256:37459C17B59639DF62B3F3943751902CE6AAF1F11B7630069DB45052EBEFB5B9
                                                                                                                                                                                                            SHA-512:CAF6F1C928528C4471229A2EF2944623545626532986628E6CE38884535286A0B38BA88C1A295E8B11322475D6BFAC61BF89786A76330C1A0C729339A3532BAF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Thimphu)]} {.. LoadTimeZoneFile Asia/Thimphu..}..set TZData(:Asia/Thimbu) $TZData(:Asia/Thimphu)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):180
                                                                                                                                                                                                            Entropy (8bit):4.887493603495978
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/2WFKvNZJMXGm2OHEQUTFnoHqVaJKuc/v6Q61V9gmZVFSTVV:SlSWB9eg/2wKVZJDm2OHEfnoHDKuc/SC
                                                                                                                                                                                                            MD5:F239452984CCA9F23E97A880652C39E6
                                                                                                                                                                                                            SHA1:52D25282D03B79960F152D21E7492EE26DAEBBAA
                                                                                                                                                                                                            SHA-256:B797C74E3840298C3CD8149FC8AA4BCE839EFE79E7C3310986FF23C965607929
                                                                                                                                                                                                            SHA-512:1044BEDAE04FCA7BD62937AFCE70F6C447583A90DD1596C3029A64A8251E3F73C106F4D940548DD38E895D67FEFDCD196B257E11437DEB399085EE80C345AA50
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Thimphu) {.. {-9223372036854775808 21516 0 LMT}.. {-706341516 19800 0 +0530}.. {560025000 21600 0 +06}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):388
                                                                                                                                                                                                            Entropy (8bit):4.470556147950505
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB862ymdHOx5CvAoK3zoiIxtoFDIe+zT0agbov:5yeOCvARzzCOVa/gby
                                                                                                                                                                                                            MD5:3CCC15B63A882DB1B7459A51CD1C8165
                                                                                                                                                                                                            SHA1:77A3EFE6E4EE524B9EC6F51593DD7521FD7B8DAD
                                                                                                                                                                                                            SHA-256:3DA522FA88541A375D53F30A0B62DC4A305FA0315FEE534B7998C9E0A239450A
                                                                                                                                                                                                            SHA-512:15238E96DABAB5D2B9FFD25B3F50417ED32205FA69239D6F6B28DA97A378D669FD409164964D0DD2A5B1D795C8F60E8D4EB15924046348C3D6010646A536E07C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Tokyo) {.. {-9223372036854775808 33539 0 LMT}.. {-2587712400 32400 0 JST}.. {-683802000 36000 1 JDT}.. {-672310800 32400 0 JST}.. {-654771600 36000 1 JDT}.. {-640861200 32400 0 JST}.. {-620298000 36000 1 JDT}.. {-609411600 32400 0 JST}.. {-588848400 36000 1 JDT}.. {-577962000 32400 0 JST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2116
                                                                                                                                                                                                            Entropy (8bit):3.695316005718174
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5CeLz/XJfsFN/3sFrOksF/sF7IyksF7FRZsFLsFTsFcsFk73sFK/XCFKTipnFEno:5H040yVRB7VfXucydm4IqtTTDOS
                                                                                                                                                                                                            MD5:E95DE93CBCE72C5E02D7ECFE94C96308
                                                                                                                                                                                                            SHA1:59A49EBFE544D97545BADFEFE716BB5659C64C20
                                                                                                                                                                                                            SHA-256:6B64A01D0F0B5EC7A1410C3BD6883BA7CC133E9F073D40E8BFECE037E3A3FA24
                                                                                                                                                                                                            SHA-512:9E33DC9C1C6D60F3226263C484AF46A14AAB31F838516A0D69BA08F8F416EF10D09697E8D7ABAC1CE1F5BCE8AB0C2635D99FBE70C89ECC268DED0DCE89E67466
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Tomsk) {.. {-9223372036854775808 20391 0 LMT}.. {-1578807591 21600 0 +06}.. {-1247551200 25200 0 +08}.. {354906000 28800 1 +08}.. {370713600 25200 0 +07}.. {386442000 28800 1 +08}.. {402249600 25200 0 +07}.. {417978000 28800 1 +08}.. {433785600 25200 0 +07}.. {449600400 28800 1 +08}.. {465332400 25200 0 +07}.. {481057200 28800 1 +08}.. {496782000 25200 0 +07}.. {512506800 28800 1 +08}.. {528231600 25200 0 +07}.. {543956400 28800 1 +08}.. {559681200 25200 0 +07}.. {575406000 28800 1 +08}.. {591130800 25200 0 +07}.. {606855600 28800 1 +08}.. {622580400 25200 0 +07}.. {638305200 28800 1 +08}.. {654634800 25200 0 +07}.. {670359600 21600 0 +07}.. {670363200 25200 1 +07}.. {686088000 21600 0 +06}.. {695764800 25200 0 +08}.. {701809200 28800 1 +08}.. {717534000 25200 0 +07}.. {733258800 28800 1 +08}.. {748983600 25200 0 +07}.. {7647084
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):186
                                                                                                                                                                                                            Entropy (8bit):4.897140749162557
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8pYFfXHAIgNzGRRL/2WFKPQOrFJ4WFKov:SlSWB9vsM3yWFPHAIg0RN/2wKPQOrFJD
                                                                                                                                                                                                            MD5:F6AE33D706C36FDD8A21F44AD59F5607
                                                                                                                                                                                                            SHA1:94D6EC7A437249AEBE2FA4AF8AFB029A620368C0
                                                                                                                                                                                                            SHA-256:732751845ACEDBFFD3C6170F4B94CB20B25BFDCFCC5EEA19F4BE439F5C5B573A
                                                                                                                                                                                                            SHA-512:2314AB2B154887842211C9A570BC1323D9B4375FF60C96296835DB001E8A277CA62D40B8562BC34EDDF281D96D5325640B79F7907558C6E0319C7D2A76BE239C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Makassar)]} {.. LoadTimeZoneFile Asia/Makassar..}..set TZData(:Asia/Ujung_Pandang) $TZData(:Asia/Makassar)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1590
                                                                                                                                                                                                            Entropy (8bit):3.7728141273024374
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5IerIvusF7cCGK6zoCjZte3kzMjsBw0oZzlL98oysHqGzJvqE+ksabzdX+YjL:5VujmUCei46oljFC67
                                                                                                                                                                                                            MD5:A4647294401D2B54ABAA8E509BF05A6F
                                                                                                                                                                                                            SHA1:BF804CC38996D7715E3BA9BAD715D7ADBED781B9
                                                                                                                                                                                                            SHA-256:A56A26981163A717CF388A423CFE7A2BAD1BE8652BE2E338670CBC0C0A70E5E9
                                                                                                                                                                                                            SHA-512:B43157FABDE016FA6636CAB7B06CC1DEA53526B42FB46BB41DC4B7E48188D191C325BEF0D170B125E885F321C4316746A8D478D798828E2DC4A51C71DA4A610C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Ulaanbaatar) {.. {-9223372036854775808 25652 0 LMT}.. {-2032931252 25200 0 +07}.. {252435600 28800 0 +08}.. {417974400 32400 1 +08}.. {433782000 28800 0 +08}.. {449596800 32400 1 +08}.. {465318000 28800 0 +08}.. {481046400 32400 1 +08}.. {496767600 28800 0 +08}.. {512496000 32400 1 +08}.. {528217200 28800 0 +08}.. {543945600 32400 1 +08}.. {559666800 28800 0 +08}.. {575395200 32400 1 +08}.. {591116400 28800 0 +08}.. {606844800 32400 1 +08}.. {622566000 28800 0 +08}.. {638294400 32400 1 +08}.. {654620400 28800 0 +08}.. {670348800 32400 1 +08}.. {686070000 28800 0 +08}.. {701798400 32400 1 +08}.. {717519600 28800 0 +08}.. {733248000 32400 1 +08}.. {748969200 28800 0 +08}.. {764697600 32400 1 +08}.. {780418800 28800 0 +08}.. {796147200 32400 1 +08}.. {811868400 28800 0 +08}.. {828201600 32400 1 +08}.. {843922800 28800 0 +08}.. {859
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):192
                                                                                                                                                                                                            Entropy (8bit):4.728285544456033
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8TcXkXHAIgNrfcXORL/2WFKhrMEBQWFKucXB:SlSWB9vsM3yXHAIgTN/2wKhrMEewKX
                                                                                                                                                                                                            MD5:D2EAEA6182FB332CAA707B523F6C8A9D
                                                                                                                                                                                                            SHA1:3BFC654E2B3BCF902AF41AEEC46772C84FFF3890
                                                                                                                                                                                                            SHA-256:D17FDAF17B3DAC3A1310E2332F61585598185E64CED799ABD68249EB5B698591
                                                                                                                                                                                                            SHA-512:E16BEE28BFE3AFFFE6F0025C09D0D65001F38D5045AAB1B554E4D3A66A88273F985B7BAA11F8D26E76E5ABC9F559E3E4B794CC939AAD5FF012A5A47924D08CB3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Ulaanbaatar)]} {.. LoadTimeZoneFile Asia/Ulaanbaatar..}..set TZData(:Asia/Ulan_Bator) $TZData(:Asia/Ulaanbaatar)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):149
                                                                                                                                                                                                            Entropy (8bit):5.006390440264841
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/2WFKjhfMXGm2OHEVPoHsWA0GVFSTVVn:SlSWB9eg/2wKjJDm2OHEVPoH3A0CUX
                                                                                                                                                                                                            MD5:D6245CAAEC9BA2579F4CEFFF196A9369
                                                                                                                                                                                                            SHA1:4D182953F2CEEFF3583265F977B14F40C1A2FB43
                                                                                                                                                                                                            SHA-256:C445B8030DEDDDED0AFF5CC692CC323B63BE8C14BBD42DC3FDE90AD4F9D14785
                                                                                                                                                                                                            SHA-512:A32C477B6FAA79247907D1C4E2DF400B05AF4B529277C4CE12B33097872311E3F579115DC8CBA93DAC936928FD574414F3473A9CB7C8E85AB57CCA57489B60F8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Urumqi) {.. {-9223372036854775808 21020 0 LMT}.. {-1325483420 21600 0 +06}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2058
                                                                                                                                                                                                            Entropy (8bit):3.773734429231407
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5petrlfgLv+OC+jsuwltZQONEa2Ggf3augO8UoxLyHdX/CX6bW4Bv/7NKxKG:5Ysv+0j6lua2Gg/3gO8UoOZU2Wc/pKF
                                                                                                                                                                                                            MD5:5ADD78E4AFCBA913D078A8790861A2DE
                                                                                                                                                                                                            SHA1:BB63A762D5D76C0FD3CB9AB2BCDE95718E1C99EB
                                                                                                                                                                                                            SHA-256:9D639C0FC69B3BEEBC96969092F9590EB48E7946E901B225BF245E165973B9A8
                                                                                                                                                                                                            SHA-512:7C2418FD1F96F101B83E2ABDF2551405C6E429DBBF30A2FA7CD2477E2CE1CEEBB790C51B28AEFF043BA7A7A914CEF3C812668058D69225B9FE9475C56508453D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Ust-Nera) {.. {-9223372036854775808 34374 0 LMT}.. {-1579426374 28800 0 +08}.. {354898800 43200 0 +12}.. {370699200 39600 0 +11}.. {386427600 43200 1 +12}.. {402235200 39600 0 +11}.. {417963600 43200 1 +12}.. {433771200 39600 0 +11}.. {449586000 43200 1 +12}.. {465318000 39600 0 +11}.. {481042800 43200 1 +12}.. {496767600 39600 0 +11}.. {512492400 43200 1 +12}.. {528217200 39600 0 +11}.. {543942000 43200 1 +12}.. {559666800 39600 0 +11}.. {575391600 43200 1 +12}.. {591116400 39600 0 +11}.. {606841200 43200 1 +12}.. {622566000 39600 0 +11}.. {638290800 43200 1 +12}.. {654620400 39600 0 +11}.. {670345200 36000 0 +11}.. {670348800 39600 1 +11}.. {686073600 36000 0 +10}.. {695750400 39600 0 +12}.. {701794800 43200 1 +12}.. {717519600 39600 0 +11}.. {733244400 43200 1 +12}.. {748969200 39600 0 +11}.. {764694000 43200 1 +12}.. {780418
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):179
                                                                                                                                                                                                            Entropy (8bit):4.858039387006872
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8VLYO5YFfXHAIgN8ELYOJARL/2WFKgTjEHp4WFKELt:SlSWB9vsM3y1LePHAIgKELtAN/2wKgsX
                                                                                                                                                                                                            MD5:D23A09C84A5368FBB47174BC0A460D14
                                                                                                                                                                                                            SHA1:045A72FEA79C75E5F0029BD110E33A022C57DFAB
                                                                                                                                                                                                            SHA-256:18F5E4FE8247F676278AC5F1912AC401DC48DF5B756D22E76FF1CFA702F88DA7
                                                                                                                                                                                                            SHA-512:404EABC2FC162E18C678CED063249C7FF4C28653880EA1903CE846FD191CD1C5B61E0610736F250B79BBAC768B1AFD6B9A8824D56D74591A95D7301B47D48387
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Bangkok)]} {.. LoadTimeZoneFile Asia/Bangkok..}..set TZData(:Asia/Vientiane) $TZData(:Asia/Bangkok)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2062
                                                                                                                                                                                                            Entropy (8bit):3.7094518963173035
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:56beOUYQ7FyDy3le3i96VwAmnuBNuTw6vl9O8nfipRkwhUZDAcD:56cYQBIy343dVNUIukElcXRDhUBAcD
                                                                                                                                                                                                            MD5:5C0C094B088D0212182E7B944197D4FE
                                                                                                                                                                                                            SHA1:CF43A511FE9CD295207DF350704462E09D4D5278
                                                                                                                                                                                                            SHA-256:2558C96E25359C72F168DAC6FB3C16C54F8FD7D0724EEB1671156D4A1F42AC6C
                                                                                                                                                                                                            SHA-512:5D659EBDC8C2B06C964B083ECC78B4370A4658590D83F020CD23910C44E2D8DAFE69F61E8EB569E1905E89F38CD03ABE6B92F6CE36CF0B1EE0732A7645AFA65D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Vladivostok) {.. {-9223372036854775808 31651 0 LMT}.. {-1487321251 32400 0 +09}.. {-1247562000 36000 0 +11}.. {354895200 39600 1 +11}.. {370702800 36000 0 +10}.. {386431200 39600 1 +11}.. {402238800 36000 0 +10}.. {417967200 39600 1 +11}.. {433774800 36000 0 +10}.. {449589600 39600 1 +11}.. {465321600 36000 0 +10}.. {481046400 39600 1 +11}.. {496771200 36000 0 +10}.. {512496000 39600 1 +11}.. {528220800 36000 0 +10}.. {543945600 39600 1 +11}.. {559670400 36000 0 +10}.. {575395200 39600 1 +11}.. {591120000 36000 0 +10}.. {606844800 39600 1 +11}.. {622569600 36000 0 +10}.. {638294400 39600 1 +11}.. {654624000 36000 0 +10}.. {670348800 32400 0 +10}.. {670352400 36000 1 +10}.. {686077200 32400 0 +09}.. {695754000 36000 0 +11}.. {701798400 39600 1 +11}.. {717523200 36000 0 +10}.. {733248000 39600 1 +11}.. {748972800 36000 0 +10}.. {7
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2058
                                                                                                                                                                                                            Entropy (8bit):3.7081033128260934
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5h+r1gIgWH/lt0irzEzCSCItWiIrW+rDQk9CVhyFY7rRWjYuhUmgr2j:K5PhtjLiII2ZFlgm
                                                                                                                                                                                                            MD5:E43E5F0EA7C4575525BAB130984DCDCC
                                                                                                                                                                                                            SHA1:2D715749469FEA51A8E25D1F4F8DC4FF9178817D
                                                                                                                                                                                                            SHA-256:3BEF13638C46F16435D326C675907E61BB68C8173153CED3359E983BE0E413E5
                                                                                                                                                                                                            SHA-512:27954FEC865031BC363CFDE94E97B3B19836A6F777646EA4AAB12ECCAEE6D60A0C690711EA192B917AC717F94A01D1EF64BAE97DF968069CC12415971B070498
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Yakutsk) {.. {-9223372036854775808 31138 0 LMT}.. {-1579423138 28800 0 +08}.. {-1247558400 32400 0 +10}.. {354898800 36000 1 +10}.. {370706400 32400 0 +09}.. {386434800 36000 1 +10}.. {402242400 32400 0 +09}.. {417970800 36000 1 +10}.. {433778400 32400 0 +09}.. {449593200 36000 1 +10}.. {465325200 32400 0 +09}.. {481050000 36000 1 +10}.. {496774800 32400 0 +09}.. {512499600 36000 1 +10}.. {528224400 32400 0 +09}.. {543949200 36000 1 +10}.. {559674000 32400 0 +09}.. {575398800 36000 1 +10}.. {591123600 32400 0 +09}.. {606848400 36000 1 +10}.. {622573200 32400 0 +09}.. {638298000 36000 1 +10}.. {654627600 32400 0 +09}.. {670352400 28800 0 +09}.. {670356000 32400 1 +09}.. {686080800 28800 0 +08}.. {695757600 32400 0 +10}.. {701802000 36000 1 +10}.. {717526800 32400 0 +09}.. {733251600 36000 1 +10}.. {748976400 32400 0 +09}.. {76470
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):244
                                                                                                                                                                                                            Entropy (8bit):4.692243303623333
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2wKs5XDm2OHGVQoHvZN6FCDx+UIFDVkvScHbY/s5UIAy:MB862KTmdHGuCvZNNkkHH3Sy
                                                                                                                                                                                                            MD5:D45766D30074719C9A88ACE8BB53204B
                                                                                                                                                                                                            SHA1:69B333DFCCCCEB66DD0F7DC28B272BB10769B6B0
                                                                                                                                                                                                            SHA-256:2526557810747E78E713AE09BC305621A80FAEECF8D441632E7825738D4C79CB
                                                                                                                                                                                                            SHA-512:5255DEED72D7D13862A4D6BED7E0458C099D2EF5A1B41536CAA7C0E65A61DE8B8D1AD62AD44559F970B6613ADFB3862778D1CC99B9A05CB5BBCA7F0202B5A5B2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Yangon) {.. {-9223372036854775808 23087 0 LMT}.. {-2840163887 23087 0 RMT}.. {-1577946287 23400 0 +0630}.. {-873268200 32400 0 +09}.. {-778410000 23400 0 +0630}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2095
                                                                                                                                                                                                            Entropy (8bit):3.704641905144701
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:5ievNhYvm1qv7vXIovPvSvlDvtvuovKKvKcNvHvAvivBvqvvEyv8vlvEv+v4v+v+:/Nupj40H6l75FKCKcZP8qdyEaoBAWkW+
                                                                                                                                                                                                            MD5:D4DABA407BB8A10E4961D1DE5D9781D1
                                                                                                                                                                                                            SHA1:6933DE65336331BD90E2BEC6AEA0609B16DAEDC9
                                                                                                                                                                                                            SHA-256:2C78699EFC60758B8F8D0D1DEEDFDED5E65C65EBF3082B23E60BDEA8BF8FBCFE
                                                                                                                                                                                                            SHA-512:459E2187FAA66414F5CE934C335F563DFD2FA5316B86A54D1A29123A0460AFD65B7CE46629BD6A070A14CB6873A28A2F2803DE5FF4F29EA610712EB07FAD303F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Yekaterinburg) {.. {-9223372036854775808 14553 0 LMT}.. {-1688270553 13505 0 PMT}.. {-1592610305 14400 0 +04}.. {-1247544000 18000 0 +06}.. {354913200 21600 1 +06}.. {370720800 18000 0 +05}.. {386449200 21600 1 +06}.. {402256800 18000 0 +05}.. {417985200 21600 1 +06}.. {433792800 18000 0 +05}.. {449607600 21600 1 +06}.. {465339600 18000 0 +05}.. {481064400 21600 1 +06}.. {496789200 18000 0 +05}.. {512514000 21600 1 +06}.. {528238800 18000 0 +05}.. {543963600 21600 1 +06}.. {559688400 18000 0 +05}.. {575413200 21600 1 +06}.. {591138000 18000 0 +05}.. {606862800 21600 1 +06}.. {622587600 18000 0 +05}.. {638312400 21600 1 +06}.. {654642000 18000 0 +05}.. {670366800 14400 0 +05}.. {670370400 18000 1 +05}.. {686095200 14400 0 +04}.. {695772000 18000 0 +06}.. {701816400 21600 1 +06}.. {717541200 18000 0 +05}.. {733266000 21600 1 +06}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2029
                                                                                                                                                                                                            Entropy (8bit):3.6487650030366106
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:5O4GeuadYlykbocXcwJUE5iu8JmFebARoc9lVNk7/9bq8dq16b3C9UPBUUUl2ue/:5xKdsUf8mFpNWFnyLCPYmPJSi3sh4
                                                                                                                                                                                                            MD5:2CFA7C55D0731D24679CA5D5DC716381
                                                                                                                                                                                                            SHA1:2BB66783D75C71E76409365757980FBC15F53231
                                                                                                                                                                                                            SHA-256:20871FA6AA959DDFB73D846271B4A568627B564CFC08A11BDD84B98C2F2019A3
                                                                                                                                                                                                            SHA-512:CAB10A48859B2C0B2CC7C56E0AA530AE7E506A4986BADC5ED974D124BD46DB328B50C423F83FCFD52D31962A249EEFC10351798B86D51EDA500F412C8D42E6BC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Asia/Yerevan) {.. {-9223372036854775808 10680 0 LMT}.. {-1441162680 10800 0 +03}.. {-405140400 14400 0 +04}.. {354916800 18000 1 +04}.. {370724400 14400 0 +04}.. {386452800 18000 1 +04}.. {402260400 14400 0 +04}.. {417988800 18000 1 +04}.. {433796400 14400 0 +04}.. {449611200 18000 1 +04}.. {465343200 14400 0 +04}.. {481068000 18000 1 +04}.. {496792800 14400 0 +04}.. {512517600 18000 1 +04}.. {528242400 14400 0 +04}.. {543967200 18000 1 +04}.. {559692000 14400 0 +04}.. {575416800 18000 1 +04}.. {591141600 14400 0 +04}.. {606866400 18000 1 +04}.. {622591200 14400 0 +04}.. {638316000 18000 1 +04}.. {654645600 14400 0 +04}.. {670370400 10800 0 +03}.. {670374000 14400 1 +03}.. {686098800 10800 0 +03}.. {701823600 14400 1 +03}.. {717548400 10800 0 +03}.. {733273200 14400 1 +03}.. {748998000 10800 0 +03}.. {764722800 14400 1 +03}.. {780447
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):9879
                                                                                                                                                                                                            Entropy (8bit):3.557602151081988
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:K35nZPOUYySoluItljncxelTMwtrayE6x5sETNek/CyNzybxYKmX6SXL/XbEcygI:K940pb6cL/b3Ldr9Q7TMq+ML
                                                                                                                                                                                                            MD5:E7F2A3EE0362E9ED3ECBAD24168AD098
                                                                                                                                                                                                            SHA1:98832274F6D9B641B809123D1272A1C04EEAA177
                                                                                                                                                                                                            SHA-256:6B3609BE4E93D21A2AB492594EDD387931E2C787E8471C9F2D3A677F34002D8F
                                                                                                                                                                                                            SHA-512:C48A76F8251AE455C759CB98802E40B3BEF716FD8E7441B6DE0242942C913367E3572B7C871082E97CA9BE67EC7DC37F8D01C438965217AC0EC36AD508DCE0D4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Azores) {.. {-9223372036854775808 -6160 0 LMT}.. {-2713904240 -6872 0 HMT}.. {-1830376800 -7200 0 -02}.. {-1689548400 -3600 1 -01}.. {-1677794400 -7200 0 -02}.. {-1667430000 -3600 1 -01}.. {-1647730800 -7200 0 -02}.. {-1635807600 -3600 1 -01}.. {-1616194800 -7200 0 -02}.. {-1604358000 -3600 1 -01}.. {-1584658800 -7200 0 -02}.. {-1572735600 -3600 1 -01}.. {-1553036400 -7200 0 -02}.. {-1541199600 -3600 1 -01}.. {-1521500400 -7200 0 -02}.. {-1442444400 -3600 1 -01}.. {-1426806000 -7200 0 -02}.. {-1379286000 -3600 1 -01}.. {-1364770800 -7200 0 -02}.. {-1348441200 -3600 1 -01}.. {-1333321200 -7200 0 -02}.. {-1316386800 -3600 1 -01}.. {-1301266800 -7200 0 -02}.. {-1284332400 -3600 1 -01}.. {-1269817200 -7200 0 -02}.. {-1221433200 -3600 1 -01}.. {-1206918000 -7200 0 -02}.. {-1191193200 -3600 1 -01}.. {-1175468400 -7200 0 -02}.. {-1127689
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8784
                                                                                                                                                                                                            Entropy (8bit):3.833553120942514
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:ZRBHksL3zq6bCvyjvspNWMPm4bPJWXtRbALtuFW4ng2CEBJuQaeEy9P19OBYEi/+:ft0CC
                                                                                                                                                                                                            MD5:B04E22B9B42722013941169B5D04DEA2
                                                                                                                                                                                                            SHA1:32B96A7D9504D5022A6C4E2D310E95B5F062947F
                                                                                                                                                                                                            SHA-256:099C3BEFBA3B4C00AE19BC53D475A52B32FAC9B36EC823C8EAEFC7D00F78F388
                                                                                                                                                                                                            SHA-512:8B93BCA1E923B7A43F2EB0889216E8FF991D13CB8D25BD300310ED7CD8537DBD858E8F422C9B52AE2F52F7C1CB450EF0B7C5C1B3AE547C9C1E18E2A851569DD5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Bermuda) {.. {-9223372036854775808 -15558 0 LMT}.. {-2524506042 -15558 0 BMT}.. {-1664307642 -11958 1 BMT}.. {-1648932042 -15558 0 BMT}.. {-1632080442 -11958 1 BMT}.. {-1618692042 -15558 0 BST}.. {-1262281242 -14400 0 AT}.. {-882727200 -10800 1 ADT}.. {-858538800 -14400 0 AST}.. {-845229600 -10800 1 ADT}.. {-825879600 -14400 0 AST}.. {-814384800 -10800 1 ADT}.. {-793825200 -14400 0 AST}.. {-782935200 -10800 1 ADT}.. {-762375600 -14400 0 AST}.. {-713988000 -10800 1 ADT}.. {-703710000 -14400 0 AST}.. {-681933600 -10800 1 ADT}.. {-672865200 -14400 0 AST}.. {-650484000 -10800 1 ADT}.. {-641415600 -14400 0 AST}.. {-618429600 -10800 1 ADT}.. {-609966000 -14400 0 AST}.. {-586980000 -10800 1 ADT}.. {-578516400 -14400 0 AST}.. {-555530400 -10800 1 ADT}.. {-546462000 -14400 0 AST}.. {-429127200 -10800 1 ADT}.. {-415825200 -14400 0 AST}.. {1
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):6856
                                                                                                                                                                                                            Entropy (8bit):3.8064107143060752
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:KXVuHfXCiZoFtFPIaFF1w0urfva946ZGsE3f2Sf+aCNmSv+kznl4klEp8OT:KXVQbkIaFF1w0us4qE3+sSGjT
                                                                                                                                                                                                            MD5:8ABD279386C50705C074EEE18BF5AE59
                                                                                                                                                                                                            SHA1:C392231DBE744F5942DA4BFAC8AD0ABEBAEA0BF3
                                                                                                                                                                                                            SHA-256:2026944DCDEBC52F64405E35119F4CF97EA9AA1E769498730880B03F29A2B885
                                                                                                                                                                                                            SHA-512:3095759D01AC7EEA25E427CA38E8A0395BEFA7250E7A0C1327BF9D61F07F4570CDF7313FBE6695973EB0DD66D201C6C63591CC0DA8A1E0029926DC7056F4C95B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Canary) {.. {-9223372036854775808 -3696 0 LMT}.. {-1509663504 -3600 0 -01}.. {-733874400 0 0 WET}.. {323827200 3600 1 WEST}.. {338950800 0 0 WET}.. {354675600 3600 1 WEST}.. {370400400 0 0 WET}.. {386125200 3600 1 WEST}.. {401850000 0 0 WET}.. {417574800 3600 1 WEST}.. {433299600 0 0 WET}.. {449024400 3600 1 WEST}.. {465354000 0 0 WET}.. {481078800 3600 1 WEST}.. {496803600 0 0 WET}.. {512528400 3600 1 WEST}.. {528253200 0 0 WET}.. {543978000 3600 1 WEST}.. {559702800 0 0 WET}.. {575427600 3600 1 WEST}.. {591152400 0 0 WET}.. {606877200 3600 1 WEST}.. {622602000 0 0 WET}.. {638326800 3600 1 WEST}.. {654656400 0 0 WET}.. {670381200 3600 1 WEST}.. {686106000 0 0 WET}.. {701830800 3600 1 WEST}.. {717555600 0 0 WET}.. {733280400 3600 1 WEST}.. {749005200 0 0 WET}.. {764730000 3600 1 WEST}.. {780454800 0 0 WET}.. {796179600
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):246
                                                                                                                                                                                                            Entropy (8bit):4.637993677747699
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/2RQ7RfDm2OHDoH1JlvQV/FFrR3FcykVvQV/FFf+nmwV:MB86267RLmdHDC1w/FH3FcyL/FomwV
                                                                                                                                                                                                            MD5:1581C6470850E0C9DB204975488B1AF8
                                                                                                                                                                                                            SHA1:6933ED13F18AD785CEDF0837F86EFAC671297A85
                                                                                                                                                                                                            SHA-256:2EA59ACDB5BBDD3C6ABCEEA456838A5CA57371A3D2BB93604B37F998ED8B9D4D
                                                                                                                                                                                                            SHA-512:9FFFA013D82CEFF6F447521C19270ECDD71152F23670164423E6013FEC46253C62D2CB79B42630BD786BD113F27369E746CA981DD17E789F7571F473B47247C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Cape_Verde) {.. {-9223372036854775808 -5644 0 LMT}.. {-1830376800 -7200 0 -02}.. {-862610400 -3600 1 -01}.. {-764118000 -7200 0 -02}.. {186120000 -3600 0 -01}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):186
                                                                                                                                                                                                            Entropy (8bit):4.709193799640151
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqLG4E23vXHAIgvMG4EeRRL/2RQqG4EZrB/4RQqG4E1n:SlSWB9vsM3yCPHAIgvoRN/2RQ1rB/4Ri
                                                                                                                                                                                                            MD5:601EB889A87F9CAD6F1DF4D1AB009FAE
                                                                                                                                                                                                            SHA1:EB43C253A48755442A67A2408D7E3295549F831C
                                                                                                                                                                                                            SHA-256:64FB8CAD17CD36666C7027AAD01344FEF659B13699EEF1942365842F8ED2170E
                                                                                                                                                                                                            SHA-512:9CFC4A446ED6A3BEF6C26AE57324F10A970EE2ADD6933130447FAD6A3DB538841F2490DD461AF5776FACD9BD2CDC4A83247DFA6B34802AE844DDC6D4C37B28EA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Atlantic/Faroe)]} {.. LoadTimeZoneFile Atlantic/Faroe..}..set TZData(:Atlantic/Faeroe) $TZData(:Atlantic/Faroe)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):6796
                                                                                                                                                                                                            Entropy (8bit):3.804838552487436
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:96ufXCiZoFtFPIaFF1w0urfva946ZGsE3f2Sf+aCNmSv+kznl4klEp8OT:/bkIaFF1w0us4qE3+sSGjT
                                                                                                                                                                                                            MD5:F97CC7EB9C52D00177BFF4715832FCD5
                                                                                                                                                                                                            SHA1:CD9DCBB5E6ADD6EA91C8F142957EC229FC7F6DA3
                                                                                                                                                                                                            SHA-256:795F438E7F01342D5F25ECCDD09FCE65C03C5D2D561B9B5191301D57EC16B850
                                                                                                                                                                                                            SHA-512:9586289FEB6C597160011A47432F0AC40000483FA2E579BD89046EFD33E98DDAD652B792FD80CEDEB4CD87B6439A7B473F25F1B7375BC75353CBAF9F77E1084E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Faroe) {.. {-9223372036854775808 -1624 0 LMT}.. {-1955748776 0 0 WET}.. {347155200 0 0 WET}.. {354675600 3600 1 WEST}.. {370400400 0 0 WET}.. {386125200 3600 1 WEST}.. {401850000 0 0 WET}.. {417574800 3600 1 WEST}.. {433299600 0 0 WET}.. {449024400 3600 1 WEST}.. {465354000 0 0 WET}.. {481078800 3600 1 WEST}.. {496803600 0 0 WET}.. {512528400 3600 1 WEST}.. {528253200 0 0 WET}.. {543978000 3600 1 WEST}.. {559702800 0 0 WET}.. {575427600 3600 1 WEST}.. {591152400 0 0 WET}.. {606877200 3600 1 WEST}.. {622602000 0 0 WET}.. {638326800 3600 1 WEST}.. {654656400 0 0 WET}.. {670381200 3600 1 WEST}.. {686106000 0 0 WET}.. {701830800 3600 1 WEST}.. {717555600 0 0 WET}.. {733280400 3600 1 WEST}.. {749005200 0 0 WET}.. {764730000 3600 1 WEST}.. {780454800 0 0 WET}.. {796179600 3600 1 WEST}.. {811904400 0 0 WET}.. {828234000 3600
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):186
                                                                                                                                                                                                            Entropy (8bit):4.957633978425468
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/y+YF3vXHAIgoq8yFRRL/2RQqG0EHEcAg/h8QahV:SlSWB9vsM3ymhVoPHAIgoh6N/2RQaK85
                                                                                                                                                                                                            MD5:95C2D55CCE5809089CDB041EA3D464F8
                                                                                                                                                                                                            SHA1:B395F5F26CE979BDF2B9E2CB51C06929AED11A6C
                                                                                                                                                                                                            SHA-256:11BF0746F95BA01807D3B34C8FAE3FF4AE9DB5E4E6BC0CB8B36906CC3F44EDE5
                                                                                                                                                                                                            SHA-512:AB2BE22E95A7C36E18EBA1BB63B3930A523ED793E43A3F597A8F63AE2F0E44436C39144BC136E7E5716D7FCBFAE7F1FAF36BCFFCF9C8D51151FF25BB14D6F8B5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Berlin)]} {.. LoadTimeZoneFile Europe/Berlin..}..set TZData(:Atlantic/Jan_Mayen) $TZData(:Europe/Berlin)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):9709
                                                                                                                                                                                                            Entropy (8bit):3.80455694200614
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:hZUiLbMsf/ss0qKd+aKyUXtOZHY1SCOcesoQivoKbFVCdm1rXWNXyCXTOuUbkIaq:hZZDQX1rWJysukysLE3+sSGjT
                                                                                                                                                                                                            MD5:AC6647F9B53B5958214EC3F3B78A4D85
                                                                                                                                                                                                            SHA1:7355622AF99296F069F73899D5C70941C207F676
                                                                                                                                                                                                            SHA-256:B2A0D0DDC26806A05B2BE806CA3F938DB12A3FA40110B8B21FD3F04EFED3A531
                                                                                                                                                                                                            SHA-512:07569CA4D5DC6D57D91D6FDC370671A7546B73BA653D094E1B501D33570F7700727AD7FF2A083BC79E9EDE807C47E7A5604BEF5803F290B2F277C51DEF10FA6B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Madeira) {.. {-9223372036854775808 -4056 0 LMT}.. {-2713906344 -4056 0 FMT}.. {-1830380400 -3600 0 -01}.. {-1689552000 0 1 +00}.. {-1677798000 -3600 0 -01}.. {-1667433600 0 1 +00}.. {-1647734400 -3600 0 -01}.. {-1635811200 0 1 +00}.. {-1616198400 -3600 0 -01}.. {-1604361600 0 1 +00}.. {-1584662400 -3600 0 -01}.. {-1572739200 0 1 +00}.. {-1553040000 -3600 0 -01}.. {-1541203200 0 1 +00}.. {-1521504000 -3600 0 -01}.. {-1442448000 0 1 +00}.. {-1426809600 -3600 0 -01}.. {-1379289600 0 1 +00}.. {-1364774400 -3600 0 -01}.. {-1348444800 0 1 +00}.. {-1333324800 -3600 0 -01}.. {-1316390400 0 1 +00}.. {-1301270400 -3600 0 -01}.. {-1284336000 0 1 +00}.. {-1269820800 -3600 0 -01}.. {-1221436800 0 1 +00}.. {-1206921600 -3600 0 -01}.. {-1191196800 0 1 +00}.. {-1175472000 -3600 0 -01}.. {-1127692800 0 1 +00}.. {-1111968000 -3600 0 -01}.. {-
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):189
                                                                                                                                                                                                            Entropy (8bit):4.910514445868106
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2RQqGsA/8rVDcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2RQjQD4
                                                                                                                                                                                                            MD5:ECB480DA99D29C0ACE67426D45534754
                                                                                                                                                                                                            SHA1:784CF126B030C3D883EE541877E6181F795C9697
                                                                                                                                                                                                            SHA-256:BDA015714260001BAE2848991DD21E802580BE2915797E5DABC376135D1C5246
                                                                                                                                                                                                            SHA-512:54C1B20E45C7C73354DCD4E0F4444720771820ED10B282F745DC391BEADEAEDC629BEF97B1908FB62CDAEC915D32AF1F54FC6AA9DC83E317E7CE19FC2586EF28
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Atlantic/Reykjavik) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):160
                                                                                                                                                                                                            Entropy (8bit):5.011466665416709
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/2RQqGtlN62/EiMXGm2OHXT14YoHvhFvdQVIyV:SlSWB9eg/2RQrlo2MiDm2OHXqYoHvTFS
                                                                                                                                                                                                            MD5:3B310BB8C90CA716DC1AC5A697ACA9CD
                                                                                                                                                                                                            SHA1:CD583F49478DCDAD91EF78539502C6FC62945C1E
                                                                                                                                                                                                            SHA-256:51BFABCB3388107753A3C1A8CF31118E6627132BAA09B9878D9E7CEDBEBB4886
                                                                                                                                                                                                            SHA-512:F593B7A1FAF0EA6B42D5EE86C20C9A8F5CD7ACD9B30EF7755E45ECAFEA8752C32E4CF4BEDF531F494E59D9F0C49CCC6FCA077292E20794AA265DFC0A56DFE579
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/South_Georgia) {.. {-9223372036854775808 -8768 0 LMT}.. {-2524512832 -7200 0 -02}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):189
                                                                                                                                                                                                            Entropy (8bit):4.880390141563645
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/2RQqGt4r+DcsS:SlSWB9vsM3y7s3HAIgNT4pHN/2RQr4rV
                                                                                                                                                                                                            MD5:2C73A963F515376A46762CE153AAF5C5
                                                                                                                                                                                                            SHA1:996C3C93DFAD89EA80AC5DFA1DFBD7CECD9ED28D
                                                                                                                                                                                                            SHA-256:1C9CA8966FC8BD0BE70F4A187E17E56FB99139BC88C392E82BA2E23E23111C54
                                                                                                                                                                                                            SHA-512:35A9ADC047DB058D71C21FC4ECB57CD14B0D9BA4416506763D1800D72CE6C9E81636F332AAD3533616F05C86F90A60416BD4065C5F832A51AA3DC186218BDCAE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Atlantic/St_Helena) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2256
                                                                                                                                                                                                            Entropy (8bit):3.662522763865322
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:506KSBSdSs2SbSwGSyPU3lSsS5SGScSo/SkSuShSceS3SBSc7XSiSgSwSd/SJkS6:JKU+Ew0FU1TuhrR//tOIoOjXZfDWSkPR
                                                                                                                                                                                                            MD5:77C7ECE4FCBE150069B611C75E8DAA0E
                                                                                                                                                                                                            SHA1:22F4E5F15BCA92D8456B70BB36230F2605CA5E1C
                                                                                                                                                                                                            SHA-256:F0E99EF01F140CD5AAFE16803A657922207E6F7F6AF10B0AE795790916C302C4
                                                                                                                                                                                                            SHA-512:6FB57E8499A587292AFAFA9BD003721572393D5268CAF956230DA76983A112B27D6731BE561A22CCEF84935F43AC988B667C2DC404C157EA8D0E7830FC1A2AB8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Atlantic/Stanley) {.. {-9223372036854775808 -13884 0 LMT}.. {-2524507716 -13884 0 SMT}.. {-1824235716 -14400 0 -04}.. {-1018209600 -10800 1 -04}.. {-1003093200 -14400 0 -04}.. {-986760000 -10800 1 -04}.. {-971643600 -14400 0 -04}.. {-954705600 -10800 1 -04}.. {-939589200 -14400 0 -04}.. {-923256000 -10800 1 -04}.. {-908139600 -14400 0 -04}.. {-891806400 -10800 1 -04}.. {-876690000 -14400 0 -04}.. {-860356800 -10800 1 -04}.. {420606000 -7200 0 -03}.. {433303200 -7200 1 -03}.. {452052000 -10800 0 -03}.. {464151600 -7200 1 -03}.. {483501600 -10800 0 -03}.. {495597600 -14400 0 -04}.. {495604800 -10800 1 -04}.. {514350000 -14400 0 -04}.. {527054400 -10800 1 -04}.. {545799600 -14400 0 -04}.. {558504000 -10800 1 -04}.. {577249200 -14400 0 -04}.. {589953600 -10800 1 -04}.. {608698800 -14400 0 -04}.. {621403200 -10800 1 -04}.. {640753200 -14400 0 -
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):190
                                                                                                                                                                                                            Entropy (8bit):4.862270414049974
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq/xJjLkXHAIgoXjLyFvHRL/2QWCCjpMFBx/h4QWCCj1:SlSWB9vsM3yI9kHAIgmON/2DCeMFB/4d
                                                                                                                                                                                                            MD5:2EF41863430897F45E0CBB51E6A44069
                                                                                                                                                                                                            SHA1:8E9561060E9509FAF235E5E033FC9C2918E438DB
                                                                                                                                                                                                            SHA-256:DF7CBDDCBB2F5926A07D19A35739E5B8DCD9733C037F7D1FF95753C28D574674
                                                                                                                                                                                                            SHA-512:9D3A37D64DCCCA28093C30FAB595690D021FACEC15F351A77CA33A779D645D305A2FA031869F0DE3B0404C498C2C321D3D02E4DC592D3C632F6700F5DCB54900
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Sydney)]} {.. LoadTimeZoneFile Australia/Sydney..}..set TZData(:Australia/ACT) $TZData(:Australia/Sydney)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8372
                                                                                                                                                                                                            Entropy (8bit):3.894755849491153
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:j8SY62BXovlCyRL8pJXa4NyPaNw0leasxMQ/UvuQPxBFNsLQ2nDs020DdDncIsea:j8X3Xzgl3PaN8asiQ/Uv9UnvtCaRs
                                                                                                                                                                                                            MD5:94E1A0C4326D09AF103107E64625CC6C
                                                                                                                                                                                                            SHA1:C026565F020EB158309549D98313632BAA79205F
                                                                                                                                                                                                            SHA-256:5C43D3152982BCFD5B9F51D0E909CF3A558BED1C270FEFFE030531D38D6F91B7
                                                                                                                                                                                                            SHA-512:CA08A8BC0EB740D59650FE0A9E56D9E169348AD0994F2BFFD6CCFBF9CC42E82F892FB719E80C4E2084B5702E9725C651359EE3066BD71BB19397EA83B6A68430
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Adelaide) {.. {-9223372036854775808 33260 0 LMT}.. {-2364110060 32400 0 ACST}.. {-2230189200 34200 0 ACST}.. {-1672558200 37800 1 ACDT}.. {-1665387000 34200 0 ACST}.. {-883639800 37800 1 ACDT}.. {-876123000 34200 0 ACST}.. {-860398200 37800 1 ACDT}.. {-844673400 34200 0 ACST}.. {-828343800 37800 1 ACDT}.. {-813223800 34200 0 ACST}.. {31501800 34200 0 ACST}.. {57688200 37800 1 ACDT}.. {67969800 34200 0 ACST}.. {89137800 37800 1 ACDT}.. {100024200 34200 0 ACST}.. {120587400 37800 1 ACDT}.. {131473800 34200 0 ACST}.. {152037000 37800 1 ACDT}.. {162923400 34200 0 ACST}.. {183486600 37800 1 ACDT}.. {194977800 34200 0 ACST}.. {215541000 37800 1 ACDT}.. {226427400 34200 0 ACST}.. {246990600 37800 1 ACDT}.. {257877000 34200 0 ACST}.. {278440200 37800 1 ACDT}.. {289326600 34200 0 ACST}.. {309889800 37800 1 ACDT}.. {320776200 34200 0 ACST}
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):674
                                                                                                                                                                                                            Entropy (8bit):4.32071371733564
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB862ELmdHLOYCvSi0xT0ryRIvUr0obZv:5ELe6dvSi6L
                                                                                                                                                                                                            MD5:900B39F1D4AB93A445F37B6C0A8DE3D9
                                                                                                                                                                                                            SHA1:DE82800779DCB8094C395B5024BD01FFA3C3BB8C
                                                                                                                                                                                                            SHA-256:0D3C39EDAB34A8DB31A658A1549772F7D69EB57565E40AA87B707953A2D854A4
                                                                                                                                                                                                            SHA-512:8D115D1D14FE6FF21A4AE77E3AAC075E6A877214E568956B9A4FD2E75A46E458CAA5AE26B483F128B4C62960D73BD7543BC32F22B760059423B3D9ABCBA24B6A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Brisbane) {.. {-9223372036854775808 36728 0 LMT}.. {-2366791928 36000 0 AEST}.. {-1672560000 39600 1 AEDT}.. {-1665388800 36000 0 AEST}.. {-883641600 39600 1 AEDT}.. {-876124800 36000 0 AEST}.. {-860400000 39600 1 AEDT}.. {-844675200 36000 0 AEST}.. {-828345600 39600 1 AEDT}.. {-813225600 36000 0 AEST}.. {31500000 36000 0 AEST}.. {57686400 39600 1 AEDT}.. {67968000 36000 0 AEST}.. {625593600 39600 1 AEDT}.. {636480000 36000 0 AEST}.. {657043200 39600 1 AEDT}.. {667929600 36000 0 AEST}.. {688492800 39600 1 AEDT}.. {699379200 36000 0 AEST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8437
                                                                                                                                                                                                            Entropy (8bit):3.902306256303896
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:QZSSY62BXovldRL8q75aANyPaNw0leasxMQ/UvuQPxBFNsLQ2nDs020DdDncIsea:QZSX3X2QfPaN8asiQ/Uv9UnvtCaRs
                                                                                                                                                                                                            MD5:1553DAAB804A6C9BB15D711554980D3B
                                                                                                                                                                                                            SHA1:5E3161B1FBB4C246DCB5E11ABD94095121CE38ED
                                                                                                                                                                                                            SHA-256:734F295BD0B558BDF6178DE62151B8913699D08AB2B1D101C55B8DEBC410074C
                                                                                                                                                                                                            SHA-512:06B21886070E39E390ECBD18841B7FDBFCA2C7C8573495D2BAA2B92EB113CD1C73C18D73C49DE3C49572CBCBCBED2FAD3248BC651BEB825A1E089B1DEDEFCBFA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Broken_Hill) {.. {-9223372036854775808 33948 0 LMT}.. {-2364110748 36000 0 AEST}.. {-2314951200 32400 0 ACST}.. {-2230189200 34200 0 ACST}.. {-1672558200 37800 1 ACDT}.. {-1665387000 34200 0 ACST}.. {-883639800 37800 1 ACDT}.. {-876123000 34200 0 ACST}.. {-860398200 37800 1 ACDT}.. {-844673400 34200 0 ACST}.. {-828343800 37800 1 ACDT}.. {-813223800 34200 0 ACST}.. {31501800 34200 0 ACST}.. {57688200 37800 1 ACDT}.. {67969800 34200 0 ACST}.. {89137800 37800 1 ACDT}.. {100024200 34200 0 ACST}.. {120587400 37800 1 ACDT}.. {131473800 34200 0 ACST}.. {152037000 37800 1 ACDT}.. {162923400 34200 0 ACST}.. {183486600 37800 1 ACDT}.. {194977800 34200 0 ACST}.. {215541000 37800 1 ACDT}.. {226427400 34200 0 ACST}.. {246990600 37800 1 ACDT}.. {257877000 34200 0 ACST}.. {278440200 37800 1 ACDT}.. {289326600 34200 0 ACST}.. {309889800 37800 1
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):195
                                                                                                                                                                                                            Entropy (8bit):4.851279484907769
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq/xJjLkXHAIgoXjLyFvHRL/2QWCCjnSV1+QWCCjLBn:SlSWB9vsM3yI9kHAIgmON/2DCcq+DCyB
                                                                                                                                                                                                            MD5:8944D3DF8FBECC03A8FB18C3B2DA3B53
                                                                                                                                                                                                            SHA1:6B17B38D6560592CA49840C47DB9BDA7E79F9F76
                                                                                                                                                                                                            SHA-256:5FE3CED97293FE0573D5ECE0CEF59CE5DDB4C57BC568AE7199E77B01D3ADE17C
                                                                                                                                                                                                            SHA-512:907D8BB7EA840E0B3AC683884F2F709A2C06D67CE9258BE46400A0DA63581A9B1403A44FA43E1059BE8F5C7E06F9FA05C176309AD6295317BF14F0E9FA5741E4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Sydney)]} {.. LoadTimeZoneFile Australia/Sydney..}..set TZData(:Australia/Canberra) $TZData(:Australia/Sydney)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):193
                                                                                                                                                                                                            Entropy (8bit):4.79231670095588
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3yI4DVJHAIgxnvVWAN/2DCkx+4DCVDy:MByMjUQVv8At2s4Ky
                                                                                                                                                                                                            MD5:0C1DFC0877CE8EB08007B7C2B7AF2D87
                                                                                                                                                                                                            SHA1:02F835BE2DA4FCA79DC2A6959BB4EB6ACC8DF708
                                                                                                                                                                                                            SHA-256:1DD4EC4ED4F854E2EF6162B2F28C89208710F8EC5AABB95FFA9425D3FBBCAB13
                                                                                                                                                                                                            SHA-512:358347045915B7D10940DB15E49528D0C636BEC1BE70129847D0B9D034F9E96E847394D88358E87D98A9E581605A3C2AB917B85FDE1296F290B4194BB7E3FA46
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Hobart)]} {.. LoadTimeZoneFile Australia/Hobart..}..set TZData(:Australia/Currie) $TZData(:Australia/Hobart)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):437
                                                                                                                                                                                                            Entropy (8bit):4.508468081487136
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB862pmdHPCvZUjMWpXgda/gd026Xgdvgd+v:5peKvZqMSX+4+56X+v+Q
                                                                                                                                                                                                            MD5:A81864B2C0BD7BF81F4FA21F17800059
                                                                                                                                                                                                            SHA1:518AC9E040A17083ED3962F4FBB47D1D83764FF7
                                                                                                                                                                                                            SHA-256:AC004FD4B3C536406991EC13EBB3E64E0EC0C7B264BC18C0700C8FA545868155
                                                                                                                                                                                                            SHA-512:3C24F4C2CC3072B3E820FCC1C68A747DCCBB9481FE743C1555783CC932DCBA44FE4851A732D24EABF62E845474D4E1278F120A04DB7549A18C7C49C31FB8D425
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Darwin) {.. {-9223372036854775808 31400 0 LMT}.. {-2364108200 32400 0 ACST}.. {-2230189200 34200 0 ACST}.. {-1672558200 37800 1 ACDT}.. {-1665387000 34200 0 ACST}.. {-883639800 37800 1 ACDT}.. {-876123000 34200 0 ACST}.. {-860398200 37800 1 ACDT}.. {-844673400 34200 0 ACST}.. {-828343800 37800 1 ACDT}.. {-813223800 34200 0 ACST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):759
                                                                                                                                                                                                            Entropy (8bit):4.110997549215461
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB862EmdHvOYCvV2mV22wF2nUV2CF2+V2pCwF21UF2biV2cHVKF25V2VF2cV2tFq:5Eemdvg2wQCKZ4j5c0LVmtH1iknohwQT
                                                                                                                                                                                                            MD5:1BC8DBD2E24606EFA49F933034FC0EEF
                                                                                                                                                                                                            SHA1:A511695A1B87A689C6BFF65257C11D3962FDDA3D
                                                                                                                                                                                                            SHA-256:79D0C770A304360DB33F3D1EF7B3935F1E4E8125893E0DCE683AC35A51302CFB
                                                                                                                                                                                                            SHA-512:A839D390D70F22FC833322029B732F3AE68FF48793B07005041BD12322DD6E5D5E5FF31787AA004A507A57F8FC245133891F266C4EF19D49F085E6B412E5B04C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Eucla) {.. {-9223372036854775808 30928 0 LMT}.. {-2337928528 31500 0 +0945}.. {-1672555500 35100 1 +0945}.. {-1665384300 31500 0 +0945}.. {-883637100 35100 1 +0945}.. {-876120300 31500 0 +0945}.. {-860395500 35100 1 +0945}.. {-844670700 31500 0 +0945}.. {-836473500 35100 0 +0945}.. {152039700 35100 1 +0945}.. {162926100 31500 0 +0945}.. {436295700 35100 1 +0945}.. {447182100 31500 0 +0945}.. {690311700 35100 1 +0945}.. {699383700 31500 0 +0945}.. {1165079700 35100 1 +0945}.. {1174756500 31500 0 +0945}.. {1193505300 35100 1 +0945}.. {1206810900 31500 0 +0945}.. {1224954900 35100 1 +0945}.. {1238260500 31500 0 +0945}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8734
                                                                                                                                                                                                            Entropy (8bit):3.8515786470328823
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:aOqigkx6WsYyS39nQiAmcO38EJ8i/V9cYgCqMEjKeIZ3wQb25Ly04:aOq05hnQiAmcOM6e0pj
                                                                                                                                                                                                            MD5:5E04BF8E1DEBFCC4130FDD1BBD67B2DF
                                                                                                                                                                                                            SHA1:796AADCE7BB2FAF5E6FC916C941A4E3DCAFACC9E
                                                                                                                                                                                                            SHA-256:D813F6A97BEFC22CA4F24C59EB755D269B9C68A449CC7CF0D2C61F911860EBE7
                                                                                                                                                                                                            SHA-512:3A69CF1D1F57D6BD39E5F4DAF76BBB06A749D42BEB29452A0A5BDAA68F5DACC0DF176EDDA7A083F5B5B84FC651926C09D46CAAD2F6C4F1595AB9CCA1A958D653
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Hobart) {.. {-9223372036854775808 35356 0 LMT}.. {-2345795356 36000 0 AEST}.. {-1680508800 39600 1 AEDT}.. {-1665388800 36000 0 AEST}.. {-1646640000 39600 1 AEDT}.. {-1635753600 36000 0 AEST}.. {-1615190400 39600 1 AEDT}.. {-1604304000 36000 0 AEST}.. {-1583920800 36000 0 AEST}.. {-883641600 39600 1 AEDT}.. {-876124800 36000 0 AEST}.. {-860400000 39600 1 AEDT}.. {-844675200 36000 0 AEST}.. {-828345600 39600 1 AEDT}.. {-813225600 36000 0 AEST}.. {-94730400 36000 0 AEST}.. {-71136000 39600 1 AEDT}.. {-55411200 36000 0 AEST}.. {-37267200 39600 1 AEDT}.. {-25776000 36000 0 AEST}.. {-5817600 39600 1 AEDT}.. {5673600 36000 0 AEST}.. {25632000 39600 1 AEDT}.. {37728000 36000 0 AEST}.. {57686400 39600 1 AEDT}.. {67968000 36000 0 AEST}.. {89136000 39600 1 AEDT}.. {100022400 36000 0 AEST}.. {120585600 39600 1 AEDT}.. {131472000 36000 0 AES
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):199
                                                                                                                                                                                                            Entropy (8bit):4.912882643701746
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3yIoGEoPHAIgjGg6N/2DCkx/2DCPGUv:MByMjeXV6t2a8v
                                                                                                                                                                                                            MD5:425DC7B1E31F4AA41DAD74E3C9AE3562
                                                                                                                                                                                                            SHA1:D92A3269F7BF5EC00F082C64CEF6E20C43017180
                                                                                                                                                                                                            SHA-256:4D84E4040FBC529C9E0366BB74D0CFADEEEEDA0DFCC6C2C9204DED6C6455CAC3
                                                                                                                                                                                                            SHA-512:F3031F16C0D00D9F8A38CD378F599EB3E63F4FF85F120DB38E3013E93F08E6F512D969F164BBC88CD625910FB3E086F3352E5B8FFC1373C3CC98F363FB3FD3F7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Lord_Howe)]} {.. LoadTimeZoneFile Australia/Lord_Howe..}..set TZData(:Australia/LHI) $TZData(:Australia/Lord_Howe)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):824
                                                                                                                                                                                                            Entropy (8bit):4.249672335529665
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB862gtmdHVCvCi0xT0ryRIvUr0obbty/ywtUj3yv:5gteMvCi6Xlt8
                                                                                                                                                                                                            MD5:504A422280E0459A2126E7CB02F527E6
                                                                                                                                                                                                            SHA1:EF61B98EFB1E44EE59020E99A69EA67D6B8ACFC2
                                                                                                                                                                                                            SHA-256:01B278309353849CC2FDF62A30E2FF483833D5713CF5E329252738BE6F2C0A84
                                                                                                                                                                                                            SHA-512:BFDAAD56D817CD3AAB17DFD0A33EFDD422645BC542ABE269C0F8520E33796DF4F19EAB2E40BFC6C4AF93EF654239B8F2E285639B4662040D865B9C340A23CFAD
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Lindeman) {.. {-9223372036854775808 35756 0 LMT}.. {-2366790956 36000 0 AEST}.. {-1672560000 39600 1 AEDT}.. {-1665388800 36000 0 AEST}.. {-883641600 39600 1 AEDT}.. {-876124800 36000 0 AEST}.. {-860400000 39600 1 AEDT}.. {-844675200 36000 0 AEST}.. {-828345600 39600 1 AEDT}.. {-813225600 36000 0 AEST}.. {31500000 36000 0 AEST}.. {57686400 39600 1 AEDT}.. {67968000 36000 0 AEST}.. {625593600 39600 1 AEDT}.. {636480000 36000 0 AEST}.. {657043200 39600 1 AEDT}.. {667929600 36000 0 AEST}.. {688492800 39600 1 AEDT}.. {699379200 36000 0 AEST}.. {709912800 36000 0 AEST}.. {719942400 39600 1 AEDT}.. {731433600 36000 0 AEST}.. {751996800 39600 1 AEDT}.. {762883200 36000 0 AEST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7764
                                                                                                                                                                                                            Entropy (8bit):3.5615258807990537
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:pmz39IyKxb/JbcD9gKniAF23QbNS1fEGXALNbbT2JFJ/FaKaTQ9ZJhRVK:p+cpVKniAF2AbkFKL
                                                                                                                                                                                                            MD5:10F983F4683CDE13A1228AC0B04D8513
                                                                                                                                                                                                            SHA1:45378BA5949BE53D698108F50FECFF50C9E3D296
                                                                                                                                                                                                            SHA-256:76D1F1ED67B8F8D6903789C2FDDF79590A83677972D416F5F3C9687614EC6238
                                                                                                                                                                                                            SHA-512:D60D802EF215A33750E4F859657BA12A67084B1E9FCF1B4A7CEEE7B9D816BC2C6670775D93C88EC8380CDD7790AD574133D6F90F0828F848313C26583B2F196A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Lord_Howe) {.. {-9223372036854775808 38180 0 LMT}.. {-2364114980 36000 0 AEST}.. {352216800 37800 0 +1030}.. {372785400 41400 1 +1030}.. {384273000 37800 0 +1030}.. {404839800 41400 1 +1030}.. {415722600 37800 0 +1030}.. {436289400 41400 1 +1030}.. {447172200 37800 0 +1030}.. {467739000 41400 1 +1030}.. {478621800 37800 0 +1030}.. {488984400 37800 0 +1030}.. {499188600 39600 1 +1030}.. {511282800 37800 0 +1030}.. {530033400 39600 1 +1030}.. {542732400 37800 0 +1030}.. {562087800 39600 1 +1030}.. {574786800 37800 0 +1030}.. {594142200 39600 1 +1030}.. {606236400 37800 0 +1030}.. {625591800 39600 1 +1030}.. {636476400 37800 0 +1030}.. {657041400 39600 1 +1030}.. {667926000 37800 0 +1030}.. {688491000 39600 1 +1030}.. {699375600 37800 0 +1030}.. {719940600 39600 1 +1030}.. {731430000 37800 0 +1030}.. {751995000 39600 1 +1030}.. {762
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8341
                                                                                                                                                                                                            Entropy (8bit):3.8532171550973526
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:Yyigkp2EUyn8/dnQiAmcO38EJ8i/V9cYgCqMEjKeIZ3wQb25Ly04:Yy3VnQiAmcOM6e0pj
                                                                                                                                                                                                            MD5:40D06B80A4A0DB415270EFD9698B97BF
                                                                                                                                                                                                            SHA1:1999F0E8C7EBAA11BD21D64D9E07FA911F13C64C
                                                                                                                                                                                                            SHA-256:F21B9EA51C0D41BAD0420FE0601E5A4B491FB895856F4BDDF6541D704469D92F
                                                                                                                                                                                                            SHA-512:E47D597CC85D177CF2804C44C216EB4C5B74472457F15F697704311A847BF8A051DCAFD26FA61DD689555F35640151E26F25D5DC5319EFEFEA62AD86657A4A95
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Melbourne) {.. {-9223372036854775808 34792 0 LMT}.. {-2364111592 36000 0 AEST}.. {-1672560000 39600 1 AEDT}.. {-1665388800 36000 0 AEST}.. {-883641600 39600 1 AEDT}.. {-876124800 36000 0 AEST}.. {-860400000 39600 1 AEDT}.. {-844675200 36000 0 AEST}.. {-828345600 39600 1 AEDT}.. {-813225600 36000 0 AEST}.. {31500000 36000 0 AEST}.. {57686400 39600 1 AEDT}.. {67968000 36000 0 AEST}.. {89136000 39600 1 AEDT}.. {100022400 36000 0 AEST}.. {120585600 39600 1 AEDT}.. {131472000 36000 0 AEST}.. {152035200 39600 1 AEDT}.. {162921600 36000 0 AEST}.. {183484800 39600 1 AEDT}.. {194976000 36000 0 AEST}.. {215539200 39600 1 AEDT}.. {226425600 36000 0 AEST}.. {246988800 39600 1 AEDT}.. {257875200 36000 0 AEST}.. {278438400 39600 1 AEDT}.. {289324800 36000 0 AEST}.. {309888000 39600 1 AEDT}.. {320774400 36000 0 AEST}.. {341337600 39600 1 AEDT}.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):190
                                                                                                                                                                                                            Entropy (8bit):4.893713405897538
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq/xJjLkXHAIgoXjLyFvHRL/2QWCCjREeQWCCjLBn:SlSWB9vsM3yI9kHAIgmON/2DC5eDCyB
                                                                                                                                                                                                            MD5:80B7CDD1EA5A5308CE84C038180005F2
                                                                                                                                                                                                            SHA1:B7CA15B58ADA8CA3EB74B7971073022D57D8EE70
                                                                                                                                                                                                            SHA-256:73D7C9E207E61ACF8DF7242BDCD84488189033E22A84873A953B65DE02FA1B0B
                                                                                                                                                                                                            SHA-512:F627F5FF335600AC9158D6A0D3694AB7E70180177449C17B5605BBF7B1B7F8FB447A9C207F4E1BCB627074DB47B8A66F5D78E03C6DB8FA17F8BDD6AABB331665
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Sydney)]} {.. LoadTimeZoneFile Australia/Sydney..}..set TZData(:Australia/NSW) $TZData(:Australia/Sydney)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):192
                                                                                                                                                                                                            Entropy (8bit):4.830368875485429
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq/xJjbvvXHAIgoXjbBvRL/2QWCCjsrQWCCjbi:SlSWB9vsM3yIFHAIg2N/2DCZrDCl
                                                                                                                                                                                                            MD5:14CB7EA1C028F457345EBEB8ADDC9237
                                                                                                                                                                                                            SHA1:208BF676F56533BA271D1B98363A766DF17CF6F2
                                                                                                                                                                                                            SHA-256:A983C9CAD7E542CAED43B083E68CD2B782959A4B54015F374C29250D3ACF9B8D
                                                                                                                                                                                                            SHA-512:099F65E5FA705FD7257CF7B8E103905EE313C6D082844F69CCD3F318E3E7F4098B29F952FA0AA28655E1FE290A0FB2E809911088315889DE7CAAF0E04698C2FC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Darwin)]} {.. LoadTimeZoneFile Australia/Darwin..}..set TZData(:Australia/North) $TZData(:Australia/Darwin)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):739
                                                                                                                                                                                                            Entropy (8bit):4.31793586514766
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB8623mdHCBdCvmlXz6zezzOz4iaLYvzkzi4zm5fVcBhg8mfev:53eCB0v4+e3Oz4iaLYbkzi4zxhfqw
                                                                                                                                                                                                            MD5:01B1A88867472AD60B8F5C0E1648E3ED
                                                                                                                                                                                                            SHA1:9975EA750458E8061DD8A83585675CB7E4910CA6
                                                                                                                                                                                                            SHA-256:FC1B54CA261074E47A8A486FEAC12DD04D46166D1D2B44163BD8791BEC32D275
                                                                                                                                                                                                            SHA-512:20BDFBCD1A5038C81552EBD955F3921DE3447A1F30E64935937768B2B98735AE53049601DCDD2D519646C78E6D03289EB465CFF4F2DADEA7D89A329504C6C475
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Perth) {.. {-9223372036854775808 27804 0 LMT}.. {-2337925404 28800 0 AWST}.. {-1672552800 32400 1 AWDT}.. {-1665381600 28800 0 AWST}.. {-883634400 32400 1 AWDT}.. {-876117600 28800 0 AWST}.. {-860392800 32400 1 AWDT}.. {-844668000 28800 0 AWST}.. {-836470800 32400 0 AWST}.. {152042400 32400 1 AWDT}.. {162928800 28800 0 AWST}.. {436298400 32400 1 AWDT}.. {447184800 28800 0 AWST}.. {690314400 32400 1 AWDT}.. {699386400 28800 0 AWST}.. {1165082400 32400 1 AWDT}.. {1174759200 28800 0 AWST}.. {1193508000 32400 1 AWDT}.. {1206813600 28800 0 AWST}.. {1224957600 32400 1 AWDT}.. {1238263200 28800 0 AWST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):203
                                                                                                                                                                                                            Entropy (8bit):4.803539644461131
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3yIaWhSHAIgPWAvN/2DCoRWJvFBx+DC7WN:MByMjL9t2rOvFel
                                                                                                                                                                                                            MD5:401B6B2E30EF17BE20212645287EB94B
                                                                                                                                                                                                            SHA1:67D15A45C61122CE680B829FE0FA3A1C501A8C8F
                                                                                                                                                                                                            SHA-256:DDA669B9BFB3E08FC23CE67030148B9E4740824ADD8DE02580D6AFD31CE05BAB
                                                                                                                                                                                                            SHA-512:F4348F8F4FF261C47854725AEE4E14E7E334B3C31496E5C46B0E0041551CB6861380E684E8888AFE9DA7E8E97236AC322B9CE2738EF245E9D46C9681665F83A1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Brisbane)]} {.. LoadTimeZoneFile Australia/Brisbane..}..set TZData(:Australia/Queensland) $TZData(:Australia/Brisbane)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):198
                                                                                                                                                                                                            Entropy (8bit):4.752918480727309
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3yIDRpGSHAIgSRrN/2DCa7QDCuRpyn:MByMjdpQYrt23QHpy
                                                                                                                                                                                                            MD5:D226A0718185854DFE549E00856AA8D5
                                                                                                                                                                                                            SHA1:94EE96FAE259D90C2FDF169DD95BD82B3171FFAE
                                                                                                                                                                                                            SHA-256:D9DCFDC377901EC0C0FEB9CEA743C2C1425273F69A1BAA7BF3B74FEC5885B267
                                                                                                                                                                                                            SHA-512:7EE29A7235CAAEF4889246B7A2241CA9A0D5D2B2E1D56B20141247C93B8736F17280F0D46004AC4588E137D1E76F661C779C906BBFC2B5F8FA73C19F7657F952
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Adelaide)]} {.. LoadTimeZoneFile Australia/Adelaide..}..set TZData(:Australia/South) $TZData(:Australia/Adelaide)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8338
                                                                                                                                                                                                            Entropy (8bit):3.847525715050911
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:AZJigk42/yn8/dnQiAmcO38EJ8i/V9cYgCqMEjKeIZ3wQb25Ly04:AZJuVnQiAmcOM6e0pj
                                                                                                                                                                                                            MD5:C0F1776E011C4C86B7709A592E7CA1EB
                                                                                                                                                                                                            SHA1:1CA528D529BF4995E145D6E0D87A8752A3577E7F
                                                                                                                                                                                                            SHA-256:FC453486325ADE1D31F14087B76D4936F3A6D551ABD1DB6FCAC129BDB043951C
                                                                                                                                                                                                            SHA-512:F872182962C2615A35F012ECAB30C88F07C6BEF0261207AD52706DB22D8CDD0DA65723CD801FDA7C548C5EB0ECFC39DD66CC17503BAA3BBB77BFA35D20650E4F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Australia/Sydney) {.. {-9223372036854775808 36292 0 LMT}.. {-2364113092 36000 0 AEST}.. {-1672560000 39600 1 AEDT}.. {-1665388800 36000 0 AEST}.. {-883641600 39600 1 AEDT}.. {-876124800 36000 0 AEST}.. {-860400000 39600 1 AEDT}.. {-844675200 36000 0 AEST}.. {-828345600 39600 1 AEDT}.. {-813225600 36000 0 AEST}.. {31500000 36000 0 AEST}.. {57686400 39600 1 AEDT}.. {67968000 36000 0 AEST}.. {89136000 39600 1 AEDT}.. {100022400 36000 0 AEST}.. {120585600 39600 1 AEDT}.. {131472000 36000 0 AEST}.. {152035200 39600 1 AEDT}.. {162921600 36000 0 AEST}.. {183484800 39600 1 AEDT}.. {194976000 36000 0 AEST}.. {215539200 39600 1 AEDT}.. {226425600 36000 0 AEST}.. {246988800 39600 1 AEDT}.. {257875200 36000 0 AEST}.. {278438400 39600 1 AEDT}.. {289324800 36000 0 AEST}.. {309888000 39600 1 AEDT}.. {320774400 36000 0 AEST}.. {341337600 39600 1 AEDT}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):195
                                                                                                                                                                                                            Entropy (8bit):4.777331394201868
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3yI4DVJHAIgxnvVWAN/2DC3neDCVDy:MByMjUQVv8At2+eKy
                                                                                                                                                                                                            MD5:9C58D9EFBB03472BBDA76CE2FFAD4BB4
                                                                                                                                                                                                            SHA1:30959E3681B64AE26F7FA3957887896C26AF7F19
                                                                                                                                                                                                            SHA-256:C94FA7A7640CD00963EE8FF1A3D9DCDA2075408739D998EDBF7CFC998DB764FD
                                                                                                                                                                                                            SHA-512:2D6B778217726691F2CB4A4995A8B1AB08DDB7FE4570A3FD04EF54F718F455EF3CBD4EEF1A1BCC99A2088C82A6E89DB455BAF1327CECD6BF608837E50F14A6C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Hobart)]} {.. LoadTimeZoneFile Australia/Hobart..}..set TZData(:Australia/Tasmania) $TZData(:Australia/Hobart)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):204
                                                                                                                                                                                                            Entropy (8bit):4.818875198673406
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3yIvFfkSHAIgoFNNvN/2DCzyQDCMF4:MByMj9fKaNNvt2xQz4
                                                                                                                                                                                                            MD5:0B144A2E47C81354BC510BC741DE5150
                                                                                                                                                                                                            SHA1:A7396F1741F02C6C208FD1286362E4E0720198B8
                                                                                                                                                                                                            SHA-256:DBEF9C5BDD290FEC5FA740D697143332D3CA1FC373CF1DF736F1883AC9BA3298
                                                                                                                                                                                                            SHA-512:562B029591F9ADB8C324BA56E849B2B524E91B26D3DB441510194882A8E1E63E6948D041874A00A0A76F29925A1CEAC53DD2AE5D7F23123B6FE919346CBFD8CC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Melbourne)]} {.. LoadTimeZoneFile Australia/Melbourne..}..set TZData(:Australia/Victoria) $TZData(:Australia/Melbourne)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):188
                                                                                                                                                                                                            Entropy (8bit):4.831654343064909
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq/xJjXFeyXHAIgoXjrWARL/2QWCCjH0QWCCjQ:SlSWB9vsM3yInHAIgOWAN/2DC00DCt
                                                                                                                                                                                                            MD5:5F5916CB038876BE27AA5E2AD74EE085
                                                                                                                                                                                                            SHA1:18AC21B638188B542455BA3DA91F958DF1724E68
                                                                                                                                                                                                            SHA-256:75ABB7F20C4A0B618138AA190AF33CEAF2A6D2C707DA6C1314E4BFF2F9904F58
                                                                                                                                                                                                            SHA-512:ADFD83E292AC1BB5E19255A9B2DA0E3BB9323A5F9B92D458DE34C291D7F9B6CFBBF62AA3351FB320E54F34305DD485ADC72134D21AFA6A27B2B8B7D93DCA2113
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Perth)]} {.. LoadTimeZoneFile Australia/Perth..}..set TZData(:Australia/West) $TZData(:Australia/Perth)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):212
                                                                                                                                                                                                            Entropy (8bit):4.918079927018121
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3yIcKlHAIgJK3N/2DCkuM0DC9KM:MByMjcKeJK3t2kVSKM
                                                                                                                                                                                                            MD5:BEDEA56FCE4B2F0A3F3E9319856A5560
                                                                                                                                                                                                            SHA1:9FD0FE998A003C6B4CCCD00A977153347DE07F55
                                                                                                                                                                                                            SHA-256:55A9264D0414644A1BE342106AE86086A6659596DC9322A74FC4D1DDB41F7C60
                                                                                                                                                                                                            SHA-512:7C438B72262B99EDEEB31AC95E0135BB722A3B0B049278B6DE67DB5FB501837FB9C03785233B538E83F4B56104F6EA3B3DA0F7C2275E0F78F232161840AA4C63
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Australia/Broken_Hill)]} {.. LoadTimeZoneFile Australia/Broken_Hill..}..set TZData(:Australia/Yancowinna) $TZData(:Australia/Broken_Hill)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):194
                                                                                                                                                                                                            Entropy (8bit):4.888429541699473
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7thteSHAIgpth9RN/xWh490th4:MByMYdIp7tQ490I
                                                                                                                                                                                                            MD5:A8A7A10DA4321819ED71F891480770F8
                                                                                                                                                                                                            SHA1:930674EF7711542D7F471A59C1870D4576E027FD
                                                                                                                                                                                                            SHA-256:2F594239A434052D36053A2B3EAB134EADBAD06EB6737E67CF72166DAB157537
                                                                                                                                                                                                            SHA-512:C6AD1869A713DDE0E4DE53F7894E5CE0B7AEFDDD7C5C3D83BB5B92FB7D8E20B373A6694045053E1AE8EA98A7B7D0C052EF2C21310E47DC650A7A399A5F73D586
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Rio_Branco)]} {.. LoadTimeZoneFile America/Rio_Branco..}..set TZData(:Brazil/Acre) $TZData(:America/Rio_Branco)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):190
                                                                                                                                                                                                            Entropy (8bit):4.875339623736144
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0wKy4oeyXHAIg20wKARL/1bIAJl0IAcGEwKyovn:SlSWB9vsM3y7/rDSHAIgp/AN/xIAE90j
                                                                                                                                                                                                            MD5:E0D0EFBEC37E27532B49FF6DD9893DA0
                                                                                                                                                                                                            SHA1:9C00993A885AF448E48201A46E17629A7A602FC6
                                                                                                                                                                                                            SHA-256:A676562A90FF8587A775F6F0E3BE05D870456A56D25B5330816BF9043C8D475B
                                                                                                                                                                                                            SHA-512:AB0E6907F9C0002CA5C050A0069AF013B14BADA08CA4553C96B302C078DF7629D5D7EDE4A19A53DEC6E7B9E6D9857F14EC7A1DB9BC11F2EEC9FFBAC70E129EEE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Noronha)]} {.. LoadTimeZoneFile America/Noronha..}..set TZData(:Brazil/DeNoronha) $TZData(:America/Noronha)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):191
                                                                                                                                                                                                            Entropy (8bit):4.948480276987682
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0tQJXveyXHAIg20tQJE6RL/1bJHIAcGEtQJXy:SlSWB9vsM3y7tIGSHAIgpt36N/xR90tF
                                                                                                                                                                                                            MD5:FCCB5F44903E1B988A058E5BBF5E163B
                                                                                                                                                                                                            SHA1:E1CC03DD4A804C7305D8B0C12D8451D08AE262EA
                                                                                                                                                                                                            SHA-256:961FB3AB99A63B1E9704B737EAB2D588B5A39D253A213E175CC678BEDFFD498D
                                                                                                                                                                                                            SHA-512:F31C80E4AD6EBE6CB8A3382E0052DC47601D073E8F81375D50241105675AA3AB45433FFD0534524D9992ABE1086C6671D85FF7C72B0D6766EB9984426F608B77
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Sao_Paulo)]} {.. LoadTimeZoneFile America/Sao_Paulo..}..set TZData(:Brazil/East) $TZData(:America/Sao_Paulo)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):182
                                                                                                                                                                                                            Entropy (8bit):4.902113962502196
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0znQZF3vXHAIg20znQv5RL/1bbAWVIAcGEznQe:SlSWB9vsM3y7zn+PHAIgpznSN/xn90zN
                                                                                                                                                                                                            MD5:9F4B43F4F27D0B7EAC0C5401A1A794B4
                                                                                                                                                                                                            SHA1:2A8543B994E93E54BD50EAA78463905E6A8EBE74
                                                                                                                                                                                                            SHA-256:0500C9A248C8CE9030EA30D0AF9DD95DC465480BAF60646C0B7C511FA23C6D1F
                                                                                                                                                                                                            SHA-512:0ADAF708ACFBD80F4704951EEBC24AD144FD5856997A429279E804F3A7F7F9A8FED41DCEE85BFB1ECDBF1E05137E87E7430186474BCF5DE42067FFC74746F048
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Manaus)]} {.. LoadTimeZoneFile America/Manaus..}..set TZData(:Brazil/West) $TZData(:America/Manaus)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7736
                                                                                                                                                                                                            Entropy (8bit):3.7984816540097843
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:09+xKDBb0S274elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhlt7:9Ss41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                            MD5:6DB983AD72FB2A88FC557BE5E873336F
                                                                                                                                                                                                            SHA1:C64E988010087ED559A990B3D95078949C9B4D72
                                                                                                                                                                                                            SHA-256:E2AEA7CFD428A43D9DB938BCC476623ADC1250BD8057013A7FFF5F89D7FF8EFC
                                                                                                                                                                                                            SHA-512:C0A646F80FB2FD42D9146A4FD36CF5A7F62016684F8D5AF80453EC190F4AEA65EDADC5BCF071AE746ABFB43B29C27B2743F2152B6986D41BFDE1617CA774A7C5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:CET) {.. {-9223372036854775808 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-938905200 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-766623600 3600 0 CET}.. {228877200 7200 1 CEST}.. {243997200 3600 0 CET}.. {260326800 7200 1 CEST}.. {276051600 3600 0 CET}.. {291776400 7200 1 CEST}.. {307501200 3600 0 CET}.. {323830800 7200 1 CEST}.. {338950800 3600 0 CET}.. {354675600 7200 1 CEST}.. {370400400 3600 0 CET}.. {386125200 7200 1 CEST}.. {401850000 3600 0 CET}.. {417574800 7200 1 CEST}.. {433299600 3600 0 CET}.. {449024400 7200 1 CEST}.. {465354000 3600 0 CET}.. {481078800 7200
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8505
                                                                                                                                                                                                            Entropy (8bit):3.8095769056779916
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:e3HgahLi8hbZlNA604qSScBgN+4ctDzIVQ/c/3hNxTh:eQaUqtfA604qSBgI7DBch
                                                                                                                                                                                                            MD5:A6F88C55E8613A27DE3E6C25B0672910
                                                                                                                                                                                                            SHA1:3B593CC17BF153A6209FC5AACE7B88DA9603BD44
                                                                                                                                                                                                            SHA-256:73A9841F233AA657AFB6CED8A86A37D55FE5582DD996B9B28975D218BCCC078F
                                                                                                                                                                                                            SHA-512:526A922B1594A2800B03F363F7BFEC29203D4A4F2B49C5F2618469F59176CE4F8AFBA0616B226AC39D308DB05DE7147714D9B6CDBB2EA7373A041A4D47F50E2E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:CST6CDT) {.. {-9223372036854775808 -21600 0 CST}.. {-1633276800 -18000 1 CDT}.. {-1615136400 -21600 0 CST}.. {-1601827200 -18000 1 CDT}.. {-1583686800 -21600 0 CST}.. {-880214400 -18000 1 CWT}.. {-769395600 -18000 1 CPT}.. {-765392400 -21600 0 CST}.. {-84384000 -18000 1 CDT}.. {-68662800 -21600 0 CST}.. {-52934400 -18000 1 CDT}.. {-37213200 -21600 0 CST}.. {-21484800 -18000 1 CDT}.. {-5763600 -21600 0 CST}.. {9964800 -18000 1 CDT}.. {25686000 -21600 0 CST}.. {41414400 -18000 1 CDT}.. {57740400 -21600 0 CST}.. {73468800 -18000 1 CDT}.. {89190000 -21600 0 CST}.. {104918400 -18000 1 CDT}.. {120639600 -21600 0 CST}.. {126691200 -18000 1 CDT}.. {152089200 -21600 0 CST}.. {162374400 -18000 1 CDT}.. {183538800 -21600 0 CST}.. {199267200 -18000 1 CDT}.. {215593200 -21600 0 CST}.. {230716800 -18000 1 CDT}.. {247042800 -21600 0 CST}.. {262771200
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):189
                                                                                                                                                                                                            Entropy (8bit):4.804821796604604
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx02NEO/vXHAIg202NEqA6RL/0nalGe2IAcGE2NEOyn:SlSWB9vsM3y7UEOXHAIgpUEqA6N/0af9
                                                                                                                                                                                                            MD5:33A04963E70EBF29339204348E0DF874
                                                                                                                                                                                                            SHA1:456C0DB88ECE4D180EEE5AE5AEF5FBEB6E977D00
                                                                                                                                                                                                            SHA-256:6DC6354D761CBE7820C9186568CAB87AD48CA925507F6A740357195B60E16D87
                                                                                                                                                                                                            SHA-512:DF8F46827760BD7EC922C6837E0B6649B4FBD220B79E6F1B67FE3DD8CB3D2D035ECDAF4CF6CE5BDE6DC79C6F7B6EE2B9787AF08A97845CD0D647720A2E78D7EF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Halifax)]} {.. LoadTimeZoneFile America/Halifax..}..set TZData(:Canada/Atlantic) $TZData(:America/Halifax)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):191
                                                                                                                                                                                                            Entropy (8bit):4.863241040396457
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0po/vXHAIg20puFvHRL/0nPQox/h4IAcGEpoyn:SlSWB9vsM3y7pYHAIgppuRN/0d490pl
                                                                                                                                                                                                            MD5:97E50CE9FBA3F1A6DFCF333F9E6D592C
                                                                                                                                                                                                            SHA1:EE472C411079E788DBF32FAC9C5B7EE121960DC2
                                                                                                                                                                                                            SHA-256:DB32E83949D62478D229E9FB57BB1624D21B3A9CCEE4CD55335F8262C01D820A
                                                                                                                                                                                                            SHA-512:D547E3DC03848A677BE67F7CF4124E067F76EE09BB724A5B10F028BEA72C1526B17678A035B2C53F69498E9ECAACD3C5445D42B7FE58DF706DD2C5F2ADA05A73
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Winnipeg)]} {.. LoadTimeZoneFile America/Winnipeg..}..set TZData(:Canada/Central) $TZData(:America/Winnipeg)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):188
                                                                                                                                                                                                            Entropy (8bit):4.758562813220951
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0qMKLRXnXHAIg20qMKLRE6RL/0nbHboxp4IAcGEqM:SlSWB9vsM3y7RQtHAIgpRQPN/0Dboxpp
                                                                                                                                                                                                            MD5:4365BEFA3D50EEE20843EF97A095E512
                                                                                                                                                                                                            SHA1:7756049B4CD6459742686925E9516E64A9727306
                                                                                                                                                                                                            SHA-256:22844994AE893F3236A091B050E932E84A5218EC0D01F72595E17CCC471FA564
                                                                                                                                                                                                            SHA-512:CB265E79DF926026BEBF7158590369ABE5353C759540F509ABBA2A7ADBE59A705BC2AB936F400614BE610EDB761DE9A2B1E179A0A8B0A87E595392362C2516AA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Toronto)]} {.. LoadTimeZoneFile America/Toronto..}..set TZData(:Canada/Eastern) $TZData(:America/Toronto)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):192
                                                                                                                                                                                                            Entropy (8bit):4.8181126338833655
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx07nKL50vXHAIg207nKLyRRL/0nNYLo/4IAcGE7nK1:SlSWB9vsM3y77G2HAIgp7bN/0W8/4908
                                                                                                                                                                                                            MD5:FA0D0024AD72CCE4EC7229FA897FB1B7
                                                                                                                                                                                                            SHA1:4373A07F2674FE974189CC801987652AA97F0204
                                                                                                                                                                                                            SHA-256:D7A203E60FF19DCDEAAD14121720DE51DA73392D25B40FFA301C1935CDF89517
                                                                                                                                                                                                            SHA-512:82EF7F429604A69734B04D298B4C9C9AC3BE57B9DD8C4CECF59C7AB3470BDFBA0505886C4E6AA3864F5EC7FBB4C69C54CF153A6417376828234833013C29A0C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Edmonton)]} {.. LoadTimeZoneFile America/Edmonton..}..set TZData(:Canada/Mountain) $TZData(:America/Edmonton)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):196
                                                                                                                                                                                                            Entropy (8bit):4.998628928230972
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7tgYJHAIgptVN/0xdBx+90twv:MByMYnKpTt590g
                                                                                                                                                                                                            MD5:A2DCCB8BFC65DD4E7C3BB7F10DCEFF11
                                                                                                                                                                                                            SHA1:6FD2F4FAE06C5D4D3F189A167A98AA76497569DD
                                                                                                                                                                                                            SHA-256:87F42F45FD7D059CA47650D445420DE8320F3A7C1CBC7671FBFA8A8881274433
                                                                                                                                                                                                            SHA-512:F42E32C5BD785BA914E5054784BF67DDF951460A708290D1899621CEEDC63475B584FC052A86A3B6D45BF3C651D42427FB6F9CE2A2A33764DFFF731053BECC16
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/St_Johns)]} {.. LoadTimeZoneFile America/St_Johns..}..set TZData(:Canada/Newfoundland) $TZData(:America/St_Johns)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):194
                                                                                                                                                                                                            Entropy (8bit):4.887587766811186
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7ZLgXPHAIgpZLgFN/0N290ZLgK:MByMY13p1stx901/
                                                                                                                                                                                                            MD5:68900CE38FE0E40578323BBD3D75184E
                                                                                                                                                                                                            SHA1:9D5EAB5CBCD495DD46974207FBE354A81DD2070F
                                                                                                                                                                                                            SHA-256:5C4FD46054B190A6D4B92585B4DAE4E3A8233EE2996D14472835DDD264911DC6
                                                                                                                                                                                                            SHA-512:3EF53F0FCD8D88A1B977886BDFAA03D7B84EF021AC6BEDF7C571BFBF2242BFC3F3EB6A6B6A9C2F6852AF412A96DFBC30F3BB25A6619CBCD8736F3DF5B64DE1BF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Vancouver)]} {.. LoadTimeZoneFile America/Vancouver..}..set TZData(:Canada/Pacific) $TZData(:America/Vancouver)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):190
                                                                                                                                                                                                            Entropy (8bit):4.887593462838566
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0sAzE5Y5XHAIg20sAzEo5RL/0nogS64IAcGEsAzEB:SlSWB9vsM3y7hzi2HAIgphznN/0Hd499
                                                                                                                                                                                                            MD5:A4237BDCAF68B0EFECA97178F3DEE724
                                                                                                                                                                                                            SHA1:A9CBC02B5545A63A0C9B38C8FA7FA2DE6D483188
                                                                                                                                                                                                            SHA-256:46BA00AE3A07A4DC83D6CB517D87C9CBBA491B3421FE9AD6C74CAC5695EB73F7
                                                                                                                                                                                                            SHA-512:832BF256BE8CB2DD205DDE50017448D5830B46FF4DCA77BDB852067EE0C9DF9977014F2A3E3DD6944336158D8EA377CFBBE519EE5B56FB26EB64325B45476B9D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Regina)]} {.. LoadTimeZoneFile America/Regina..}..set TZData(:Canada/Saskatchewan) $TZData(:America/Regina)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):195
                                                                                                                                                                                                            Entropy (8bit):4.889486451014262
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7peR2fkSHAIgppeR2rN/0CF/490peR24:MByMYkGk7pkOtBQ90kB
                                                                                                                                                                                                            MD5:490D99BD5465CBF5A8FE28F33180B8A6
                                                                                                                                                                                                            SHA1:4783295C31A804BE98145270ED28956A0783E655
                                                                                                                                                                                                            SHA-256:A1B1AF37DC89C6BA663E4E967A18409AE4E0FA9EF1B908D0461368DA31001C09
                                                                                                                                                                                                            SHA-512:9F6B4F204A21B69E1DFCB766C0671D3736414C73269DCEDCDB4FC3DBA869BBA1511DF6B5061F8964F0AF9C3816133D04E5DFB8A6AD07CA06E7712787A8FECC5A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Whitehorse)]} {.. LoadTimeZoneFile America/Whitehorse..}..set TZData(:Canada/Yukon) $TZData(:America/Whitehorse)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):194
                                                                                                                                                                                                            Entropy (8bit):4.812019117774239
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7tfEJkHAIgptfEJo5N/0rHM490tfEJB:MByMYE9pEOt4X90EB
                                                                                                                                                                                                            MD5:6EF54792279C249B16877100682F1806
                                                                                                                                                                                                            SHA1:A62629EA055207D917740E3AEF4F0B005EA49CC4
                                                                                                                                                                                                            SHA-256:5B40167DD0C0B5C293861070C4AC249F78DDF8BAD798DD0165E3AE894C9B9570
                                                                                                                                                                                                            SHA-512:3CF93003C3EA2B4386660F0C87074F9AE2BAC4EE72D88451DCB1EA8B79502D2187B1608B6D5CE8D7EDC00AED99CF9DB7B006EB6ED2A2B5009F2C0E757D282D74
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Santiago)]} {.. LoadTimeZoneFile America/Santiago..}..set TZData(:Chile/Continental) $TZData(:America/Santiago)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):189
                                                                                                                                                                                                            Entropy (8bit):4.808907056781067
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQG7ZAJWXHAIgObT7ZAiFvRL/0bxOdBx/nUDH7ZAZv:SlSWB9vsM3ycJAUHAIgObJAiRN/04dBn
                                                                                                                                                                                                            MD5:2EC4FDD1EFBAF1D9F9DBAC8B1B5EDD09
                                                                                                                                                                                                            SHA1:FECED8EBC7B666628B7B45C9694FCB3A0B20A42A
                                                                                                                                                                                                            SHA-256:1E2DA1862E0E0F131B7C6EB12FAC5F920852C61C162993A30BC843A464A5AAD4
                                                                                                                                                                                                            SHA-512:74D61141505BAF1ABAD61FB91941C63C169EFE3C85829FEBB4D29A72EA54D1A07EC84E2E9B48E963E65CBF7663245459FAD288D620B1BEFFE682A2D1C243794D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Easter)]} {.. LoadTimeZoneFile Pacific/Easter..}..set TZData(:Chile/EasterIsland) $TZData(:Pacific/Easter)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):175
                                                                                                                                                                                                            Entropy (8bit):4.857134440822812
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx02TEMVFfXHAIg202TEyRRL/0lIAcGE2TEMy:SlSWB9vsM3y76EkHAIgp6EyRN/0l9068
                                                                                                                                                                                                            MD5:3FB16EA4A9B0529220133C4A7B05215B
                                                                                                                                                                                                            SHA1:BD56B6E76A92A5925140CB5CC3D940E1DE90993F
                                                                                                                                                                                                            SHA-256:6F4F2D7F5BCA4E5183460C0153D2B98F5239A99F149DE6638B311C73CEDB1329
                                                                                                                                                                                                            SHA-512:690EC1BCE7FA979BD55725B8ED6DF042BB331CAD332827B2C64B31F107539934AA5A30268B1F03D52697528E68A1BA72E4D56B5199A68B1ED897B75FAFB33A8A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Havana)]} {.. LoadTimeZoneFile America/Havana..}..set TZData(:Cuba) $TZData(:America/Havana)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7440
                                                                                                                                                                                                            Entropy (8bit):3.695300167191082
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:CgDIMcVbf+uO7DVopaNlKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYjlt:KlfyDjivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                            MD5:34339D40AC889DCB5A09D10F123175AD
                                                                                                                                                                                                            SHA1:57E1F70FA8999106FA3874A9CE1E75A7ACBC81E9
                                                                                                                                                                                                            SHA-256:64E284F9F7A36CC0A352809141D76E73A99344A9F30CFFEA254CBB9D2C589ADA
                                                                                                                                                                                                            SHA-512:2DCF16D9D7593FC3E5844E18FD689AADA157866490CFD37A38A47F747DDA189822055F6DD470CA2D77040D2C5A2527512880C22ED8EC16D9424EDF3DC228AFED
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:EET) {.. {-9223372036854775808 7200 0 EET}.. {228877200 10800 1 EEST}.. {243997200 7200 0 EET}.. {260326800 10800 1 EEST}.. {276051600 7200 0 EET}.. {291776400 10800 1 EEST}.. {307501200 7200 0 EET}.. {323830800 10800 1 EEST}.. {338950800 7200 0 EET}.. {354675600 10800 1 EEST}.. {370400400 7200 0 EET}.. {386125200 10800 1 EEST}.. {401850000 7200 0 EET}.. {417574800 10800 1 EEST}.. {433299600 7200 0 EET}.. {449024400 10800 1 EEST}.. {465354000 7200 0 EET}.. {481078800 10800 1 EEST}.. {496803600 7200 0 EET}.. {512528400 10800 1 EEST}.. {528253200 7200 0 EET}.. {543978000 10800 1 EEST}.. {559702800 7200 0 EET}.. {575427600 10800 1 EEST}.. {591152400 7200 0 EET}.. {606877200 10800 1 EEST}.. {622602000 7200 0 EET}.. {638326800 10800 1 EEST}.. {654656400 7200 0 EET}.. {670381200 10800 1 EEST}.. {686106000 7200 0 EET}.. {701830800 10800 1 E
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):111
                                                                                                                                                                                                            Entropy (8bit):4.924838898127838
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yLbNMXGm2OHLVva0v:SlSWB9eg/ylDm2OHLVi0v
                                                                                                                                                                                                            MD5:B221E7141FFC9DEA317F64F81C7BB4E0
                                                                                                                                                                                                            SHA1:B13BBDE790B169D8B9075275523F319D5173E2C7
                                                                                                                                                                                                            SHA-256:6344BE02529C1CC5F7B5FE14B7E9BBCED4DDE68A24B824601EEBCAE207ABFDF2
                                                                                                                                                                                                            SHA-512:FFFA733476D6C7DCF49C0B88C9F5E381DE2B69BAEDF6C7B1D91C6F45CE2D36E06D40F25B6BB65D4B5D650471BB52CD2EC3F68703DAB4BD5414F8D3F831D92BD2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:EST) {.. {-9223372036854775808 -18000 0 EST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8505
                                                                                                                                                                                                            Entropy (8bit):3.8091719283634853
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:R+kNoStCt/cL1BRP0HY2iU7KKdFL6Aa2K4gSLf8e:RXoSItON0HY2iUmUFLqU
                                                                                                                                                                                                            MD5:4578FE48781599B55F4BCF5560019789
                                                                                                                                                                                                            SHA1:4EAA7134621DFDEBFD1405F5CC58227FA7E80C3A
                                                                                                                                                                                                            SHA-256:0BE6161403BC5A96BFAB174F2C3FCBA8A677D4349699B408E9872B9DD0FE15CE
                                                                                                                                                                                                            SHA-512:9ACC2EF396F635D22E3DF6B785831AD74B510049F1BE85F996467A5BBC0DF49A28B2FC3E4CA0CA9DC8FC2C29EA50D909F0B153265B107445D3052E81D9A4D50A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:EST5EDT) {.. {-9223372036854775808 -18000 0 EST}.. {-1633280400 -14400 1 EDT}.. {-1615140000 -18000 0 EST}.. {-1601830800 -14400 1 EDT}.. {-1583690400 -18000 0 EST}.. {-880218000 -14400 1 EWT}.. {-769395600 -14400 1 EPT}.. {-765396000 -18000 0 EST}.. {-84387600 -14400 1 EDT}.. {-68666400 -18000 0 EST}.. {-52938000 -14400 1 EDT}.. {-37216800 -18000 0 EST}.. {-21488400 -14400 1 EDT}.. {-5767200 -18000 0 EST}.. {9961200 -14400 1 EDT}.. {25682400 -18000 0 EST}.. {41410800 -14400 1 EDT}.. {57736800 -18000 0 EST}.. {73465200 -14400 1 EDT}.. {89186400 -18000 0 EST}.. {104914800 -14400 1 EDT}.. {120636000 -18000 0 EST}.. {126687600 -14400 1 EDT}.. {152085600 -18000 0 EST}.. {162370800 -14400 1 EDT}.. {183535200 -18000 0 EST}.. {199263600 -14400 1 EDT}.. {215589600 -18000 0 EST}.. {230713200 -14400 1 EDT}.. {247039200 -18000 0 EST}.. {262767600
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):170
                                                                                                                                                                                                            Entropy (8bit):4.862365884559795
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsPHV5XHAIgNGE7TRRL/yCh0DcPHy:SlSWB9vsM3y7fHAIgNTRN/yg0DH
                                                                                                                                                                                                            MD5:ACD69F34396296BA553243267D06CEE0
                                                                                                                                                                                                            SHA1:9575FFE5E7833B9532F17AC5413EA9DB23F07ECA
                                                                                                                                                                                                            SHA-256:936B6484469351DEF8FAFE8EC180862729F5E43BDE4E53E2E9636E221B54C3C2
                                                                                                                                                                                                            SHA-512:149D23FF35747127E9A2F4056D09472E8E689970BC795D5411C5BF621D949ADDEBDA68674D375A248A63106ABDFF6C54A8AFE5385C45BE2916CAED0C30F7C4A1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Cairo)]} {.. LoadTimeZoneFile Africa/Cairo..}..set TZData(:Egypt) $TZData(:Africa/Cairo)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):172
                                                                                                                                                                                                            Entropy (8bit):4.901791318009318
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV5QH+o3vXHAIgoq6QHFRRL/yMQs/h8QanQHuv:SlSWB9vsM3ymnQeoPHAIgonQzN/yM/hm
                                                                                                                                                                                                            MD5:E9C2C97EB65526F1D4BE1AD7385336FA
                                                                                                                                                                                                            SHA1:09E4000CE320F779E2DFCA2FFD6B9258FFBA6CE4
                                                                                                                                                                                                            SHA-256:B78A833337EFEC8B5F64622F1BFDA21FCB79CF290E9CF32A54B206EB20C6FDE9
                                                                                                                                                                                                            SHA-512:EAEC097B58BF466CC7D6C0C6297628AF910CC308AC822565FD6CDABF96CD4EC57D4CC724FE782B6C1B606DFF9424013F6A890A871339577F7CB68BBB3C425E65
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Dublin)]} {.. LoadTimeZoneFile Europe/Dublin..}..set TZData(:Eire) $TZData(:Europe/Dublin)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):110
                                                                                                                                                                                                            Entropy (8bit):4.928744204623185
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDMbNMXGm2OHvDwy:SlSWB9eg/yRQJDm2OHsy
                                                                                                                                                                                                            MD5:9C08898081382F52CE681B592B8E2C8D
                                                                                                                                                                                                            SHA1:165944424740B1FA9B4B3B8E622198ABD0BDA0F8
                                                                                                                                                                                                            SHA-256:66B0DF8888883BFF44B18728B48CDF24AAED0BB745D601F3422C4F2D4063E0AC
                                                                                                                                                                                                            SHA-512:86EA639F999169F2FBA2457BE5042463A1938031268CCA71FDD03CCBC6194932937BA58B49FBED461E055E9AA668FF6EBF391AA7EC603C0A425416DF2E6CC84D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT) {.. {-9223372036854775808 0 0 GMT}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):159
                                                                                                                                                                                                            Entropy (8bit):4.910789466104329
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqSsM4DovXHAIgexovYovHRL/yRDOm7/8RDMovn:SlSWB9vsM3yFXHAIgnvVHN/yRSw8RQy
                                                                                                                                                                                                            MD5:333F2BFA92742A49BB88F11C7CD896A9
                                                                                                                                                                                                            SHA1:BB5BEC010C36427AEEBDDA2FB72083E22A3F5073
                                                                                                                                                                                                            SHA-256:64466EA3759301E88C29AD1A833CDCBBC495EB4A5A3AC45E7B2987FECD6702BD
                                                                                                                                                                                                            SHA-512:E2270F4B57C5F1C849726259B886E8644DCF497FA0D034AD48885146BEDC70DC8899900DA9AC01F2609A2DA881E10F9042CCBF75A3F5DA7344D7E92F1B070806
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:Etc/GMT+0) $TZData(:Etc/GMT)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):116
                                                                                                                                                                                                            Entropy (8bit):4.980500771169276
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDOveyXMXGm2OH1VOwVn:SlSWB9eg/yRSvPDm2OH1VOwV
                                                                                                                                                                                                            MD5:A7C3FD06D1E06F125813C9687C42067C
                                                                                                                                                                                                            SHA1:515622C0B63E977AFBFC78AD8466053C4A4A71A6
                                                                                                                                                                                                            SHA-256:3BE1EC71D2CC88FA9A3DB7DC0476475F33FE5BCBE6BC35C0F083859766466C32
                                                                                                                                                                                                            SHA-512:548DA608CFCA5B8539652F94CA2040D624602D2DF64B2C8CCDB8B219B9B384E01386CDF95F3BF77409DF0584FA12A3B73D56D13107D98BEB4C2555F458B3F374
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+1) {.. {-9223372036854775808 -3600 0 -01}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):118
                                                                                                                                                                                                            Entropy (8bit):4.965033464829338
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDOPFNMXGm2OH1VYU7vV:SlSWB9eg/yRSPXDm2OH1VYW9
                                                                                                                                                                                                            MD5:FF71149E56D4CB553D0ED949B5F4C122
                                                                                                                                                                                                            SHA1:3459B47E0EEC80D7A29512CA4F3F236C89E86573
                                                                                                                                                                                                            SHA-256:E61E826E6FBC2396EF152640698098F4477D4FFDFE5F791F62250C3EC5865304
                                                                                                                                                                                                            SHA-512:43B0CC8BD7F1EFC80C3F14F115D651EADD5743B17B854C2FB7AC25995138D3DF8792915C2952B80F35784A7115F8FB335ACE171479B24C668190AC175523DB21
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+10) {.. {-9223372036854775808 -36000 0 -10}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):118
                                                                                                                                                                                                            Entropy (8bit):5.002239901486653
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDOeJMXGm2OHaBByVn:SlSWB9eg/yRSsDm2OHa7yV
                                                                                                                                                                                                            MD5:08AABA917A8D6B3BB3D0DD1637F5ABFC
                                                                                                                                                                                                            SHA1:D1D704F0250D4CBD450922A02D021E0000FBF5CF
                                                                                                                                                                                                            SHA-256:143528946275DDC8B894218D3F1BE56C950F740828CEC13166C3D7E8E1B6BB7E
                                                                                                                                                                                                            SHA-512:F37AE54864A613C830308CB94AB7CEA9534A86A53B52B4A2C28CEEFE6F5BC0518143AAFD77A6DA5EC55D392F5BD34FCD4B5BE51794B1A386ED783B9BA89C10C3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+11) {.. {-9223372036854775808 -39600 0 -11}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):118
                                                                                                                                                                                                            Entropy (8bit):4.97889339723103
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDONdNMXGm2OH3FNyUFFv:SlSWB9eg/yRSNDm2OH3XyMv
                                                                                                                                                                                                            MD5:7374B66D6E883D7581E9561C3815EB92
                                                                                                                                                                                                            SHA1:235E96A7420DF6733F3CA368D4A2D57766656043
                                                                                                                                                                                                            SHA-256:A93EAFAC2C1089C608C8536127D0E8B53D8C7CFD13AE7DD69339E12A89F803C6
                                                                                                                                                                                                            SHA-512:9BA59B17F20D65DFF1A5A2D557B535F69B04C172AECB15F88CA3484D74CC7D53894985C08653CF13D868BCBD5E7E5041E0CB2F457B5B603F3851198E552E33A7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+12) {.. {-9223372036854775808 -43200 0 -12}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):116
                                                                                                                                                                                                            Entropy (8bit):4.922268982357521
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDOcF3vFNMXGm2OHnFQVIyV:SlSWB9eg/yRS0fXDm2OHnFQVb
                                                                                                                                                                                                            MD5:FDDC663E40F8FFFE27959E94625725DF
                                                                                                                                                                                                            SHA1:EE3FBC1F6C8BBCF1BDC9E5DB4D2EA1A57E2E9BB3
                                                                                                                                                                                                            SHA-256:AD5833153446960BDE0653A22AE2111BF80CFD61C3010993CE87B81D40C75C72
                                                                                                                                                                                                            SHA-512:A1B2A153834FEAD7DC27C0918E1B1CB905671F82850C1CAAEBD89F5535703FB259F02F699EA7F82F3044E37668EE93DFA4D4EB862CD437AFF0DABA84867B1963
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+2) {.. {-9223372036854775808 -7200 0 -02}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):117
                                                                                                                                                                                                            Entropy (8bit):4.949132511023475
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDOFfMXGm2OHBFVGAvFv:SlSWB9eg/yRSlDm2OHBFAKV
                                                                                                                                                                                                            MD5:5C6F16F2CFD46030688066F9BFBE675D
                                                                                                                                                                                                            SHA1:1DB5F36584822EB92E75B9AC9F440FD671BD90AE
                                                                                                                                                                                                            SHA-256:C7BEE4C71905EDDB40BAF42C0CD0DC70BB9F298EAAB8B9367D484B8431DD084A
                                                                                                                                                                                                            SHA-512:FFB2C4CD8EA7DE165C3D989454898FF2023D1A1E3B2B34EC23B1B71EFA7BF2538488DA0069E59F1152B8933D2263B762D2D7C56ADBED826C33FC0BA6672E34DB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+3) {.. {-9223372036854775808 -10800 0 -03}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):117
                                                                                                                                                                                                            Entropy (8bit):4.971627677226461
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDOqJMXGm2OHBvGQy:SlSWB9eg/yRSQDm2OHBON
                                                                                                                                                                                                            MD5:E35244C1A6084C7BC1D79E437677C55C
                                                                                                                                                                                                            SHA1:898619DA4B8B9AC72E69C7BD30DEA2ADEF9440FE
                                                                                                                                                                                                            SHA-256:26D1EF512CC5797FC63BA2B83C7D6271025F4D4F5C904D9FA8E97F053393D9A7
                                                                                                                                                                                                            SHA-512:0687758558C4C5FF7802F3A57212694A1515761A8337D4B75FFE81434D2AD8A221B005DEC36BF013F2FC3DE1E46DFBED36352811EB7C5A5AE3A167A2E314F57C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+4) {.. {-9223372036854775808 -14400 0 -04}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):117
                                                                                                                                                                                                            Entropy (8bit):4.956438091983076
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDOJNMXGm2OHLVvyV6Aov:SlSWB9eg/yRSDDm2OHLVKVg
                                                                                                                                                                                                            MD5:7C560A0F3C42E399AC1247CB6C516DC6
                                                                                                                                                                                                            SHA1:C314B09D4E369C69C23A8DC1FB066FD0CFDC7211
                                                                                                                                                                                                            SHA-256:054910BDDFC44D9B806BBD3008C30547FA57ECD3C043418C406A725158144688
                                                                                                                                                                                                            SHA-512:FCE8431B759BD5359847734FD98D9D91394916235B2AF587FC927D5F3196FB283E241A6A9200EA852F9265ECEF81402FF6ACD0FA3A4AAEF6DF9DB1B056B3A9EF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+5) {.. {-9223372036854775808 -18000 0 -05}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):117
                                                                                                                                                                                                            Entropy (8bit):4.974743300958087
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDOAkSMXGm2OHvTmULyn:SlSWB9eg/yRSbSDm2OHviX
                                                                                                                                                                                                            MD5:EEB1A3E0FD3339E332587D19C116D4EF
                                                                                                                                                                                                            SHA1:5DBF046031CD354B1EF88E46D3FED74706D21AC6
                                                                                                                                                                                                            SHA-256:D53BB247E0E429A6243AB9A9BDCAE1EE1CF5F271D79748A843631906AB63A988
                                                                                                                                                                                                            SHA-512:07BDF9056DC335C773684E634B1D389FBD139464D4597DE862B7EAC096676A093934682BF911F4E68F299789931218C0E431F0CC6BEBD7275B5FC8015EDD0942
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+6) {.. {-9223372036854775808 -21600 0 -06}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):117
                                                                                                                                                                                                            Entropy (8bit):4.930134062078826
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDONeyFNMXGm2OHrXVYVny:SlSWB9eg/yRSNPDm2OHriVy
                                                                                                                                                                                                            MD5:F92B31548D6BF8CCFA326C0CA6E205A0
                                                                                                                                                                                                            SHA1:3FFC6C214EDBCBE9C2509306CE73B429113E1C8A
                                                                                                                                                                                                            SHA-256:6BA5779E35D581B409F53B14B6E28ECC16F536FFEDD45DDBC8DAE4B8C28F66E7
                                                                                                                                                                                                            SHA-512:317872E986099D02AF083397AE936854043D54CEBF45A70672F02DDC9E2F3B27BC3FA80902F9675131C51A09BBD3C2BD1CD437330935CEA113C643769E0DF20C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+7) {.. {-9223372036854775808 -25200 0 -07}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):117
                                                                                                                                                                                                            Entropy (8bit):4.915798027862021
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDOOF3vXMXGm2OHmFvGpn:SlSWB9eg/yRSqfXDm2OHaOp
                                                                                                                                                                                                            MD5:B31B15E6006F8DF0D7627D6C90FF39AF
                                                                                                                                                                                                            SHA1:7C4137BE11DA84771DF6DC5EBC32D5E5E87E060F
                                                                                                                                                                                                            SHA-256:CA87559B154B165E83482AEE3D753BA8E38ABCA347A005E8504C566433CF4CB3
                                                                                                                                                                                                            SHA-512:220F7E7379EABBC8ACD7ADBB7A4AC8E93E4B268F8F1C0965B7E6A09735EE86E293EF1C492990331EEB4176B8301A91EC20579756B962AE45C858A96C09349CCD
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+8) {.. {-9223372036854775808 -28800 0 -08}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):117
                                                                                                                                                                                                            Entropy (8bit):4.95764928386407
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDO3fMXGm2OHNms:SlSWB9eg/yRSPDm2OHNms
                                                                                                                                                                                                            MD5:5B10173EB7119F1219250763504A3526
                                                                                                                                                                                                            SHA1:A845021437C4638079040EF27AEF163C865FF8F8
                                                                                                                                                                                                            SHA-256:A0987A1D078B0993FB3B07208E3F4538A2319DCDDDEB2FAEA32FC463DEAFB8DB
                                                                                                                                                                                                            SHA-512:D213285D0A723B7771263122AFA269C2ABD0325A97D32C3870341255C06597DD6851C22860CFF42BF54E3FF5A36FC88C306F3BF1C69E7BD7FD7F69FE7601ED1A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT+9) {.. {-9223372036854775808 -32400 0 -09}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):159
                                                                                                                                                                                                            Entropy (8bit):4.898210849752128
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqSsM4DovXHAIgexovYovHRL/yRDIyHp8RDMovn:SlSWB9vsM3yFXHAIgnvVHN/yRUyJ8RQy
                                                                                                                                                                                                            MD5:5AFB7F12BA056619252D48904523DFA9
                                                                                                                                                                                                            SHA1:CD6E6681C8302BF38095975DF556BD14959FDAC8
                                                                                                                                                                                                            SHA-256:EFF27B3DEE9306641FF344801E06BB33FF768CDCCFE2409FA8AF752FF6D39F66
                                                                                                                                                                                                            SHA-512:2869BB347F42667A3D174816466B15916FC61FCB5A6A1BE1DD750C5C1751602FEE0FE5A27651B7A19C9F6764872DD0F00D3D5AA16CA1A743DBA09646D25A4EB2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:Etc/GMT-0) $TZData(:Etc/GMT)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):115
                                                                                                                                                                                                            Entropy (8bit):4.979902281541545
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDI/fMXGm2OHMKUrn:SlSWB9eg/yRUXDm2OHtUr
                                                                                                                                                                                                            MD5:4000096844091488200125FC8F50E2F5
                                                                                                                                                                                                            SHA1:9FFEAE66405CFB254180C7DBE185288791DFEE5F
                                                                                                                                                                                                            SHA-256:B4BF883FBE9246EF4079179A746B1F9E59F2C77D4F598794B60732D198DC6044
                                                                                                                                                                                                            SHA-512:25C69E04018C2978A2E5748F0D3C61157453D998C16FA4B3C257A6515B87F5FD2B754893B47604BBC60AB60B60BA162BF2D1463E616E72CB8713C736F1B4D428
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-1) {.. {-9223372036854775808 3600 0 +01}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):117
                                                                                                                                                                                                            Entropy (8bit):4.964101313797091
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDINFeyFNMXGm2OHMUUMy:SlSWB9eg/yRUN5XDm2OHXFy
                                                                                                                                                                                                            MD5:AE6601FACF6BE1E68083F8D353901181
                                                                                                                                                                                                            SHA1:8B3BFA307D2A94BADD3A1A5E42545D6F7C620BCE
                                                                                                                                                                                                            SHA-256:EF3046D7789CAE069B5473D053F3EF0157248F8A359A1282EE02BA613A75FC94
                                                                                                                                                                                                            SHA-512:1859E6A2CB94EFEE7CD5C17803AA4F2DEEBE4DCF43D3B1EA737DF00BA86ECEC79D296D75E69D5829DECB48380B6B650724104FFA7959FD18FE032DF7D002A88B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-10) {.. {-9223372036854775808 36000 0 +10}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):117
                                                                                                                                                                                                            Entropy (8bit):5.00162575418652
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDIVSMXGm2OHlVVtyn:SlSWB9eg/yRUVSDm2OHlVLy
                                                                                                                                                                                                            MD5:D864BA451C9E441BF47D233626C57B99
                                                                                                                                                                                                            SHA1:6C38E6F8BA292575C496124572D187F97C9F8E73
                                                                                                                                                                                                            SHA-256:CCDEADBD18BE81E59A669A460A14AFCBFF733C3A5D164FC2B6B93DEAF009B78A
                                                                                                                                                                                                            SHA-512:5C16BD1189F3FE6789CB3630C841FD168EC87D0498EE6FCC4C8D635F8CF4BCAF0558B44F859C37E418F6BC5A7F6693D6EF1DD218A1DB6DA2D54FF55916685119
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-11) {.. {-9223372036854775808 39600 0 +11}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):117
                                                                                                                                                                                                            Entropy (8bit):4.978079707159482
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDIjbNMXGm2OHwvv0UIoAov:SlSWB9eg/yRUjJDm2OHwvv0YAov
                                                                                                                                                                                                            MD5:C3E7748C7CB9D8A7F7FA5170D5098983
                                                                                                                                                                                                            SHA1:54F5374A32173BEC6EDA430745DCD18749ABC233
                                                                                                                                                                                                            SHA-256:23B61B18C653E25F7245B0BB6E04AD347E038585B145962FD1EEACE26F118D54
                                                                                                                                                                                                            SHA-512:4783A7CD4C94CCC67C1C71F9C5D9CD99A3918EA4792D8CE2443ACE8F034B9023EBC02405B5DEAB919AA35FD1FD29D8980774316AC96D32ECDEBEFA15BBE6878D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-12) {.. {-9223372036854775808 43200 0 +12}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):117
                                                                                                                                                                                                            Entropy (8bit):4.994320173226919
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDIaMXGm2OH1dNv7Dy:SlSWB9eg/yRUaDm2OHty
                                                                                                                                                                                                            MD5:224AAAA8A31C283F50149A090E3970D5
                                                                                                                                                                                                            SHA1:E7E4876EC2474FEFD82D4B174CA8E3A3427062F5
                                                                                                                                                                                                            SHA-256:A9F1AD5A7CB5ED43C5E6E8A7A9B887329890ABB75B9FC9483B8543A367457EBE
                                                                                                                                                                                                            SHA-512:6EE0C6F519AAB2DAA3F7D802F0F838BA9F6BF1D56530000D3C9EA4FDA81DCB9832A3285E36208F29EEB23C27EC5BFD3438DC272929A7531268B7C0626A65D6A5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-13) {.. {-9223372036854775808 46800 0 +13}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):117
                                                                                                                                                                                                            Entropy (8bit):4.9895752453470585
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDIxhfMXGm2OH0FVtXvFv:SlSWB9eg/yRUxJDm2OH8jNv
                                                                                                                                                                                                            MD5:8ADF71739DCADE63433B7BF8321EAC77
                                                                                                                                                                                                            SHA1:AA6BDE83FF0D8BCFDE0426160250F2D17D3AF81D
                                                                                                                                                                                                            SHA-256:A37A7160027BD38356764C4D1AA5B9B17F8D5DC3CFB81EF2ED399E44C41734CE
                                                                                                                                                                                                            SHA-512:AEE3929DE269ADB5265A54841F041E41595359C101539F6309A4E737E3F5DF0BC91560781C7118975398C29A084113682C78F66E07E2E4AC5EAC8DFC33C4F0ED
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-14) {.. {-9223372036854775808 50400 0 +14}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):115
                                                                                                                                                                                                            Entropy (8bit):4.921164129348819
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDInWNMXGm2OH/VXF9:SlSWB9eg/yRUnSDm2OH/Vb
                                                                                                                                                                                                            MD5:CABB864F4E76B90928F5C54CD9334DEB
                                                                                                                                                                                                            SHA1:4818D47F83F16B9F7612D1E979B2440C170ECDB9
                                                                                                                                                                                                            SHA-256:7211BF8329B2388563ED8FA8C5140099A171B8A303A9473E9A6F3AF0C5D239CB
                                                                                                                                                                                                            SHA-512:1FDCB05D675F1D28CB52B9F5EAC7EC52FDF2CE7E7411740A6F8FB5E9D443ED636CE268E3AF9E08605CC3E13A49B2D86FF4EA6A85F518D5C79E263BA94263361D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-2) {.. {-9223372036854775808 7200 0 +02}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):116
                                                                                                                                                                                                            Entropy (8bit):4.948161547682094
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDIYyXMXGm2OHkNsWYcv:SlSWB9eg/yRUlDm2OHkKWYe
                                                                                                                                                                                                            MD5:4AE5F29A13A86E4A7064E9200668E43B
                                                                                                                                                                                                            SHA1:2460BD1BB0FF3A3C774A5C7CC3DA10235DA06B0D
                                                                                                                                                                                                            SHA-256:BFC86D65B0B94725DCE4C88EDC4300141ABBCA4B6CDECF037C437DF49F0C1D6A
                                                                                                                                                                                                            SHA-512:190DC38B4A20F964C967866507086317D85D979DFCFA415D1569C485C6476024922BC6E7103273C41889D9D7B22E97933F286FCF4D341248077C1BA777D0EE3B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-3) {.. {-9223372036854775808 10800 0 +03}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):116
                                                                                                                                                                                                            Entropy (8bit):4.970850637731657
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDIQXMXGm2OHkVsRYovV:SlSWB9eg/yRUQXDm2OHkSN
                                                                                                                                                                                                            MD5:BBAF760E27C02D176A675AC3CF2D1E6D
                                                                                                                                                                                                            SHA1:E524FAA7D424A1C1545D1D8EC00169125A68E8E5
                                                                                                                                                                                                            SHA-256:02E2EEAF88EE179EF63DD29ACC7384A4B46DE1E3A151C1F3A5DD31BBB5A05AEE
                                                                                                                                                                                                            SHA-512:6AC7CC0E52E7793C7F2D3DDA9551709DEAE654C1182EAD7108D04F1BAAAB7E1C473B6E8A3A126B0E421D8A246294A03B2EE9E070330924502DF2869CC61C37F7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-4) {.. {-9223372036854775808 14400 0 +04}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):116
                                                                                                                                                                                                            Entropy (8bit):4.955530107787899
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDI7tNMXGm2OHM0VQVFv:SlSWB9eg/yRU7PDm2OHnVQVV
                                                                                                                                                                                                            MD5:17F64A5969D3755211E60C0A9F83974F
                                                                                                                                                                                                            SHA1:FEFA84725EFAE6405F43797296C342B974F2D272
                                                                                                                                                                                                            SHA-256:3A2C75DCA11D1167126F0D44A8682420FAF75B0B82B3DCFC35A9F028A9A759E8
                                                                                                                                                                                                            SHA-512:77DBCD8284A470E4869976E2E8A5EDE28104283F120C863785A6B2E64CF87E06243196817C0055A9B32D6FFFE94A25772F67D58BF8E885F7EC06C34FABE38766
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-5) {.. {-9223372036854775808 18000 0 +05}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):116
                                                                                                                                                                                                            Entropy (8bit):4.973993120288556
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDIg3fMXGm2OHETNSTVVn:SlSWB9eg/yRUgPDm2OHETMX
                                                                                                                                                                                                            MD5:51CAF7956E133C8A9788AE0B8C6145AB
                                                                                                                                                                                                            SHA1:47F8B49DF9ED477BD95F908693A483AE4FDE881F
                                                                                                                                                                                                            SHA-256:D22C87321373EC0EFB0F312925476CD0747323EF303E17621A871BF814C8ABB1
                                                                                                                                                                                                            SHA-512:EC4B4BE74C1BA64DEC8EF11DAAA338C52BD67D55E8A2352FBC6C83FA142F8DBE424CC1110E9A9D9A891E1E858D1FFA6D1E3B997D41BBB374556FA1F9A708559E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-6) {.. {-9223372036854775808 21600 0 +06}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):116
                                                                                                                                                                                                            Entropy (8bit):4.928999319005163
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDIpdNMXGm2OHAXUVSYovV:SlSWB9eg/yRURDm2OHAXUVSYyV
                                                                                                                                                                                                            MD5:56D88B54CA33B43E2E7D3EA6AD3A4D6E
                                                                                                                                                                                                            SHA1:9351E0C001C5D83325281AF54363D76D65548B7D
                                                                                                                                                                                                            SHA-256:70CB3A766A2E84148B68613D68687D263D3592ED4B6E672797FB20801ECA8231
                                                                                                                                                                                                            SHA-512:32B58AD16F64590903C7AB49BA4890DAF6F1F3D33187A7654D3DA88A1C0047483EAA58B2498D824A30116E235FCC8F8FB3FADD57F86396240E5D92B2CA337027
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-7) {.. {-9223372036854775808 25200 0 +07}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):116
                                                                                                                                                                                                            Entropy (8bit):4.9145396982864895
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDIlSMXGm2OHN/VsdYLyn:SlSWB9eg/yRUlSDm2OHUp
                                                                                                                                                                                                            MD5:E462AD5E0C046EA6769EDB4B2C80F4D4
                                                                                                                                                                                                            SHA1:6DDB94485648622875E0927BA1E8CFE67CEC1382
                                                                                                                                                                                                            SHA-256:80C85D59416CEC91DB3DAC5FDD2FD7B91D6FC74A37BBBEF6FF58F6F6816E8FC9
                                                                                                                                                                                                            SHA-512:42734FD2DA8BD6E0BC271FF1375A31DEB72EED85AB5EA6E1E0F81EE4E3E7E74380FFC98FAC30409684F736DB580AAAF4F62DB4757AA35C10383584F6144EF363
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-8) {.. {-9223372036854775808 28800 0 +08}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):116
                                                                                                                                                                                                            Entropy (8bit):4.956751740978211
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRDIeyXMXGm2OHENScFAy:SlSWB9eg/yRUPDm2OHsScr
                                                                                                                                                                                                            MD5:98F70EC1B1AC7D38CB8D01705FB0CA56
                                                                                                                                                                                                            SHA1:EDAFA132E48935ACEB8E72D3FF463E4FC857C1A9
                                                                                                                                                                                                            SHA-256:57395BB968AFA5A041EADA4B684B82F0379A9333F9522D69F069A79FDEA2B8D7
                                                                                                                                                                                                            SHA-512:97B8D7603D6B54C075B005B905B2A7A28B8BEA67894F055663C44D2BF730BB937AC8EF5B2DF182BDD2D9EFFDBD135DF9467C813AEE39AA6B34256908A12DC011
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/GMT-9) {.. {-9223372036854775808 32400 0 +09}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):158
                                                                                                                                                                                                            Entropy (8bit):4.886484135647838
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqSsM4DovXHAIgexovYovHRL/yRDVMFHp8RDMovn:SlSWB9vsM3yFXHAIgnvVHN/yRC1p8RQy
                                                                                                                                                                                                            MD5:F879FB24EA976394B8F4FAF1A9BF268C
                                                                                                                                                                                                            SHA1:903714237EBD395A27EAF00B3DAAA89131267EE5
                                                                                                                                                                                                            SHA-256:AB742F93BE44BD68AB8FE84505FA28120F1808765D9BAED32A3490AF7C83D35B
                                                                                                                                                                                                            SHA-512:F5EE4C331E37036516F2A1BF12F2E088B2E2C7F6475127BF4E7B4937F864550D64D570BC855B6058D4311755E8696EC42095A36AEF13BB29E62192EE0AFB6EAF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:Etc/GMT0) $TZData(:Etc/GMT)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):163
                                                                                                                                                                                                            Entropy (8bit):4.911342539638601
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqSsM4DovXHAIgexovYovHRL/yRp+FB5yRDMovn:SlSWB9vsM3yFXHAIgnvVHN/yRp6BURQy
                                                                                                                                                                                                            MD5:CDD2DE9CF0FECFEA0CDD32DAC32DCDE2
                                                                                                                                                                                                            SHA1:311CD4C6E819E18BAAACC382F81359BC208E2F73
                                                                                                                                                                                                            SHA-256:F89167B6117838D9679C0397496B6D96D3A7BEAEF0BD99406ABACDBDB658FBCC
                                                                                                                                                                                                            SHA-512:1AF061D07D2F579A089905B6B259AABD7C58F4FA0CD379EE54206164F0DCAEA5C720FB1F5E76F5782F8613E62D8F83BD55F1848D5D7A73D4A5C9F7BC6B9F5DB1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:Etc/Greenwich) $TZData(:Etc/GMT)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):157
                                                                                                                                                                                                            Entropy (8bit):4.838936002050477
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqAxmS3vXHAIgELyHRL/yRKh8RFB:SlSWB9vsM3yzTHAIgm6N/yR68RX
                                                                                                                                                                                                            MD5:0587EB7D1B1C684A4A0F90D3CB0959C8
                                                                                                                                                                                                            SHA1:3F2840AE512774494D9A0B6357C52CCB7DBA5265
                                                                                                                                                                                                            SHA-256:0856D14DBBC53D46460BCD530BD070E9E8966D1C96BA01BA556E215A98C09CD4
                                                                                                                                                                                                            SHA-512:DE38EF28893853219AC24AE4A522307ADAA1502F6D0C129219FAD9D75CFCE03A505C3E0758CFF2D2D4F7101414A5F7E4FC1C1B119B667E6A9C89B60DDA641E86
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:Etc/UCT) $TZData(:Etc/UTC)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):110
                                                                                                                                                                                                            Entropy (8bit):4.903699772785336
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/yRF3yFNMXGm2OHvL:SlSWB9eg/yR9SDm2OHj
                                                                                                                                                                                                            MD5:3D3F94B6AC5FA232E509356C703D9177
                                                                                                                                                                                                            SHA1:502B8EE9D4A1EA75A91272181AC87B9B6ECE1F84
                                                                                                                                                                                                            SHA-256:4D74D9EC2397B1708FEF47806294B0BCA26679F3A63149AE24E4E0C641976970
                                                                                                                                                                                                            SHA-512:205A761A01C577F602236CB5C9938C834B7F3F9F681B94036B0A86101119893EF87D206D0C3F7737075ED833D4E35E374ACAE6605163E9C37B705D99BEBC928C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Etc/UTC) {.. {-9223372036854775808 0 0 UTC}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):163
                                                                                                                                                                                                            Entropy (8bit):4.874807282103623
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqAxmS3vXHAIgELyHRL/yRYzXDJMFfh8RFB:SlSWB9vsM3yzTHAIgm6N/yRY7VMr8RX
                                                                                                                                                                                                            MD5:65E28EFF342B625E79175793FD38F9FD
                                                                                                                                                                                                            SHA1:08B11474822E670DEAB8F0EA168BAED7D5E3DBE1
                                                                                                                                                                                                            SHA-256:A2B62C5914DE169A68A018A5B47C1253DBCA10A251862D17B0781ECFD19B6192
                                                                                                                                                                                                            SHA-512:79641D0E05F81BFB80034937D34E74B7483A790F33C1F9A0FA92C6A7913AC8C03036CFDEFB43850B84EFB3DD3C4A39022DC8F22E5B5DE6353586A546E03A5789
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:Etc/Universal) $TZData(:Etc/UTC)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):158
                                                                                                                                                                                                            Entropy (8bit):4.874356623237119
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqAxmS3vXHAIgELyHRL/yRaQEBURFB:SlSWB9vsM3yzTHAIgm6N/yRYaRX
                                                                                                                                                                                                            MD5:EDABCAC858EC9632D5D8DCCFB28F4D6E
                                                                                                                                                                                                            SHA1:E5BEF1367A97A1900749CE6B1E01CF32F582BDD9
                                                                                                                                                                                                            SHA-256:BBD6E93206FF3B7017AFBE63905B4C932C422B582F3CE2A79A7B885D390EE555
                                                                                                                                                                                                            SHA-512:3A22364D423F2F970123561408018A2B72F43C4978836D3B6DF7517217445605838DCB8DDBDA204FD01C49A4A7D5ADAD4CA8BDA7C3B412D54750BAEAA589B683
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:Etc/Zulu) $TZData(:Etc/UTC)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):190
                                                                                                                                                                                                            Entropy (8bit):4.892809684252761
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/So3vXHAIgoq82yHRL/yQaiFAXowQahCv:SlSWB9vsM3ymhS2HAIgoh26N/ywAXoww
                                                                                                                                                                                                            MD5:B0B409D665190569A56697799FBA5CD3
                                                                                                                                                                                                            SHA1:840AA7D61E64ACE61FDDAB96F716575A61CEDB52
                                                                                                                                                                                                            SHA-256:46141E7BC0F99D2117319C661569F8B38AF7D00108CED5784FA3A3B5090EF8E9
                                                                                                                                                                                                            SHA-512:D7C0588D98AC46B5191D7C7E8F5181E94306EFFCC9E3F2DBA9E0003BAE51D992334527ADDD6D0C9701CFD60169A74984B3401E7A6A1322A734BC3D90DCC933BC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Brussels)]} {.. LoadTimeZoneFile Europe/Brussels..}..set TZData(:Europe/Amsterdam) $TZData(:Europe/Brussels)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):6927
                                                                                                                                                                                                            Entropy (8bit):3.8182041031531897
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:CA34elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhltlUxOrnW+:CI41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                            MD5:D897DCA686A03495EB2C3323FAB0BEAD
                                                                                                                                                                                                            SHA1:1433BC303DE92F7B36F881C8595A42B35E0814FC
                                                                                                                                                                                                            SHA-256:F0B48DA7CA3659450D87CC0DDFDDFD28B464543DF1EE40D935C44D5CD7C9B9B3
                                                                                                                                                                                                            SHA-512:A1C4AE1E0EC26B159B0F5D058A7A77B8774F611A4D3C6AECEDD7186957D6BD9F15CDFCBA248FCC8A4B4146BD72CD7D66B9F88A2BF7CDEF416F1831A2F335D48C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Andorra) {.. {-9223372036854775808 364 0 LMT}.. {-2177453164 0 0 WET}.. {-733881600 3600 0 CET}.. {481078800 7200 0 CEST}.. {496803600 3600 0 CET}.. {512528400 7200 1 CEST}.. {528253200 3600 0 CET}.. {543978000 7200 1 CEST}.. {559702800 3600 0 CET}.. {575427600 7200 1 CEST}.. {591152400 3600 0 CET}.. {606877200 7200 1 CEST}.. {622602000 3600 0 CET}.. {638326800 7200 1 CEST}.. {654656400 3600 0 CET}.. {670381200 7200 1 CEST}.. {686106000 3600 0 CET}.. {701830800 7200 1 CEST}.. {717555600 3600 0 CET}.. {733280400 7200 1 CEST}.. {749005200 3600 0 CET}.. {764730000 7200 1 CEST}.. {780454800 3600 0 CET}.. {796179600 7200 1 CEST}.. {811904400 3600 0 CET}.. {828234000 7200 1 CEST}.. {846378000 3600 0 CET}.. {859683600 7200 1 CEST}.. {877827600 3600 0 CET}.. {891133200 7200 1 CEST}.. {909277200 3600 0 CET}.. {922582800 7200 1 CEST}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2063
                                                                                                                                                                                                            Entropy (8bit):3.679377249443024
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:TvCAs6kKR6aQmF1cSNWrI+AjXgV/Ap40FjDOP:rCAs6kC6aZF1cSN4I+AjXgV/ApDFjDM
                                                                                                                                                                                                            MD5:CB860328FA96A14055BF51A3B2D35A08
                                                                                                                                                                                                            SHA1:CFA49DC861F4AC3D29A78D63D71C2D6D83D68F84
                                                                                                                                                                                                            SHA-256:4B5FB0AF225974D117374028285F20A02B833FF4136E6BFAE7B65E6D6D28829E
                                                                                                                                                                                                            SHA-512:960152826F4245012462E53F80B69B0C45C27D75D46C70D485674CA19071DF268671C7691B614BE53B9E7BD8CFEC5D24F3DCF933F2F14D827F2A32EB347D7540
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Astrakhan) {.. {-9223372036854775808 11532 0 LMT}.. {-1441249932 10800 0 +03}.. {-1247540400 14400 0 +05}.. {354916800 18000 1 +05}.. {370724400 14400 0 +04}.. {386452800 18000 1 +05}.. {402260400 14400 0 +04}.. {417988800 18000 1 +05}.. {433796400 14400 0 +04}.. {449611200 18000 1 +05}.. {465343200 14400 0 +04}.. {481068000 18000 1 +05}.. {496792800 14400 0 +04}.. {512517600 18000 1 +05}.. {528242400 14400 0 +04}.. {543967200 18000 1 +05}.. {559692000 14400 0 +04}.. {575416800 18000 1 +05}.. {591141600 14400 0 +04}.. {606866400 10800 0 +04}.. {606870000 14400 1 +04}.. {622594800 10800 0 +03}.. {638319600 14400 1 +04}.. {654649200 10800 0 +03}.. {670374000 14400 0 +04}.. {701820000 10800 0 +04}.. {701823600 14400 1 +04}.. {717548400 10800 0 +03}.. {733273200 14400 1 +04}.. {748998000 10800 0 +03}.. {764722800 14400 1 +04}.. {7
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7954
                                                                                                                                                                                                            Entropy (8bit):3.7252594544513795
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:1D/8QdzFu+f+uO7DVopaNlKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYf:Z/8ohvyDjivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                            MD5:8B2C99E1CD04D7559709FDF8D382343C
                                                                                                                                                                                                            SHA1:C595D5159C742B815AF89EC8604376E01291F9F1
                                                                                                                                                                                                            SHA-256:47353319419505AAB205C23F8C97EA0B12E5DED2113147794F77B67349AFF52F
                                                                                                                                                                                                            SHA-512:227CA21A3B6160357988582E261A62AE7B09D46D479EABFAC8039185D710EFA765CD1694F4388EBF8800978A1E1DB69F6AF9BB9BF82C0FCD66E883930E1F8249
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Athens) {.. {-9223372036854775808 5692 0 LMT}.. {-2344642492 5692 0 AMT}.. {-1686101632 7200 0 EET}.. {-1182996000 10800 1 EEST}.. {-1178161200 7200 0 EET}.. {-906861600 10800 1 EEST}.. {-904878000 7200 0 CEST}.. {-857257200 3600 0 CET}.. {-844477200 7200 1 CEST}.. {-828237600 3600 0 CET}.. {-812422800 7200 0 EET}.. {-552362400 10800 1 EEST}.. {-541652400 7200 0 EET}.. {166485600 10800 1 EEST}.. {186184800 7200 0 EET}.. {198028800 10800 1 EEST}.. {213753600 7200 0 EET}.. {228873600 10800 1 EEST}.. {244080000 7200 0 EET}.. {260323200 10800 1 EEST}.. {275446800 7200 0 EET}.. {291798000 10800 1 EEST}.. {307407600 7200 0 EET}.. {323388000 10800 1 EEST}.. {338936400 7200 0 EET}.. {347148000 7200 0 EET}.. {354675600 10800 1 EEST}.. {370400400 7200 0 EET}.. {386125200 10800 1 EEST}.. {401850000 7200 0 EET}.. {417574800 10800 1 EEST}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):182
                                                                                                                                                                                                            Entropy (8bit):4.876296755647751
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVxKL823vXHAIgoqyKL8H6RL/yQahs3QavKL81n:SlSWB9vsM3ymvKA2PHAIgovKAH6N/y72
                                                                                                                                                                                                            MD5:7160C6EE32380846653F016AE8AFD52A
                                                                                                                                                                                                            SHA1:DE7805089639C54893F2107FA67342DA72A79BBC
                                                                                                                                                                                                            SHA-256:557023674F6E8376707517103EE69C1DEBBE53CDD4BCAB11E763CC53B9CB1908
                                                                                                                                                                                                            SHA-512:FDBDECBBDB0C419226E2604608FD2923CFB06E4B6948493208FD83FD796880E81F6147C0FAFEB572079C9C916831B7B055620EC939164CCA1DAF76897BE60F2C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/London)]} {.. LoadTimeZoneFile Europe/London..}..set TZData(:Europe/Belfast) $TZData(:Europe/London)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7309
                                                                                                                                                                                                            Entropy (8bit):3.8204712502914653
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:lp+/4elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhltlUxOrnW+:lY41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                            MD5:02A003411B61A311896A6407B622152A
                                                                                                                                                                                                            SHA1:3B8BC6D1AF698CE7BB14A08307F5A4295EB8ED03
                                                                                                                                                                                                            SHA-256:74B225511B518B0CED972CBB33D694697712CCB96A6D81E0F50ADA28CF6E2C92
                                                                                                                                                                                                            SHA-512:9E03B3EB1E528E5B1ADBA09F808E73BF9C4314EDCBF6F96E46844D51A5F425BED3EE8FD5BA8706C46A7FB9882485F119F81996F2EAB7E1E9B598978C402DDE0F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Belgrade) {.. {-9223372036854775808 4920 0 LMT}.. {-2713915320 3600 0 CET}.. {-905824800 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-788922000 3600 0 CET}.. {-777942000 7200 1 CEST}.. {-766623600 3600 0 CET}.. {407199600 3600 0 CET}.. {417574800 7200 1 CEST}.. {433299600 3600 0 CET}.. {449024400 7200 1 CEST}.. {465354000 3600 0 CET}.. {481078800 7200 1 CEST}.. {496803600 3600 0 CET}.. {512528400 7200 1 CEST}.. {528253200 3600 0 CET}.. {543978000 7200 1 CEST}.. {559702800 3600 0 CET}.. {575427600 7200 1 CEST}.. {591152400 3600 0 CET}.. {606877200 7200 1 CEST}.. {622602000 3600 0 CET}.. {638326800 7200 1 CEST}.. {654656400 3600 0 CET}.. {670381200 7200 1 CEST}.. {686106000 3600 0 CET}.. {701830800 7200 1 CEST}.. {717555600 360
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8020
                                                                                                                                                                                                            Entropy (8bit):3.820756136386754
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:Pi9+qFR274elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhltlUxo:PQs41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                            MD5:84027C3C8315BD479B38DE11F38E873F
                                                                                                                                                                                                            SHA1:6E92A2A9734A9C6B02ECCD99F114D667C909C5BA
                                                                                                                                                                                                            SHA-256:7E7111F06288069B52A4E1CA0B016216DF9328FB3B1560A740146497CCDD4D24
                                                                                                                                                                                                            SHA-512:5FFDE523021FC0C490261F55999204C9CE6C8C274888525EA6EE7C01BC5CCABC7A3877FD454B4167D81F4B89BACB087E8BA6AB0BAC46C2874ED9257BE2092340
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Berlin) {.. {-9223372036854775808 3208 0 LMT}.. {-2422054408 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-938905200 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-776559600 10800 0 CEMT}.. {-765936000 7200 1 CEST}.. {-761180400 3600 0 CET}.. {-757386000 3600 0 CET}.. {-748479600 7200 1 CEST}.. {-733273200 3600 0 CET}.. {-717631200 7200 1 CEST}.. {-714610800 10800 1 CEMT}.. {-710380800 7200 1 CEST}.. {-701910000 3600 0 CET}.. {-684975600 7200 1 CEST}.. {-670460400 3600 0 CET}.. {-654130800 7200 1 CEST}.. {-639010800 3600 0 CET}.. {315529200 3600 0 CET}.. {323830800 7200
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):185
                                                                                                                                                                                                            Entropy (8bit):4.943205109348136
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVtXrAeovXHAIgoquXrsY6RL/yQahcvEB5yQazXrH:SlSWB9vsM3ymzbAeSHAIgozbsY6N/y7c
                                                                                                                                                                                                            MD5:C69AB60BE74D4BB7E31BE4E5ECCD8FD2
                                                                                                                                                                                                            SHA1:9DD0BA6171080F074858EF88ADA2E91C1F465619
                                                                                                                                                                                                            SHA-256:1D7C539AAA1E3AD5EF3574A629523B5B781F1A91D352C9B39B8DE7316756026E
                                                                                                                                                                                                            SHA-512:C273B97CCFB5F328EB7A13CCA3126DE8D91B3876CBD248990C0BE063DDBE5B0F31EA138E31A1C5C43B1ABCF42EA511448E6DC589EB99E8172D7C2A68BA31A8E7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Prague)]} {.. LoadTimeZoneFile Europe/Prague..}..set TZData(:Europe/Bratislava) $TZData(:Europe/Prague)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):9223
                                                                                                                                                                                                            Entropy (8bit):3.8450929464870804
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:RhcSQnG1Czyc1+FdDKDBb0S274elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcM:Rh8zyc4Ss41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                            MD5:E6C1153C3F71C8C005D7A46DDF6461FB
                                                                                                                                                                                                            SHA1:CBDF7D5D36AF57D83859C910B493464617EC9571
                                                                                                                                                                                                            SHA-256:1402A2072ADC9EBB35F4C0368D2E9A7A11493626C667C022614FFB7CC05B6CB6
                                                                                                                                                                                                            SHA-512:8B1B47678F75DBE59DB08E034F0701BD11FF4FD3AD0304C8ABF45E848F717D2787B8E47558D3C334D369E0938C633DC217178D3EAE6486CEFBE25CF1668479F6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Brussels) {.. {-9223372036854775808 1050 0 LMT}.. {-2840141850 1050 0 BMT}.. {-2450995200 0 0 WET}.. {-1740355200 3600 0 CET}.. {-1693702800 7200 0 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-1613826000 0 0 WET}.. {-1604278800 3600 1 WEST}.. {-1585530000 0 0 WET}.. {-1574038800 3600 1 WEST}.. {-1552266000 0 0 WET}.. {-1539997200 3600 1 WEST}.. {-1520557200 0 0 WET}.. {-1507510800 3600 1 WEST}.. {-1490576400 0 0 WET}.. {-1473642000 3600 1 WEST}.. {-1459126800 0 0 WET}.. {-1444006800 3600 1 WEST}.. {-1427677200 0 0 WET}.. {-1411952400 3600 1 WEST}.. {-1396227600 0 0 WET}.. {-1379293200 3600 1 WEST}.. {-1364778000 0 0 WET}.. {-1348448400 3600 1 WEST}.. {-1333328400 0 0 WET}.. {-1316394000 3600 1 WEST}.. {-1301263200 0 0 WET}.. {
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7974
                                                                                                                                                                                                            Entropy (8bit):3.7264631277913853
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:vMSsQMAz5CXNU5paNlKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYjlBK0:vMS1kdUoivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                            MD5:88DB5686937D3499A8142413B2CF2EB5
                                                                                                                                                                                                            SHA1:E37BAD2127553600D0E38A43053D1B07B2498DA8
                                                                                                                                                                                                            SHA-256:C560D45104A8DD73FC7370B5AC1615E22043DBC93DFB46A9ECC6468C2D38B19A
                                                                                                                                                                                                            SHA-512:375B8A63CFF2E278CD8C78BF9DBC86288FFB1AD57DAED00CD2199F0B05F4FBFA7D17D93C6458B20B86F6D05F3E3A49D594E60AC97DDB47141E21D7CDE10F8456
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Bucharest) {.. {-9223372036854775808 6264 0 LMT}.. {-2469404664 6264 0 BMT}.. {-1213148664 7200 0 EET}.. {-1187056800 10800 1 EEST}.. {-1175479200 7200 0 EET}.. {-1159754400 10800 1 EEST}.. {-1144029600 7200 0 EET}.. {-1127700000 10800 1 EEST}.. {-1111975200 7200 0 EET}.. {-1096250400 10800 1 EEST}.. {-1080525600 7200 0 EET}.. {-1064800800 10800 1 EEST}.. {-1049076000 7200 0 EET}.. {-1033351200 10800 1 EEST}.. {-1017626400 7200 0 EET}.. {-1001901600 10800 1 EEST}.. {-986176800 7200 0 EET}.. {-970452000 10800 1 EEST}.. {-954727200 7200 0 EET}.. {296604000 10800 1 EEST}.. {307486800 7200 0 EET}.. {323816400 10800 1 EEST}.. {338940000 7200 0 EET}.. {354672000 10800 0 EEST}.. {370396800 7200 0 EET}.. {386121600 10800 1 EEST}.. {401846400 7200 0 EET}.. {417571200 10800 1 EEST}.. {433296000 7200 0 EET}.. {449020800 10800 1 EEST}.. {465
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8287
                                                                                                                                                                                                            Entropy (8bit):3.8244305880244567
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:rHw0+D5xp4elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhltlUxo:rQXj41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                            MD5:11468F958796F971ADD5FB1A0C426D78
                                                                                                                                                                                                            SHA1:3FA58BEF391BCF7BAC6A124D093B6505B4EAC452
                                                                                                                                                                                                            SHA-256:B58F3E9066B8B57EB037D509636AA67A06ACC8348BE6C48482D87CDC49844A4E
                                                                                                                                                                                                            SHA-512:0492EABD6EE16392C00A196AF38995E5F9E55E30A82A50EFFB381DC978E9E63E801555CDC219869E6251BD51115972F742D8A7D9524372B8B11702AE4B28BFB7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Budapest) {.. {-9223372036854775808 4580 0 LMT}.. {-2498260580 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1640998800 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-1600470000 7200 1 CEST}.. {-1587250800 3600 0 CET}.. {-1569711600 7200 1 CEST}.. {-1555196400 3600 0 CET}.. {-906775200 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-788922000 3600 0 CET}.. {-778471200 7200 1 CEST}.. {-762656400 3600 0 CET}.. {-749689200 7200 1 CEST}.. {-733276800 3600 0 CET}.. {-717634800 7200 1 CEST}.. {-701910000 3600 0 CET}.. {-686185200 7200 1 CEST}.. {-670460400 3600 0 CET}.. {-654130800 7200 1 CEST}.. {-639010800 3600 0 CET}.. {-492656400 7
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):183
                                                                                                                                                                                                            Entropy (8bit):4.952483060656419
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVnCMPfXHAIgoqkCM4ARL/yQahDZALMFB5h8Qa5CMS:SlSWB9vsM3ym5XPHAIgo5gAN/y7D17/f
                                                                                                                                                                                                            MD5:CED145F8D9B231234E021D2214C1064B
                                                                                                                                                                                                            SHA1:7B111DC24CA01C78A382CECD3247CF495D71CD34
                                                                                                                                                                                                            SHA-256:F511A80AB70FF93A0EB9F29293F73DF952B773BB33EB85D581E4FB1FE06E4F05
                                                                                                                                                                                                            SHA-512:E2323C04BF99909ABA9A09A66F9B4696519B5F9FE3AF178FB04D5E0053F41CAA8B937DC4148954ED093D317F454E0547786BEC934F2ABF22A60AAA6A24E63BF9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Zurich)]} {.. LoadTimeZoneFile Europe/Zurich..}..set TZData(:Europe/Busingen) $TZData(:Europe/Zurich)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8096
                                                                                                                                                                                                            Entropy (8bit):3.7635458172251406
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:jXSsijEpkv2XkN8qc/OyEie8hF5WQ9VX/Zs1cw27oXqdCA5XqjqFLigTE9s5VpJ:jXS+WeUqKie8hF5f9PwdXM9
                                                                                                                                                                                                            MD5:E7F52393523729CA3916768B3F3B4E55
                                                                                                                                                                                                            SHA1:1524A3E610DCD33AC0006946BAB2929CA7F5A33F
                                                                                                                                                                                                            SHA-256:2BD1C0AB412A5E9C97F533C4D06B773D045215B92568A4E89ADC93C7462D62EC
                                                                                                                                                                                                            SHA-512:218674ECD9FD6C1A1C83EE69AFE6AA5AD0D5A8BB59FF497FDF2573B7CF52DAE98ECE0815CF99668CA4E172FF67D220B227369865076333B3EE802A8839C65279
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Chisinau) {.. {-9223372036854775808 6920 0 LMT}.. {-2840147720 6900 0 CMT}.. {-1637114100 6264 0 BMT}.. {-1213148664 7200 0 EET}.. {-1187056800 10800 1 EEST}.. {-1175479200 7200 0 EET}.. {-1159754400 10800 1 EEST}.. {-1144029600 7200 0 EET}.. {-1127700000 10800 1 EEST}.. {-1111975200 7200 0 EET}.. {-1096250400 10800 1 EEST}.. {-1080525600 7200 0 EET}.. {-1064800800 10800 1 EEST}.. {-1049076000 7200 0 EET}.. {-1033351200 10800 1 EEST}.. {-1017626400 7200 0 EET}.. {-1001901600 10800 1 EEST}.. {-986176800 7200 0 EET}.. {-970452000 10800 1 EEST}.. {-954727200 7200 0 EET}.. {-927165600 10800 1 EEST}.. {-898138800 7200 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-800154000 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):185
                                                                                                                                                                                                            Entropy (8bit):4.925156646979837
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/y+YF3vXHAIgoq8yFRRL/yQagKVihh8Qahyuv:SlSWB9vsM3ymhVoPHAIgoh6N/yy87Fv
                                                                                                                                                                                                            MD5:3AEDE4B340D0250D496C49CADBA04E62
                                                                                                                                                                                                            SHA1:C466D8275C465752F5B024615268F6D1CBBA4B41
                                                                                                                                                                                                            SHA-256:2B9A0F1775355E311FB63903E3829F98B5F6C73C08F1BECE1A2D471ACC2673E3
                                                                                                                                                                                                            SHA-512:2B08B57D58699C65A9AAA43AC87F29DD1EDCBA9F91E79DF4B1E07832032F5B03A43847E20345484730E8D2323199E7439D8C1FC662E812E8BA6EE19C53C89681
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Berlin)]} {.. LoadTimeZoneFile Europe/Berlin..}..set TZData(:Europe/Copenhagen) $TZData(:Europe/Berlin)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):9810
                                                                                                                                                                                                            Entropy (8bit):3.7678769652077873
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:sExxHZiMU8EKTy74jT56XdEN1+UZBdMN186LPR:sEzZiMUZ6y0jT5bZHMN186LPR
                                                                                                                                                                                                            MD5:E1EB426EA3351AF0D7D563006F9146BC
                                                                                                                                                                                                            SHA1:1E94F3B38366FE43BB031A57D19894B569EBABED
                                                                                                                                                                                                            SHA-256:895957521D6CA4DE7E4089DC587A6C177B803D8ADF63303B1F85DEB279726324
                                                                                                                                                                                                            SHA-512:8F24E9519F5D42F34AEE5C52A94CAC7D035EAE7B31DC3E629C29CFE3BD85F1510188290D35CD327492A030168443FED8BD80EC57ED27811B786C4DC89B4B1181
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Dublin) {.. {-9223372036854775808 -1521 0 LMT}.. {-2821649679 -1521 0 DMT}.. {-1691962479 2079 1 IST}.. {-1680471279 0 0 GMT}.. {-1664143200 3600 1 BST}.. {-1650146400 0 0 GMT}.. {-1633903200 3600 1 BST}.. {-1617487200 0 0 GMT}.. {-1601848800 3600 1 BST}.. {-1586037600 0 0 GMT}.. {-1570399200 3600 1 BST}.. {-1552168800 0 0 GMT}.. {-1538344800 3600 1 BST}.. {-1522533600 0 0 GMT}.. {-1517011200 0 0 IST}.. {-1507500000 3600 1 IST}.. {-1490565600 0 0 IST}.. {-1473631200 3600 1 IST}.. {-1460930400 0 0 IST}.. {-1442786400 3600 1 IST}.. {-1428876000 0 0 IST}.. {-1410732000 3600 1 IST}.. {-1396216800 0 0 IST}.. {-1379282400 3600 1 IST}.. {-1364767200 0 0 IST}.. {-1348437600 3600 1 IST}.. {-1333317600 0 0 IST}.. {-1315778400 3600 1 IST}.. {-1301263200 0 0 IST}.. {-1284328800 3600 1 IST}.. {-1269813600 0 0 IST}.. {-1253484000 3600 1 IST
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):9509
                                                                                                                                                                                                            Entropy (8bit):3.8837074152297704
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:QTOKVA1oCobz0W4x2+ZE74elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNA:QyoCvTZ641sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                            MD5:D04F8EDDA1C3611692FB91E317CCADFE
                                                                                                                                                                                                            SHA1:1C483FC95459EC6F1D5FE4DD275879A9EBCA1718
                                                                                                                                                                                                            SHA-256:0524A31131405347C1D5D86C5EE38A2064AB055C030AB3B43F25DB3B28FFD8D2
                                                                                                                                                                                                            SHA-512:4E2E18EBDE2765F2251B1FE41EF8E6AC79875617348974A28619F5E59EC0467239C682CCE8DEBD7A698BE2F00252C77D1F7FA50B6CAFF920B3BE53A0B836F815
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Gibraltar) {.. {-9223372036854775808 -1284 0 LMT}.. {-2821649916 0 0 GMT}.. {-1691964000 3600 1 BST}.. {-1680472800 0 0 GMT}.. {-1664143200 3600 1 BST}.. {-1650146400 0 0 GMT}.. {-1633903200 3600 1 BST}.. {-1617487200 0 0 GMT}.. {-1601848800 3600 1 BST}.. {-1586037600 0 0 GMT}.. {-1570399200 3600 1 BST}.. {-1552168800 0 0 GMT}.. {-1538344800 3600 1 BST}.. {-1522533600 0 0 GMT}.. {-1507500000 3600 1 BST}.. {-1490565600 0 0 GMT}.. {-1473631200 3600 1 BST}.. {-1460930400 0 0 GMT}.. {-1442786400 3600 1 BST}.. {-1428876000 0 0 GMT}.. {-1410732000 3600 1 BST}.. {-1396216800 0 0 GMT}.. {-1379282400 3600 1 BST}.. {-1364767200 0 0 GMT}.. {-1348437600 3600 1 BST}.. {-1333317600 0 0 GMT}.. {-1315778400 3600 1 BST}.. {-1301263200 0 0 GMT}.. {-1284328800 3600 1 BST}.. {-1269813600 0 0 GMT}.. {-1253484000 3600 1 BST}.. {-1238364000 0 0 GMT}
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):183
                                                                                                                                                                                                            Entropy (8bit):4.879252060643389
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVxKL823vXHAIgoqyKL8H6RL/yQakQAL/yQavKL81n:SlSWB9vsM3ymvKA2PHAIgovKAH6N/yYU
                                                                                                                                                                                                            MD5:07AF23DA01CB963EA9E57534E34E7704
                                                                                                                                                                                                            SHA1:1C4A214FF3B722E80C0ECACA0FFD5DFF302F6AE9
                                                                                                                                                                                                            SHA-256:F7046808A8E80B7AE449D1A49AE3E480096736B7D3F554A240C7DFB10F82076A
                                                                                                                                                                                                            SHA-512:713860D340C0EBA5EEF873ECB9B28CCDE9BFAD31B6A8626EF507E96585F5CC1091BF8D8A2DB7E5CB532E44F4561FBAE1797141724EF934755B69919FEA09A78A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/London)]} {.. LoadTimeZoneFile Europe/London..}..set TZData(:Europe/Guernsey) $TZData(:Europe/London)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7368
                                                                                                                                                                                                            Entropy (8bit):3.7258352536809705
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:OsR0uO7DVopaNlKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYjlBKb0hzj:OkyDjivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                            MD5:7FF902B06FA79F14553670A70E77FF8C
                                                                                                                                                                                                            SHA1:0105051541F38956EA6192BD0C7ED4047668005E
                                                                                                                                                                                                            SHA-256:5B5C0A9261A414EA8DC34F594EE05BEE16F695488B230857D2B569A6B603BC39
                                                                                                                                                                                                            SHA-512:551940199783A0FF9D73695B77B10300644F50E91D6B02FE79BB0CD4B78C7BA88CCE56F4B9408EC146361BF408F52D01A1F435183360C801EA5E219FB718247F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Helsinki) {.. {-9223372036854775808 5989 0 LMT}.. {-2890258789 5989 0 HMT}.. {-1535938789 7200 0 EET}.. {-875671200 10800 1 EEST}.. {-859773600 7200 0 EET}.. {354672000 10800 1 EEST}.. {370396800 7200 0 EET}.. {386121600 10800 1 EEST}.. {401846400 7200 0 EET}.. {410220000 7200 0 EET}.. {417574800 10800 1 EEST}.. {433299600 7200 0 EET}.. {449024400 10800 1 EEST}.. {465354000 7200 0 EET}.. {481078800 10800 1 EEST}.. {496803600 7200 0 EET}.. {512528400 10800 1 EEST}.. {528253200 7200 0 EET}.. {543978000 10800 1 EEST}.. {559702800 7200 0 EET}.. {575427600 10800 1 EEST}.. {591152400 7200 0 EET}.. {606877200 10800 1 EEST}.. {622602000 7200 0 EET}.. {638326800 10800 1 EEST}.. {654656400 7200 0 EET}.. {670381200 10800 1 EEST}.. {686106000 7200 0 EET}.. {701830800 10800 1 EEST}.. {717555600 7200 0 EET}.. {733280400 10800 1 EEST}.. {749
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):186
                                                                                                                                                                                                            Entropy (8bit):4.914274131294981
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVxKL823vXHAIgoqyKL8H6RL/yQaqpfioxp8QavKLS:SlSWB9vsM3ymvKA2PHAIgovKAH6N/ycS
                                                                                                                                                                                                            MD5:F9A0F19FAF3131D8A70C50FF21B365B7
                                                                                                                                                                                                            SHA1:7FC2B5302FAD06BC4C633CD22A80A7D40073FFF8
                                                                                                                                                                                                            SHA-256:2F1151B0528A5325443379D4E7CCE32C00213722AD9DF764E1DC90198084B076
                                                                                                                                                                                                            SHA-512:6D04DF4480FE132A6641C4BF7E01936E2E4A71A3A6C2AB9F7DA7A9D8A4B836BC66EE2BB597B8C318D07A06F72C05B07E6785B53308ED9BC1103AE6DBDD0FF24E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/London)]} {.. LoadTimeZoneFile Europe/London..}..set TZData(:Europe/Isle_of_Man) $TZData(:Europe/London)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3683
                                                                                                                                                                                                            Entropy (8bit):3.814835316757376
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:Qi0p05zvSPBUUl0ZFzo4ay0CREDcxn6nH78BV0QbCgkCPviiM0H7hdli80+j7x9L:Qiq66OFEIFMssCfMsXV3heM2MRlA0
                                                                                                                                                                                                            MD5:A8256656B971F58CB991BC270BF93B26
                                                                                                                                                                                                            SHA1:189796E1B8E29A7A7B8B0E143DD9B44BAF217AB2
                                                                                                                                                                                                            SHA-256:08061A80FC0F1EF375EEFE784EACDF0812E289FD67E8613BDEC36209985CA1D7
                                                                                                                                                                                                            SHA-512:1F11308B5BAC1F3DB75CAC7322BBEA6E51C6B4A2A3450F1DB84DE6AA127F0F1BAA7DAB409FAF1288C100BDA77DA6FA1C6E3C0BA962F9406D1445D7C9E2AA3A60
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Istanbul) {.. {-9223372036854775808 6952 0 LMT}.. {-2840147752 7016 0 IMT}.. {-1869875816 7200 0 EET}.. {-1693706400 10800 1 EEST}.. {-1680490800 7200 0 EET}.. {-1570413600 10800 1 EEST}.. {-1552186800 7200 0 EET}.. {-1538359200 10800 1 EEST}.. {-1522551600 7200 0 EET}.. {-1507514400 10800 1 EEST}.. {-1490583600 7200 0 EET}.. {-1440208800 10800 1 EEST}.. {-1428030000 7200 0 EET}.. {-1409709600 10800 1 EEST}.. {-1396494000 7200 0 EET}.. {-931053600 10800 1 EEST}.. {-922676400 7200 0 EET}.. {-917834400 10800 1 EEST}.. {-892436400 7200 0 EET}.. {-875844000 10800 1 EEST}.. {-764737200 7200 0 EET}.. {-744343200 10800 1 EEST}.. {-733806000 7200 0 EET}.. {-716436000 10800 1 EEST}.. {-701924400 7200 0 EET}.. {-684986400 10800 1 EEST}.. {-670474800 7200 0 EET}.. {-654141600 10800 1 EEST}.. {-639025200 7200 0 EET}.. {-622087200 10800 1 EEST}.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):181
                                                                                                                                                                                                            Entropy (8bit):4.8801202136140915
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVxKL823vXHAIgoqyKL8H6RL/yQap6cEBx/yQavKLS:SlSWB9vsM3ymvKA2PHAIgovKAH6N/yzx
                                                                                                                                                                                                            MD5:FE10770868A75F4F8D76C5E23D99AA81
                                                                                                                                                                                                            SHA1:30AC768BA47AF7A53831F5142B58ECEC41933621
                                                                                                                                                                                                            SHA-256:97EB33915ED7C9C34144F8F42357FAB2262B3CD45287F3CFFD26C33D65F7651E
                                                                                                                                                                                                            SHA-512:1D82DF45AB0CCDFBFAD0431C668794996E01776800F34DD4131C5287D37291657A749D497AA5B0AB81CAFF3190896633FBFF456BFFEB7E93A3420AA841E54842
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/London)]} {.. LoadTimeZoneFile Europe/London..}..set TZData(:Europe/Jersey) $TZData(:Europe/London)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2512
                                                                                                                                                                                                            Entropy (8bit):3.941165221943348
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:coNlj+X2uxhuHJkw0QqXknzaVV04v3TfdGY3kNmneVuNlh000sGpdh:coN9+1EpkwCXkSV3A8qc0
                                                                                                                                                                                                            MD5:104CCB93300F40BAF8F4D7CC882EFC05
                                                                                                                                                                                                            SHA1:EA83F3C3791BD6F083844939DC405B248E738FE3
                                                                                                                                                                                                            SHA-256:2387D26DF5429DF9867F42F7D4F872DC146643B4B3CC57DA7298C18561DE8BFE
                                                                                                                                                                                                            SHA-512:12724C5BBEE0835626A98B66BF55C3DF1311F07018C70D76FC5C50E7E7BA5C4A9F064D9EDC376CC3B06C4FFFECA3FAF5B66948615A03DFECA7C361E326D950EA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Kaliningrad) {.. {-9223372036854775808 4920 0 LMT}.. {-2422056120 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-938905200 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-780368400 7200 0 EET}.. {-778730400 10800 1 EEST}.. {-762663600 7200 0 EET}.. {-749095200 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):173
                                                                                                                                                                                                            Entropy (8bit):4.970386708540243
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV2cvXHAIgoq1csFARL/yQaoM2EBUQaocqn:SlSWB9vsM3ym5HAIgoiAN/yOEBUC
                                                                                                                                                                                                            MD5:74ACF46A3248341CFD84B1592F884A8F
                                                                                                                                                                                                            SHA1:888FBB54381A1B5BC19E65AF38A1913635A8E7E4
                                                                                                                                                                                                            SHA-256:05C55F87182F0D5D3E8E6C1F9164EDDBDB8035146A0955C04283BC1347D45B30
                                                                                                                                                                                                            SHA-512:21A752390E023CBD582BC43865D43458B44B036299A2373948269196071742ED7EB6067DD9A288F3A15E808B452FE4192750FAE813F70738FAB0C866219D57CB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Kyiv)]} {.. LoadTimeZoneFile Europe/Kyiv..}..set TZData(:Europe/Kiev) $TZData(:Europe/Kyiv)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2029
                                                                                                                                                                                                            Entropy (8bit):3.668326642402654
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:FFvCAs6kKR6aQmF1cSNWrI+AjXgV/Ap40FjDM:FhCAs6kC6aZF1cSN4I+AjXgV/ApDFjDM
                                                                                                                                                                                                            MD5:57BB199152815B12FE4491C92FE25186
                                                                                                                                                                                                            SHA1:7BC5ECDE9EFADE812AF40CB92CCE5323FB57C78D
                                                                                                                                                                                                            SHA-256:60884D4B8B17A9AB8FB5697DA95F62E570755348109C661D783D56CD047BBE9E
                                                                                                                                                                                                            SHA-512:2043FDBA860E8F6578F7E26A80C7787B82C7D15188327923EC36D153FDF9BEEAE063012ACE4309B76DB9DBA2DFFB7404DE370BA85023CCE93159FCAD3B9B92B5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Kirov) {.. {-9223372036854775808 11928 0 LMT}.. {-1593820800 10800 0 +03}.. {-1247540400 14400 0 +05}.. {354916800 18000 1 +05}.. {370724400 14400 0 +04}.. {386452800 18000 1 +05}.. {402260400 14400 0 +04}.. {417988800 18000 1 +05}.. {433796400 14400 0 +04}.. {449611200 18000 1 +05}.. {465343200 14400 0 +04}.. {481068000 18000 1 +05}.. {496792800 14400 0 +04}.. {512517600 18000 1 +05}.. {528242400 14400 0 +04}.. {543967200 18000 1 +05}.. {559692000 14400 0 +04}.. {575416800 18000 1 +05}.. {591141600 14400 0 +04}.. {606866400 10800 0 +04}.. {606870000 14400 1 +04}.. {622594800 10800 0 +03}.. {638319600 14400 1 +04}.. {654649200 10800 0 +03}.. {670374000 14400 0 +04}.. {701820000 10800 0 +04}.. {701823600 14400 1 +04}.. {717548400 10800 0 +03}.. {733273200 14400 1 +04}.. {748998000 10800 0 +03}.. {764722800 14400 1 +04}.. {78044
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7455
                                                                                                                                                                                                            Entropy (8bit):3.7624983280224953
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:vC1LyEpkv8V3MpaNlKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYjlBKb4:vC9VW0bivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                            MD5:F37C7529B53C4C158341AF90F80C3A11
                                                                                                                                                                                                            SHA1:210650A882350D35C72A934749F276C58C572DFA
                                                                                                                                                                                                            SHA-256:591264F69DB19DDCDC90E704525E2D3D3984117B710F482F19DA8F88628EE6A7
                                                                                                                                                                                                            SHA-512:F23B0C5251EB7418A1C80344AB7623D2A0197E681E3B7D152E416187BF66DE09A7A60A65F8ED6A810272CF0C253D63684F08AF594A8C22ABEA89E3BBADC8F0A0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Kyiv) {.. {-9223372036854775808 7324 0 LMT}.. {-2840148124 7324 0 KMT}.. {-1441159324 7200 0 EET}.. {-1247536800 10800 0 MSK}.. {-892522800 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-825382800 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {606870000 14400 1 MSD}.. {622594800 10800 0 MSK}.. {638319600 14400 1 MSD}.. {646786800 10800 1 EEST}.. {686102400 7200 0 EET}.. {701827200 10800 1 EEST}.. {7175
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):9878
                                                                                                                                                                                                            Entropy (8bit):3.8275310275285723
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:j76abXsyZLEjx82YbtIaFF1w0us4qE3+sSGjT:j77bXsyZLEjx82atysLE3+sSGjT
                                                                                                                                                                                                            MD5:0DA331C2A815739E6758797BD24554EA
                                                                                                                                                                                                            SHA1:3829C441E908BEFDC4ED6AB65FD4ACD0C97D5E1B
                                                                                                                                                                                                            SHA-256:9FAC9812411F88014779D34722F3E0D2750E45BF21595DF1AE14CB9CCFD3F33F
                                                                                                                                                                                                            SHA-512:FEBBA05F64AC1F3066AF6351493DD89768154FD171D447503DAEDB90D16858BEDBCE4A74E24AC0C37B5FF191692AF44AADDE4A92E752F88C48DA646352AD9A0B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Lisbon) {.. {-9223372036854775808 -2205 0 LMT}.. {-2713908195 -2205 0 LMT}.. {-1830384000 0 0 WET}.. {-1689555600 3600 1 WEST}.. {-1677801600 0 0 WET}.. {-1667437200 3600 1 WEST}.. {-1647738000 0 0 WET}.. {-1635814800 3600 1 WEST}.. {-1616202000 0 0 WET}.. {-1604365200 3600 1 WEST}.. {-1584666000 0 0 WET}.. {-1572742800 3600 1 WEST}.. {-1553043600 0 0 WET}.. {-1541206800 3600 1 WEST}.. {-1521507600 0 0 WET}.. {-1442451600 3600 1 WEST}.. {-1426813200 0 0 WET}.. {-1379293200 3600 1 WEST}.. {-1364778000 0 0 WET}.. {-1348448400 3600 1 WEST}.. {-1333328400 0 0 WET}.. {-1316394000 3600 1 WEST}.. {-1301274000 0 0 WET}.. {-1284339600 3600 1 WEST}.. {-1269824400 0 0 WET}.. {-1221440400 3600 1 WEST}.. {-1206925200 0 0 WET}.. {-1191200400 3600 1 WEST}.. {-1175475600 0 0 WET}.. {-1127696400 3600 1 WEST}.. {-1111971600 0 0 WET}.. {-1096851
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):190
                                                                                                                                                                                                            Entropy (8bit):4.948438246006353
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/sUE2tovXHAIgoq8sUE2oAovRL/yQavPSJ5Qahs0:SlSWB9vsM3ymhrE2tSHAIgohrE2LovNl
                                                                                                                                                                                                            MD5:56C6C95484FEAF9BAF755683E7417B58
                                                                                                                                                                                                            SHA1:A43176BEBC5B4D7144A7E1109E0AAEFD95C21EC6
                                                                                                                                                                                                            SHA-256:713A842197516D618F2D86977262542A1CA334D7DF6026539FA2F2980DBF4CD3
                                                                                                                                                                                                            SHA-512:566B6DF2D76A8A4D3405C4785C7A471A23D65CD8838831BD0DEDF5BF194E8A3B304CA9920CB4A8EC9D6CD60EAA9BE0335E38D9547A4D23C7E4E5E5A39A09DDAC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Belgrade)]} {.. LoadTimeZoneFile Europe/Belgrade..}..set TZData(:Europe/Ljubljana) $TZData(:Europe/Belgrade)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):10211
                                                                                                                                                                                                            Entropy (8bit):3.826887992237191
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:GNoCvTZtcf80KYiK3BG0Myj9TYQOeMAwbccM0Fp:GNNTZtcf15iOBG08eNwbccM0Fp
                                                                                                                                                                                                            MD5:0625C99E16D3C956DED1C0C0F867DEC3
                                                                                                                                                                                                            SHA1:6ACDF0DB619B63E21EC89046B9320A85FBD3397A
                                                                                                                                                                                                            SHA-256:D04C4E25DF4DE1C1CFE1EF84B3B6DD746CF08A271AB0958F22C7D580A3ED10E6
                                                                                                                                                                                                            SHA-512:07AC42F0635DF01CC0AFD13F9668B143D4943BA0E4C377D254B5AF034D9DDBAB77BA813187E9AB73D2EEAD86EBAA26DC15599FD74FC82EEF287F5A6AB9C01635
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/London) {.. {-9223372036854775808 -75 0 LMT}.. {-3852662325 0 0 GMT}.. {-1691964000 3600 1 BST}.. {-1680472800 0 0 GMT}.. {-1664143200 3600 1 BST}.. {-1650146400 0 0 GMT}.. {-1633903200 3600 1 BST}.. {-1617487200 0 0 GMT}.. {-1601848800 3600 1 BST}.. {-1586037600 0 0 GMT}.. {-1570399200 3600 1 BST}.. {-1552168800 0 0 GMT}.. {-1538344800 3600 1 BST}.. {-1522533600 0 0 GMT}.. {-1507500000 3600 1 BST}.. {-1490565600 0 0 GMT}.. {-1473631200 3600 1 BST}.. {-1460930400 0 0 GMT}.. {-1442786400 3600 1 BST}.. {-1428876000 0 0 GMT}.. {-1410732000 3600 1 BST}.. {-1396216800 0 0 GMT}.. {-1379282400 3600 1 BST}.. {-1364767200 0 0 GMT}.. {-1348437600 3600 1 BST}.. {-1333317600 0 0 GMT}.. {-1315778400 3600 1 BST}.. {-1301263200 0 0 GMT}.. {-1284328800 3600 1 BST}.. {-1269813600 0 0 GMT}.. {-1253484000 3600 1 BST}.. {-1238364000 0 0 GMT}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):191
                                                                                                                                                                                                            Entropy (8bit):4.920751023999728
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/So3vXHAIgoq82yHRL/yQavQLHKQX9J8QahCv:SlSWB9vsM3ymhS2HAIgoh26N/y1QzKQt
                                                                                                                                                                                                            MD5:E4A8C25756D6C5D2073A51D2B54E3A0C
                                                                                                                                                                                                            SHA1:4A24667ADC9BD31E8CB298BE3787C12301C3F1C8
                                                                                                                                                                                                            SHA-256:8C0486A5B235E8B01069420976E1B8D08D77A4BEF587203AF1B68D7B5333546E
                                                                                                                                                                                                            SHA-512:F3593C3B75C9DA931FB39BC2054EB9691C3A544A74F871425169C3244040D6D060510741FE1E352A1E59F53E5A585307D434A0D7C9D159D065717E78C807787C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Brussels)]} {.. LoadTimeZoneFile Europe/Brussels..}..set TZData(:Europe/Luxembourg) $TZData(:Europe/Brussels)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8517
                                                                                                                                                                                                            Entropy (8bit):3.8326167134909177
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:k5m01LdXKc0TJp+bwS274elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOn:+DaNVLSs41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                            MD5:63263380F57B756A1DFA3796E4188CD3
                                                                                                                                                                                                            SHA1:8EEE707AC4FEA1C098C81AC2D289A46239121A5E
                                                                                                                                                                                                            SHA-256:5337C9843C56DEEC6B91C4468C76EC1C896E80421B72B583B69DE5579063E09A
                                                                                                                                                                                                            SHA-512:ACA4830020715C471741E27EB2292ACF002D2CD7EDCD1061978B64967EB447F61AA095F960D8A75A01B9B87558D83FF409F30BDACA83E063024F1E2381FA64C4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Madrid) {.. {-9223372036854775808 -884 0 LMT}.. {-2177452800 0 0 WET}.. {-1631926800 3600 1 WEST}.. {-1616889600 0 0 WET}.. {-1601168400 3600 1 WEST}.. {-1585353600 0 0 WET}.. {-1442451600 3600 1 WEST}.. {-1427673600 0 0 WET}.. {-1379293200 3600 1 WEST}.. {-1364774400 0 0 WET}.. {-1348448400 3600 1 WEST}.. {-1333324800 0 0 WET}.. {-1316390400 3600 1 WEST}.. {-1301270400 0 0 WET}.. {-1284339600 3600 1 WEST}.. {-1269820800 0 0 WET}.. {-1026954000 3600 1 WEST}.. {-1017619200 0 0 WET}.. {-1001898000 3600 1 WEST}.. {-999482400 7200 1 WEMT}.. {-986090400 3600 1 WEST}.. {-954115200 0 0 WET}.. {-940208400 3600 0 CET}.. {-873079200 7200 1 CEST}.. {-862621200 3600 0 CET}.. {-842839200 7200 1 CEST}.. {-828320400 3600 0 CET}.. {-811389600 7200 1 CEST}.. {-796870800 3600 0 CET}.. {-779940000 7200 1 CEST}.. {-765421200 3600 0 CET}.. {-74849
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8724
                                                                                                                                                                                                            Entropy (8bit):3.816380386871747
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:KAGvi2GmkwwnpH74elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZN:KLsww141sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                            MD5:9B09D6EED8F23BAFFB62929C0115E852
                                                                                                                                                                                                            SHA1:4AEF15333C73C2836C09D818FD0E20440D7C4780
                                                                                                                                                                                                            SHA-256:C5C240BAAECE8235D1FBDD251C1A67CB2D2FC8195DD5BBE37FF9CFF0445FCDA2
                                                                                                                                                                                                            SHA-512:43AA3492BD335A290C6EFEE275B47EA18E544199E37A9BBAE2E350D42BDFF42F0E9ED461A4BB1824CA33F84A90D4060906844A3E22DA49C9821E4CB460832D6E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Malta) {.. {-9223372036854775808 3484 0 LMT}.. {-2403478684 3600 0 CET}.. {-1690765200 7200 1 CEST}.. {-1680487200 3600 0 CET}.. {-1664758800 7200 1 CEST}.. {-1648951200 3600 0 CET}.. {-1635123600 7200 1 CEST}.. {-1616896800 3600 0 CET}.. {-1604278800 7200 1 CEST}.. {-1585533600 3600 0 CET}.. {-1571014800 7200 1 CEST}.. {-1555293600 3600 0 CET}.. {-932432400 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812588400 7200 1 CEST}.. {-798073200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-766717200 3600 0 CET}.. {-750898800 7200 1 CEST}.. {-733359600 3600 0 CET}.. {-719456400 7200 1 CEST}.. {-701917200 3600 0 CET}.. {-689209200 7200 1 CEST}.. {-670460400 3600 0 CET}.. {-114051600 7200 1 CEST}.. {-103168800 3600 0 CET}.. {-81997200 7200 1 CEST}.. {-71715600 3600 0 CET}.. {-50547600 7200 1
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):190
                                                                                                                                                                                                            Entropy (8bit):4.959733196757503
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV1AYKjG5XHAIgoq2AYKjo0ARL/yQausWILMFJ8QaC:SlSWB9vsM3ymrAdjGJHAIgorAdjo0ANn
                                                                                                                                                                                                            MD5:C1844961691214F6E6DF6487788A7758
                                                                                                                                                                                                            SHA1:6D08E9FB7B8602A80622148BFACD9676F45F0E2B
                                                                                                                                                                                                            SHA-256:6136C3CFA4A767E7C9DDA23A283AD98B72E9868F192E6A8E3BFE6396F6989BD1
                                                                                                                                                                                                            SHA-512:B2D1EA51AC5B34792AC02820A9D60FD41F3B91AB6505896476FCB0DC339B8DC1DE9E2C89A7627F69E16247661AE8040D789FFD2F8F1CD59F243B57C4845B450F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Helsinki)]} {.. LoadTimeZoneFile Europe/Helsinki..}..set TZData(:Europe/Mariehamn) $TZData(:Europe/Helsinki)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2177
                                                                                                                                                                                                            Entropy (8bit):3.9354590900153172
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:K8cVnR7xhuHJkminzaVV04v3TfdGY3kNmneVuNlh000sGpde:5mnRtEpkmiSV3A8qcN
                                                                                                                                                                                                            MD5:9C10EAE9FA0DE192C5FD4F76E12606F0
                                                                                                                                                                                                            SHA1:AFD5650410EC3E6ED564A8B2ABF91709D090B4AD
                                                                                                                                                                                                            SHA-256:8C95EA696EA578DEF726502AC181AF475A676030878F56B4E2D667757BBD1C49
                                                                                                                                                                                                            SHA-512:3B9ED6B68858485B9A46A0863B7D9D3C1E4C5BBA269457F24A9A12C274F0F9B35E63D8C25EB53E7200DB57DD35ACCB7FD7D8AB005FEE2C4D7FC6E72E8CF57194
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Minsk) {.. {-9223372036854775808 6616 0 LMT}.. {-2840147416 6600 0 MMT}.. {-1441158600 7200 0 EET}.. {-1247536800 10800 0 MSK}.. {-899780400 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-804646800 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {606870000 14400 1 MSD}.. {622594800 10800 0 MSK}.. {631141200 10800 0 MSK}.. {670374000 7200 0 EEMMTT}.. {670377600 10800 1 EEST}.. {
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):178
                                                                                                                                                                                                            Entropy (8bit):4.9089012087310095
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVtEXc4o3vXHAIgoquEXeRL/yQauPMFBx6QazEXcov:SlSWB9vsM3ymzESPHAIgozEON/ySRpEB
                                                                                                                                                                                                            MD5:2015CF8BBEEE12AF0D9C82FD2E246C72
                                                                                                                                                                                                            SHA1:062BFFBB266C3EBB5776A509DDB7A6044C82B864
                                                                                                                                                                                                            SHA-256:9DF16BB1C26100635DC4CB1DF409B0FA7B139C22BF09574ED337EE244CA3C546
                                                                                                                                                                                                            SHA-512:FD3479588D4F3B84CF6C8B8A5DB1AB3BFA0A87CA2FFADB4FEBBBB25711C77963BE7CD0D1DA5ED985D729F39C5B44E8CBD429F1E2DA813DF26272D66CAE4F425A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Paris)]} {.. LoadTimeZoneFile Europe/Paris..}..set TZData(:Europe/Monaco) $TZData(:Europe/Paris)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2430
                                                                                                                                                                                                            Entropy (8bit):3.942836780611272
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:7fnjazk7e+LxhuHJkvVineTeCTU50x0Y7:7fnjazk7eoEpkvVieTeCTUax0Y7
                                                                                                                                                                                                            MD5:4547D47E9364ACAFB2A4BEE52D04BFBB
                                                                                                                                                                                                            SHA1:1E7F964692F81D49AEAF581FE70AD22D4E36226B
                                                                                                                                                                                                            SHA-256:31F9C3C2F17B3EE4FA6D9EE6A86BF407AC0377DE4D666C65E86CE5AC591F829F
                                                                                                                                                                                                            SHA-512:7F1D7C80A1BF611D5440EEF9085DA6CDED86B5EF4C2737C105640030E5AA998A0951182E72DC224190A25DA8846CDE856A78EBAA8876AA0B18B1CBCADBB060FF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Moscow) {.. {-9223372036854775808 9017 0 LMT}.. {-2840149817 9017 0 MMT}.. {-1688265017 9079 0 MMT}.. {-1656819079 12679 1 MST}.. {-1641353479 9079 0 MMT}.. {-1627965079 16279 1 MDST}.. {-1618716679 12679 1 MST}.. {-1596429079 16279 1 MDST}.. {-1593820800 14400 0 MSD}.. {-1589860800 10800 0 MSK}.. {-1542427200 14400 1 MSD}.. {-1539493200 18000 1 +05}.. {-1525323600 14400 1 MSD}.. {-1491188400 7200 0 EET}.. {-1247536800 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):179
                                                                                                                                                                                                            Entropy (8bit):4.7873368289068905
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq85GKLlXHAIgNwMGKLZRRL/yQatHefeWFKYGKL8n:SlSWB9vsM3yZdL1HAIgGMdLZRN/y3HeA
                                                                                                                                                                                                            MD5:BE82205480617CF07F76BA0DF06C95BC
                                                                                                                                                                                                            SHA1:46D2D8D9FE4FB570C2A09BC809B02C8960F9601F
                                                                                                                                                                                                            SHA-256:FC93B7516933EDFDC211AC0822EE88BF7ACAD1C58A0643B15294F82EB0F14414
                                                                                                                                                                                                            SHA-512:F490A70053A6011D80FB0A4E96D2871BFEEB168690E21C4EC31F2F5C0E24A67C706528C81322A1D48E71242F0FFA277550192925FDE5B1F34BFCB308290E11FC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Nicosia)]} {.. LoadTimeZoneFile Asia/Nicosia..}..set TZData(:Europe/Nicosia) $TZData(:Asia/Nicosia)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):179
                                                                                                                                                                                                            Entropy (8bit):4.910647918749938
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/y+YF3vXHAIgoq8yFRRL/yQasWJAQahyuv:SlSWB9vsM3ymhVoPHAIgoh6N/yI7Fv
                                                                                                                                                                                                            MD5:242748F361AD524CD8E288BEE8611E19
                                                                                                                                                                                                            SHA1:A636A544BB54851185E2BE83DAC69C813B824827
                                                                                                                                                                                                            SHA-256:C84E9C0D22059573079211CBF487072CAB95C14B5ECEFB596CF1F594ABD3458C
                                                                                                                                                                                                            SHA-512:404B272D0C6B70332052601EA65C0F7AE71C12F62D19FD3010BBA6FB25E4F2F95BB9E5F295D8494CBADB1AE9C7F833C42382AE7488317EA6F0C20E60B63BEFE8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Berlin)]} {.. LoadTimeZoneFile Europe/Berlin..}..set TZData(:Europe/Oslo) $TZData(:Europe/Berlin)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):9152
                                                                                                                                                                                                            Entropy (8bit):3.8506895725632746
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:fySTO1C+4qoMYOKDBb0S274elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdi:fdp+3Ss41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                            MD5:9CAF8C5C5AF630E7F782C0480DD786E7
                                                                                                                                                                                                            SHA1:9FBEF9EEDD8BAFB48B17E3AC388CFEF8DCD10CB0
                                                                                                                                                                                                            SHA-256:AE61491C4A587F56426A9F2118E31060276F2B0231E750C461781577551CA196
                                                                                                                                                                                                            SHA-512:F809744BB597184A2815758A27B6A07C515C65DB96CFFB3625FD059DEBBF05EE903E999483B3459C7C8D3991824746F8530CD1378F8A63B1F54F60CFACE9F89B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Paris) {.. {-9223372036854775808 561 0 LMT}.. {-2486592561 561 0 PMT}.. {-1855958961 0 0 WET}.. {-1689814800 3600 1 WEST}.. {-1680397200 0 0 WET}.. {-1665363600 3600 1 WEST}.. {-1648342800 0 0 WET}.. {-1635123600 3600 1 WEST}.. {-1616893200 0 0 WET}.. {-1604278800 3600 1 WEST}.. {-1585443600 0 0 WET}.. {-1574038800 3600 1 WEST}.. {-1552266000 0 0 WET}.. {-1539997200 3600 1 WEST}.. {-1520557200 0 0 WET}.. {-1507510800 3600 1 WEST}.. {-1490576400 0 0 WET}.. {-1470618000 3600 1 WEST}.. {-1459126800 0 0 WET}.. {-1444006800 3600 1 WEST}.. {-1427677200 0 0 WET}.. {-1411952400 3600 1 WEST}.. {-1396227600 0 0 WET}.. {-1379293200 3600 1 WEST}.. {-1364778000 0 0 WET}.. {-1348448400 3600 1 WEST}.. {-1333328400 0 0 WET}.. {-1316394000 3600 1 WEST}.. {-1301274000 0 0 WET}.. {-1284339600 3600 1 WEST}.. {-1269824400 0 0 WET}.. {-1253494800 3
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):190
                                                                                                                                                                                                            Entropy (8bit):4.910162937111088
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/sUE2tovXHAIgoq8sUE2oAovRL/yQazKIGl1/yQ0:SlSWB9vsM3ymhrE2tSHAIgohrE2LovNK
                                                                                                                                                                                                            MD5:52C36955D6BD1D9FE9CB64822D04B6DB
                                                                                                                                                                                                            SHA1:D5FF82EC486409E6FB314AD5ACE608577C9632CF
                                                                                                                                                                                                            SHA-256:B87630FF459DE07EB16CD0C2452660772E3FFC4EEB8419EA77A013B6F63A5900
                                                                                                                                                                                                            SHA-512:ABA49D3F05A41A4982600E4DA5C225D8994251F447401EE6FE8478E008BCD5D41C057034185B5CFF805634D571F3CC98EFE98093ABC8E6271351E11A4DA1E7AD
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Belgrade)]} {.. LoadTimeZoneFile Europe/Belgrade..}..set TZData(:Europe/Podgorica) $TZData(:Europe/Belgrade)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8038
                                                                                                                                                                                                            Entropy (8bit):3.8240363895915914
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:Kr9+neXAS274elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhltlh:KnASs41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                            MD5:828134FA1263FEFA2B06A8B2F075F564
                                                                                                                                                                                                            SHA1:4B332DE6E0855F8B9517F7098A3FB439671FC349
                                                                                                                                                                                                            SHA-256:5D3AFED5C1B07C6C6635D6BDEB28A0FB4D11A61F25F26C91227B2254BE5F4AA0
                                                                                                                                                                                                            SHA-512:9AB1462CDBD7F13F0CECDCCC2D91A85D8C0576B71508F935D26638C25ED023CF8FF4BA4FFDA402B308E6142B135D1B9D88700A519DBE2381E8E945329A5354F7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Prague) {.. {-9223372036854775808 3464 0 LMT}.. {-3786829064 3464 0 PMT}.. {-2469401864 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-938905200 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-777862800 7200 0 CEST}.. {-765327600 3600 0 CET}.. {-746578800 7200 1 CEST}.. {-733359600 3600 0 CET}.. {-728517600 0 1 GMT}.. {-721260000 0 0 CET}.. {-716425200 7200 1 CEST}.. {-701910000 3600 0 CET}.. {-684975600 7200 1 CEST}.. {-670460400 3600 0 CET}.. {-654217200 7200 1 CEST}.. {-639010800 3600 0 CET}.. {283993200 3600 0 CET}.. {291776400 7200 1 CEST}.. {307501200 3600 0 CET}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7658
                                                                                                                                                                                                            Entropy (8bit):3.7750218768791806
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:eq+cEpkjXkSV385aNlKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYjlBK0:ePWjUS7ivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                            MD5:0D3C919F60081388524BD5DB22E6904B
                                                                                                                                                                                                            SHA1:6691EAB901C8B57D2F2693120A45A67799D05FCB
                                                                                                                                                                                                            SHA-256:8B64A42BAFD90F9255CACFDBAC603D638DD7C18DC27249F9C9B515E1DA634424
                                                                                                                                                                                                            SHA-512:62A2820B8C1C5468AC1F1BB626F9AAAD0BA1DEC5B73740F00FE4DB8CFA3F2BCF9947968E693824FC8770BA20AB962F93F7E5E345AE8A85F99CDB18E2B510308E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Riga) {.. {-9223372036854775808 5794 0 LMT}.. {-2840146594 5794 0 RMT}.. {-1632008194 9394 1 LST}.. {-1618702594 5794 0 RMT}.. {-1601681794 9394 1 LST}.. {-1597275394 5794 0 RMT}.. {-1377308194 7200 0 EET}.. {-928029600 10800 0 MSK}.. {-899521200 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-795834000 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {6
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8813
                                                                                                                                                                                                            Entropy (8bit):3.8168470239811736
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:hhGvC2GmkNXEq74elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhn:hUsF41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                            MD5:C4F49446D3696301EDB339691DCB2FDB
                                                                                                                                                                                                            SHA1:537963A77B9BE9BE6B997A812A6E6DD120F6F247
                                                                                                                                                                                                            SHA-256:DCD2D9144507311E573568598E1FFD0E0574FB677AA0DAFC5641D80A19EB6E58
                                                                                                                                                                                                            SHA-512:1F0A9A549FA0995C51E90AC392671E3F09744B268F1EE6A27CA7E3C41C2B02A4BA0F98369BE40BA482FBA1FED8F1EE712F0B3217AD86164D1AD498E369C24D76
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Rome) {.. {-9223372036854775808 2996 0 LMT}.. {-3252098996 2996 0 RMT}.. {-2403565200 3600 0 CET}.. {-1690765200 7200 1 CEST}.. {-1680487200 3600 0 CET}.. {-1664758800 7200 1 CEST}.. {-1648951200 3600 0 CET}.. {-1635123600 7200 1 CEST}.. {-1616896800 3600 0 CET}.. {-1604278800 7200 1 CEST}.. {-1585533600 3600 0 CET}.. {-1571014800 7200 1 CEST}.. {-1555293600 3600 0 CET}.. {-932432400 7200 1 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-830307600 7200 0 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-807152400 7200 0 CEST}.. {-798073200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-766717200 3600 0 CET}.. {-750898800 7200 1 CEST}.. {-733359600 3600 0 CET}.. {-719456400 7200 1 CEST}.. {-701917200 3600 0 CET}.. {-689209200 7200 1 CEST}.. {-670460400 3600 0 CET}.. {-114051600 7200 1 CEST}.. {-103168800 36
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2118
                                                                                                                                                                                                            Entropy (8bit):3.664269700453612
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:7PvCAs6kKR6aQmF1cSNWrI+AjQnTRYZ/YF0LUdt/LkajuZbIJltiabs2Tb:7HCAs6kC6aZF1cSN4I+AjQTRYZ/YF0Lw
                                                                                                                                                                                                            MD5:965D987F6576F66A08871697144D4CDB
                                                                                                                                                                                                            SHA1:AF7226DF81C2B3C3A5832F59FC708A6BCBF389CA
                                                                                                                                                                                                            SHA-256:8F395352AA05D35E7D13380E73659A0D5B56FFC17E3F4E40E4F678A902F0E49B
                                                                                                                                                                                                            SHA-512:B82E0CFA5EDA0FCDF03609AE439255F8937A7E9EFA0AFE15EA8877316782AFC74514BCD2B4F06F1B5F0F3C5A64A933D73CB50D5AED2BB1491BD6CACBB77B10E8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Samara) {.. {-9223372036854775808 12020 0 LMT}.. {-1593820800 10800 0 +03}.. {-1247540400 14400 0 +04}.. {-1102305600 14400 0 +05}.. {354916800 18000 1 +05}.. {370724400 14400 0 +04}.. {386452800 18000 1 +05}.. {402260400 14400 0 +04}.. {417988800 18000 1 +05}.. {433796400 14400 0 +04}.. {449611200 18000 1 +05}.. {465343200 14400 0 +04}.. {481068000 18000 1 +05}.. {496792800 14400 0 +04}.. {512517600 18000 1 +05}.. {528242400 14400 0 +04}.. {543967200 18000 1 +05}.. {559692000 14400 0 +04}.. {575416800 18000 1 +05}.. {591141600 14400 0 +04}.. {606866400 10800 0 +04}.. {606870000 14400 1 +04}.. {622594800 10800 0 +03}.. {638319600 14400 1 +04}.. {654649200 10800 0 +03}.. {670374000 7200 0 +03}.. {670377600 10800 1 +03}.. {686102400 10800 0 +03}.. {687916800 14400 0 +04}.. {701820000 18000 1 +05}.. {717544800 14400 0 +04}.. {733
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):179
                                                                                                                                                                                                            Entropy (8bit):4.955758257767983
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVvjF3vXHAIgoqspvVHRL/yQawELDX7x/yQaxE:SlSWB9vsM3ymx5PHAIgoxvN/yt/yrE
                                                                                                                                                                                                            MD5:D253DA6880630A31D39DB0CFA4933ABD
                                                                                                                                                                                                            SHA1:E5798DAAE574729685FE489F296B964BC1CCF2E4
                                                                                                                                                                                                            SHA-256:B6856A0E38C2404F7D5FA1821559503F8AE70923A562F0D993124D131515F395
                                                                                                                                                                                                            SHA-512:CFB6005F3E8D1C585AF36EB7A8C9F49760EF6F446C97E7804EB61EFD0804424C4FB6AE81B71C5A867274EF89A17DAC0D2A0FF882A0F6AEA1D5FFD51593726C5F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Rome)]} {.. LoadTimeZoneFile Europe/Rome..}..set TZData(:Europe/San_Marino) $TZData(:Europe/Rome)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):189
                                                                                                                                                                                                            Entropy (8bit):4.937834327554967
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/sUE2tovXHAIgoq8sUE2oAovRL/yQawEX3GEaQa5:SlSWB9vsM3ymhrE2tSHAIgohrE2LovNZ
                                                                                                                                                                                                            MD5:F7C7DAE9C5D371EF9EE1F490246ED3CC
                                                                                                                                                                                                            SHA1:40C388FE2A55078C8E0524A4385B3F8846960E24
                                                                                                                                                                                                            SHA-256:BC00D953C2F3E55E40EDA13838AB66B9E9D0BDAD620E4EB917637761ABB06FB1
                                                                                                                                                                                                            SHA-512:EB22C59F4D58D96797A718FC59B010795F587626E456D44A3E6398E0FBF4ECD97BCDC151BC1359151798B5AF2964FE5708233F8ECD0D344C3E27629F2645687F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Belgrade)]} {.. LoadTimeZoneFile Europe/Belgrade..}..set TZData(:Europe/Sarajevo) $TZData(:Europe/Belgrade)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2061
                                                                                                                                                                                                            Entropy (8bit):3.6638125261109824
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:yFvCAs6kKR6aQmF1cSNWJjXgV/Ap40FjDQ:yhCAs6kC6aZF1cSNcjXgV/ApDFjDQ
                                                                                                                                                                                                            MD5:CC4D7C478790588D232568CAB12D8E67
                                                                                                                                                                                                            SHA1:07A7CFCFFFF91D124EDFC99F5053BAFC79FBB12B
                                                                                                                                                                                                            SHA-256:AB90363DEE5077C39EC55FE8E519593FF08223E5A8E593F6CCE01FB5B8B35BAE
                                                                                                                                                                                                            SHA-512:23944D20624C942CFDE58F1019160D64401BD0AFB8C3EC49F904038482FAA6741812548C860A2DAE050B8D17A7E08ED9C6EBE7FF19393CFA46D78B1D21B1CACA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Saratov) {.. {-9223372036854775808 11058 0 LMT}.. {-1593820800 10800 0 +03}.. {-1247540400 14400 0 +05}.. {354916800 18000 1 +05}.. {370724400 14400 0 +04}.. {386452800 18000 1 +05}.. {402260400 14400 0 +04}.. {417988800 18000 1 +05}.. {433796400 14400 0 +04}.. {449611200 18000 1 +05}.. {465343200 14400 0 +04}.. {481068000 18000 1 +05}.. {496792800 14400 0 +04}.. {512517600 18000 1 +05}.. {528242400 14400 0 +04}.. {543967200 18000 1 +05}.. {559692000 14400 0 +04}.. {575416800 10800 0 +04}.. {575420400 14400 1 +04}.. {591145200 10800 0 +03}.. {606870000 14400 1 +04}.. {622594800 10800 0 +03}.. {638319600 14400 1 +04}.. {654649200 10800 0 +03}.. {670374000 14400 0 +04}.. {701820000 10800 0 +04}.. {701823600 14400 1 +04}.. {717548400 10800 0 +03}.. {733273200 14400 1 +04}.. {748998000 10800 0 +03}.. {764722800 14400 1 +04}.. {780
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2389
                                                                                                                                                                                                            Entropy (8bit):3.9491446081772748
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:wM2wE0xhuHJkYaVV0XOnbdSisa0ewEKGfUslIYtq8X:UwEAEpkzVFgaNl7
                                                                                                                                                                                                            MD5:03E05E60E064198BF6562B2E6E8DA8D2
                                                                                                                                                                                                            SHA1:51461207B671536CD4A7587BA283DE2D0017AA4A
                                                                                                                                                                                                            SHA-256:D51CD3DE50C50BCA1624EFC952ADD15D418A09EC213760DF5BC3097E35C5A7A0
                                                                                                                                                                                                            SHA-512:73B7773DABE19F20DD211E178B822FD35620DC4AC8B9D20259971B1157ED7A60A5A41026258FAA8B15016268D241ED804AC1307CACDA00D6FE657407D254B02C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Simferopol) {.. {-9223372036854775808 8184 0 LMT}.. {-2840148984 8160 0 SMT}.. {-1441160160 7200 0 EET}.. {-1247536800 10800 0 MSK}.. {-888894000 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-811645200 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {606870000 14400 1 MSD}.. {622594800 10800 0 MSK}.. {631141200 10800 0 MSK}.. {646786800 7200 0 EET}.. {701042400 7200 0 EET}.. {
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):187
                                                                                                                                                                                                            Entropy (8bit):4.953089768975736
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/sUE2tovXHAIgoq8sUE2oAovRL/yQawOgpr8Qahr:SlSWB9vsM3ymhrE2tSHAIgohrE2LovNO
                                                                                                                                                                                                            MD5:0BF8ADBB63F5D6187C75FF1B0BAC761E
                                                                                                                                                                                                            SHA1:7DE15E767D34812F784CE6E85438A592E2CBA418
                                                                                                                                                                                                            SHA-256:52F20858433261B15797B64F0A09CEE95D552EF93B5DAA7C141BFAB6D718C345
                                                                                                                                                                                                            SHA-512:27D395635427C8FA1A4E0063A32F482701D2CC7C7724B4A06E661D4A419D23E219672888D37367FE5E70B6872914EB9EE034AE359DCB6A4C4CE05CA34C3589A9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Belgrade)]} {.. LoadTimeZoneFile Europe/Belgrade..}..set TZData(:Europe/Skopje) $TZData(:Europe/Belgrade)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7654
                                                                                                                                                                                                            Entropy (8bit):3.727428614069594
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:8lmG4+K7Gjz5CXNUatpaNlKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYf:8lmGWwkdUasivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                            MD5:91357DFC23ADB0CE80C463E4B6D896BE
                                                                                                                                                                                                            SHA1:273F51BE4C67A9AC1182F86AC060E963684151D5
                                                                                                                                                                                                            SHA-256:6415F279CB143EA598CF8272263AC5B502827B10CEEB242B39E6EFCC23A2EE12
                                                                                                                                                                                                            SHA-512:8EA7E2D4C2239879A4D6CCE302C38A6D2A9093A2CADEF4F4294E60D373AB9A2C468BA6E3D54DEC7F73D954CE5226EF2B022F8BDEF29B3B4AAB3838B05C72EA29
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Sofia) {.. {-9223372036854775808 5596 0 LMT}.. {-2840146396 7016 0 IMT}.. {-2369527016 7200 0 EET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-788922000 3600 0 CET}.. {-781048800 7200 0 EET}.. {291762000 10800 0 EEST}.. {307576800 7200 0 EET}.. {323816400 10800 1 EEST}.. {339026400 7200 0 EET}.. {355266000 10800 1 EEST}.. {370393200 7200 0 EET}.. {386715600 10800 1 EEST}.. {401846400 7200 0 EET}.. {417571200 10800 1 EEST}.. {433296000 7200 0 EET}.. {449020800 10800 1 EEST}.. {465350400 7200 0 EET}.. {481075200 10800 1 EEST}.. {496800000 7200 0 EET}.. {512524800 10800 1 EEST}.. {528249600 7200 0 EET}.. {543974400 10800 1 EEST}.. {559699200 7200 0 EET}.. {575424000 10800 1 EEST}.. {591148800 7200 0 EET}.. {606873600 10800 1 EEST}.. {62259
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):184
                                                                                                                                                                                                            Entropy (8bit):4.956798438511978
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/y+YF3vXHAIgoq8yFRRL/yQawRMNSTyQahyuv:SlSWB9vsM3ymhVoPHAIgoh6N/yqMNSTm
                                                                                                                                                                                                            MD5:ACFB8E2D1D4BA0D2D46410F2F2823B21
                                                                                                                                                                                                            SHA1:4AC3A19E94DE606DFF7D93BC6C7F113F3D2D083A
                                                                                                                                                                                                            SHA-256:64615AEA9EF14A2609D2C804901281C83FDDC0A8BCA9B377D6CAD62D81801C66
                                                                                                                                                                                                            SHA-512:2E23AC0DE7D3D0CF2BA4FE3EE31E15EB614A7442097578209D38CE2FF2E3DF006881463866FE67DD4DDEAB179E5CD2946E8A9E8F7401F1B953E9AB216EC753F0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Berlin)]} {.. LoadTimeZoneFile Europe/Berlin..}..set TZData(:Europe/Stockholm) $TZData(:Europe/Berlin)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7549
                                                                                                                                                                                                            Entropy (8bit):3.76585669030767
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:dUusEpkjXkSV3AMaNlKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYjlBK0:O0WjUSWivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                            MD5:54EF0224F5E28FA78F212EC97D4AE561
                                                                                                                                                                                                            SHA1:FA7C9A951ED943F1E1E609D2253582016BC26B57
                                                                                                                                                                                                            SHA-256:6F3594CCDA78B02B2EE14C8FAE29E668E47193AF2DFCF5AF1ECD210F13BCE9CE
                                                                                                                                                                                                            SHA-512:2D1CA2BB1945AE5E3F56AF8FA7F950CE7169F215C783E683634581C5EC01B54159E47A0E9551897077BBEAB06158906029A4E4B0051A263D9E5D903EA9DA1692
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Tallinn) {.. {-9223372036854775808 5940 0 LMT}.. {-2840146740 5940 0 TMT}.. {-1638322740 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-1593824400 5940 0 TMT}.. {-1535938740 7200 0 EET}.. {-927943200 10800 0 MSK}.. {-892954800 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-797648400 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {606870000 10800 1 EEST}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7675
                                                                                                                                                                                                            Entropy (8bit):3.809498345470167
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:n05NWKIHBJ9AE4elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhlt:0iKqxAE41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                            MD5:1983B88075A92942209BB2B80E565F4E
                                                                                                                                                                                                            SHA1:12A0401026C5C036144FD1D544173AAB39969F61
                                                                                                                                                                                                            SHA-256:C62686BF598138FEFB72E8CC6632BA75A5FE147F2A30124EE3583BE1F732E38D
                                                                                                                                                                                                            SHA-512:E95C38FA0A2B526C00B9DCF5CDF53059DECF64B085AA18BE000968DA626561944415D053CF7A5C32BC672085538920CFD67A3A3B627CFD5B1A4C9CEC49AA3F96
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Tirane) {.. {-9223372036854775808 4760 0 LMT}.. {-1767230360 3600 0 CET}.. {-932346000 7200 0 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-843519600 3600 0 CET}.. {136854000 7200 1 CEST}.. {149896800 3600 0 CET}.. {168130800 7200 1 CEST}.. {181432800 3600 0 CET}.. {199839600 7200 1 CEST}.. {213141600 3600 0 CET}.. {231894000 7200 1 CEST}.. {244591200 3600 0 CET}.. {263257200 7200 1 CEST}.. {276040800 3600 0 CET}.. {294706800 7200 1 CEST}.. {307490400 3600 0 CET}.. {326156400 7200 1 CEST}.. {339458400 3600 0 CET}.. {357087600 7200 1 CEST}.. {370389600 3600 0 CET}.. {389142000 7200 1 CEST}.. {402444000 3600 0 CET}.. {419468400 7200 1 CEST}.. {433807200 3600 0 CET}.. {449622000 7200 1 CEST}.. {457480800 7200 0 CEST}.. {465354000 3600 0 CET}.. {481078800 7200 1 CEST}.. {496803600 3600 0 CET}.. {512528400 7200 1 C
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):189
                                                                                                                                                                                                            Entropy (8bit):4.906212162381389
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV+NM/LWXHAIgoq9NM/HARL/yQa3MPgJM1p8QagNMj:SlSWB9vsM3ymI6CHAIgoI6HAN/ytM4MO
                                                                                                                                                                                                            MD5:E0C99DB7673EEE440BA1848046455BA1
                                                                                                                                                                                                            SHA1:1BCCC1BE46306DEF8A9CA249DE8FA11FC57CC04D
                                                                                                                                                                                                            SHA-256:FDD53FDB5F754BBBA8FF98F0B1555FE0BAEB7852843220A7CF93A190B641A9AD
                                                                                                                                                                                                            SHA-512:CD56B540AE9084DEAA9D0A1DBBAF89733C465424C22CE74696B9AE90FD4FEFAB265CF23C5B13A7F04597D75FD0147BD593E0552B56D87372170CB4CA1BFC8259
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Chisinau)]} {.. LoadTimeZoneFile Europe/Chisinau..}..set TZData(:Europe/Tiraspol) $TZData(:Europe/Chisinau)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2119
                                                                                                                                                                                                            Entropy (8bit):3.680951255407528
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:kFvCAs6kKR6aQmF1cSNWrI+AjQndgV/Ap40FjDOP:khCAs6kC6aZF1cSN4I+AjQdgV/ApDFj4
                                                                                                                                                                                                            MD5:83C86E437B5FBA1DC9CC5235396AC381
                                                                                                                                                                                                            SHA1:5493A59C3A5A1B55ACD493E67F9E29D2A415A8DB
                                                                                                                                                                                                            SHA-256:9FA9D09509B4F8F5A9C8E422DBA02605070C3EBDAEB7C1DF8527C8EEF5E3632D
                                                                                                                                                                                                            SHA-512:86222489C65C87646939DECF91C2EC336EB46F64B644526A3FA8A4854B9D11819F6FD253107AB8A3DE911E254C88092D25137442164A6E437CDAF258A7CBB66C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Ulyanovsk) {.. {-9223372036854775808 11616 0 LMT}.. {-1593820800 10800 0 +03}.. {-1247540400 14400 0 +05}.. {354916800 18000 1 +05}.. {370724400 14400 0 +04}.. {386452800 18000 1 +05}.. {402260400 14400 0 +04}.. {417988800 18000 1 +05}.. {433796400 14400 0 +04}.. {449611200 18000 1 +05}.. {465343200 14400 0 +04}.. {481068000 18000 1 +05}.. {496792800 14400 0 +04}.. {512517600 18000 1 +05}.. {528242400 14400 0 +04}.. {543967200 18000 1 +05}.. {559692000 14400 0 +04}.. {575416800 18000 1 +05}.. {591141600 14400 0 +04}.. {606866400 10800 0 +04}.. {606870000 14400 1 +04}.. {622594800 10800 0 +03}.. {638319600 14400 1 +04}.. {654649200 10800 0 +03}.. {670374000 7200 0 +03}.. {670377600 10800 1 +03}.. {686102400 7200 0 +02}.. {695779200 10800 0 +04}.. {701823600 14400 1 +04}.. {717548400 10800 0 +03}.. {733273200 14400 1 +04}.. {748
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):177
                                                                                                                                                                                                            Entropy (8bit):5.051734481833866
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV2cvXHAIgoq1csFARL/yQa2rUQaocqn:SlSWB9vsM3ym5HAIgoiAN/yFC
                                                                                                                                                                                                            MD5:17A0CC51331756920B13FFA3FF556751
                                                                                                                                                                                                            SHA1:C575FEF4F053393C57B34C7C7B0C1E9605413792
                                                                                                                                                                                                            SHA-256:F8CAF5DBE12F1647B28E7CCDDB2E09E36788A766690D12E770A8ABD82E708644
                                                                                                                                                                                                            SHA-512:E73F0FE5BE4DD91948A88DC895E148D81267576BA3BCFEA777E25C01EAE9C06845DBFFB651526045B70B7A3CCDB195DFFF60486C01E0A115DFB856873970008E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Kyiv)]} {.. LoadTimeZoneFile Europe/Kyiv..}..set TZData(:Europe/Uzhgorod) $TZData(:Europe/Kyiv)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):180
                                                                                                                                                                                                            Entropy (8bit):4.953146873643623
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVnCMPfXHAIgoqkCM4ARL/yQa1NEHp8Qa5CMS:SlSWB9vsM3ym5XPHAIgo5gAN/yvNEJ8G
                                                                                                                                                                                                            MD5:A0BAEC8B6AF1589ECBE52667DDB2A153
                                                                                                                                                                                                            SHA1:37093F4F885CBFA90A1F136D082E8B7546244ACC
                                                                                                                                                                                                            SHA-256:06B235BF047FC2303102BC3DC609A5754A6103321D28440B74EEC1C9E3D24642
                                                                                                                                                                                                            SHA-512:DBEC235AFB413FA8D116FA1AFFE73706762E7458038B6D68E0BFD71C339510D766825BA97055A06DEE14D5880EAE6CD035BFE0C935C0DF44B0107A356D293A78
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Zurich)]} {.. LoadTimeZoneFile Europe/Zurich..}..set TZData(:Europe/Vaduz) $TZData(:Europe/Zurich)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):176
                                                                                                                                                                                                            Entropy (8bit):4.914414313741477
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVvjF3vXHAIgoqspvVHRL/yQa1xLM1p8QaxE:SlSWB9vsM3ymx5PHAIgoxvN/yvN+8rE
                                                                                                                                                                                                            MD5:2404265F8DE1F7D7745893DD4752BA1C
                                                                                                                                                                                                            SHA1:C07E7F72DBDC7F5F746385523EA733C2714F5DA2
                                                                                                                                                                                                            SHA-256:C203E94465BD1D91018FC7670437226EF9A4BB41D59DDE49095363865CA33D00
                                                                                                                                                                                                            SHA-512:5C20834542B74041AAB1DBE35686781B32EEB5814B1A35A942E87D1FC3B6D8F9264CB90433C44A480EA86DDEA65D8C152F41CE3E983C1DE5FA74D6FB5208F701
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Rome)]} {.. LoadTimeZoneFile Europe/Rome..}..set TZData(:Europe/Vatican) $TZData(:Europe/Rome)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7930
                                                                                                                                                                                                            Entropy (8bit):3.8193566380830273
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:8F6zq+gH74elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhltlUxo:8ozE41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                            MD5:6A3A8055DD67174E853C7A208BABAC9B
                                                                                                                                                                                                            SHA1:64445543DE9D6C01FA858442976E249E37BE23EF
                                                                                                                                                                                                            SHA-256:A8165313C9B51DAEF130401439CBA60DAA9887FC5EAA61A5AFD4F7BAD1AD934F
                                                                                                                                                                                                            SHA-512:4407B9E8709A8DD05337A10030895AA9876EAF64EF5347952249EE2A541E304331B46D38532FD7CDFF9E633BF8C9884282F0A5ED259EBA1D99DC0914AF1A50C6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Vienna) {.. {-9223372036854775808 3921 0 LMT}.. {-2422055121 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618700400 3600 0 CET}.. {-1577926800 3600 0 CET}.. {-1569711600 7200 1 CEST}.. {-1555801200 3600 0 CET}.. {-938905200 7200 0 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796777200 3600 0 CET}.. {-781052400 7200 1 CEST}.. {-780188400 3600 0 CET}.. {-757386000 3600 0 CET}.. {-748479600 7200 1 CEST}.. {-733273200 3600 0 CET}.. {-717634800 7200 1 CEST}.. {-701910000 3600 0 CET}.. {-684975600 7200 1 CEST}.. {-670460400 3600 0 CET}.. {323823600 7200 1 CEST}.. {338940000 3600 0 CET}.. {347151600 3600 0 CET}.. {354675600 7200 1 CEST}.. {370400400 3600 0 CE
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7485
                                                                                                                                                                                                            Entropy (8bit):3.7711709848169592
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:FAhEpkwCXkSV3A/PplKkUpvBeRF+iDlKSdkwSMTHkB2vwz59F06Kgr/y/rYjlBK0:FfWHUSKivBeRF+W35Syrwl9h5j
                                                                                                                                                                                                            MD5:1AB5FCEACC4E09074BA9F72F0B7747D5
                                                                                                                                                                                                            SHA1:E0134E61EC0ADC60BF6DB4544EA7B7FFA4EC7857
                                                                                                                                                                                                            SHA-256:B762DB4A068DC79FA57691E070D7026086E5A6D2FC273D5C1872E7C8E3711533
                                                                                                                                                                                                            SHA-512:07565071D05CF972DD64F6060599EB68A00BF264172873BA310168AD07CE0CFCF90D0019B775433EC910DA748B89F0C614E7FD4E821993DA53C7E33F194C6A97
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Vilnius) {.. {-9223372036854775808 6076 0 LMT}.. {-2840146876 5040 0 WMT}.. {-1672536240 5736 0 KMT}.. {-1585100136 3600 0 CET}.. {-1561251600 7200 0 EET}.. {-1553565600 3600 0 CET}.. {-928198800 10800 0 MSK}.. {-900126000 3600 0 CET}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-802141200 10800 0 MSD}.. {354920400 14400 1 MSD}.. {370728000 10800 0 MSK}.. {386456400 14400 1 MSD}.. {402264000 10800 0 MSK}.. {417992400 14400 1 MSD}.. {433800000 10800 0 MSK}.. {449614800 14400 1 MSD}.. {465346800 10800 0 MSK}.. {481071600 14400 1 MSD}.. {496796400 10800 0 MSK}.. {512521200 14400 1 MSD}.. {528246000 10800 0 MSK}.. {543970800 14400 1 MSD}.. {559695600 10800 0 MSK}.. {575420400 14400 1 MSD}.. {591145200 10800 0 MSK}.. {606870000 7200 0 EEMMTT}.. {606873600 10800 1 EEST}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2123
                                                                                                                                                                                                            Entropy (8bit):3.667144931158014
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:menvCAs6kKR6aQmF1cSNWJjXgV/Ap40FjDqR:mevCAs6kC6aZF1cSNcjXgV/ApDFjDqR
                                                                                                                                                                                                            MD5:53E5BA5747B3255BB049F6FF651CEE25
                                                                                                                                                                                                            SHA1:A69E2BFDB89AC8756E1CD2EAA9109ACD924A0850
                                                                                                                                                                                                            SHA-256:22968D40DAC2B669E6D2BC43ED6B16C8A9CA3E1F9DACBF8B246299C3C24CC397
                                                                                                                                                                                                            SHA-512:3269D20DF9C9DDFF8252F33ED563B118771FC71049542DA7C6678E0B5B75FFEA00845FA6F3BC26EDABB4BB7CE449B0B7E00B72473D8D95F126AB3893A9A969B4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Volgograd) {.. {-9223372036854775808 10660 0 LMT}.. {-1577761060 10800 0 +03}.. {-1247540400 14400 0 +04}.. {-256881600 14400 0 +05}.. {354916800 18000 1 +05}.. {370724400 14400 0 +04}.. {386452800 18000 1 +05}.. {402260400 14400 0 +04}.. {417988800 18000 1 +05}.. {433796400 14400 0 +04}.. {449611200 18000 1 +05}.. {465343200 14400 0 +04}.. {481068000 18000 1 +05}.. {496792800 14400 0 +04}.. {512517600 18000 1 +05}.. {528242400 14400 0 +04}.. {543967200 18000 1 +05}.. {559692000 14400 0 +04}.. {575416800 10800 0 +04}.. {575420400 14400 1 +04}.. {591145200 10800 0 +03}.. {606870000 14400 1 +04}.. {622594800 10800 0 +03}.. {638319600 14400 1 +04}.. {654649200 10800 0 +03}.. {670374000 14400 0 +04}.. {701820000 10800 0 +04}.. {701823600 14400 1 +04}.. {717548400 10800 0 +03}.. {733273200 14400 1 +04}.. {748998000 10800 0 +03}.. {
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8662
                                                                                                                                                                                                            Entropy (8bit):3.8187545871488995
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:ELn9M9Nivtctwwoy4qelPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCso:E6Nivtctgq1sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                            MD5:992C1D268E336AF1FB8200966C111644
                                                                                                                                                                                                            SHA1:C893B82224C8EF282DB2E16A5BBCC3A21C49B6FE
                                                                                                                                                                                                            SHA-256:F9DC10EC2AE2CC810A6C08837059B34BE651900BA4E1CEDB93C209972CCFB5A2
                                                                                                                                                                                                            SHA-512:EC4E0D8684D57FA66144F11D8E8C80E5272D4A7304300FEBE20E236476C1B8B33BBC5E479BF96D9ED12900FE6D41DD1DC0D11CBE02B89E0C4C7A153B4BFBCB1F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Warsaw) {.. {-9223372036854775808 5040 0 LMT}.. {-2840145840 5040 0 WMT}.. {-1717032240 3600 0 CET}.. {-1693706400 7200 1 CEST}.. {-1680483600 3600 0 CET}.. {-1663455600 7200 1 CEST}.. {-1650150000 3600 0 CET}.. {-1632006000 7200 1 CEST}.. {-1618696800 7200 0 EET}.. {-1600473600 10800 1 EEST}.. {-1587168000 7200 0 EET}.. {-931734000 7200 0 CEST}.. {-857257200 3600 0 CET}.. {-844556400 7200 1 CEST}.. {-828226800 3600 0 CET}.. {-812502000 7200 1 CEST}.. {-796870800 7200 0 CEST}.. {-796608000 3600 0 CET}.. {-778726800 7200 1 CEST}.. {-762660000 3600 0 CET}.. {-748486800 7200 1 CEST}.. {-733273200 3600 0 CET}.. {-715215600 7200 1 CEST}.. {-701910000 3600 0 CET}.. {-684975600 7200 1 CEST}.. {-670460400 3600 0 CET}.. {-654130800 7200 1 CEST}.. {-639010800 3600 0 CET}.. {-397094400 7200 1 CEST}.. {-386812800 3600 0 CET}.. {-371088000 72
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):187
                                                                                                                                                                                                            Entropy (8bit):4.899266605519742
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV/sUE2tovXHAIgoq8sUE2oAovRL/yQa5rXv1/h8Q0:SlSWB9vsM3ymhrE2tSHAIgohrE2LovNB
                                                                                                                                                                                                            MD5:B07D9D3A5B0D11A578F77995A5FBE12B
                                                                                                                                                                                                            SHA1:1C4E186F2D53C0A1E6A82A6D33B172E403A41D6D
                                                                                                                                                                                                            SHA-256:A49B3894EB84F003EB357647D6A40CEAF6213523196CC1EC24EEFD7D9D6D3C3E
                                                                                                                                                                                                            SHA-512:43520AE325980B236C47C866620D1DA200AC0CD794E8EB642D2936D4B0ECEFE2DA0A93C9559D08581B3CCE2BC75251A4D5B967D376B16EB0C042B0ADCE1DCD01
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Belgrade)]} {.. LoadTimeZoneFile Europe/Belgrade..}..set TZData(:Europe/Zagreb) $TZData(:Europe/Belgrade)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):179
                                                                                                                                                                                                            Entropy (8bit):4.999265802825238
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV2cvXHAIgoq1csFARL/yQa58KXkcAEfh8Qaocqn:SlSWB9vsM3ym5HAIgoiAN/yjzVbh8C
                                                                                                                                                                                                            MD5:5B150E25521FE5DD8B83DD9B1B8F3A7A
                                                                                                                                                                                                            SHA1:0BB6F73F2C4B2464F3B1E62138843389AF1A07BC
                                                                                                                                                                                                            SHA-256:EF928AC09B9A366FD015F488B6A19FEFD72DE1BAF34E5CADFB8334946BCF19FE
                                                                                                                                                                                                            SHA-512:4A85A4E929EC6FE66AE60899FA55A75156D075CB2FE41C19337A128F5FA7363B9208AC2DC1BF4E44B76D5F115143D73F6D923E255EA78538D1BE4E45DEBA2049
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Kyiv)]} {.. LoadTimeZoneFile Europe/Kyiv..}..set TZData(:Europe/Zaporozhye) $TZData(:Europe/Kyiv)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7305
                                                                                                                                                                                                            Entropy (8bit):3.8199799674700277
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:94hH74elPiIEtzsFpMbFNBwA3ybuNTjrjBDmE0DmiTcoYdNOMCsyZhltlUxOrnW+:9Y41sFpM5vwA6Efv03TBZLl
                                                                                                                                                                                                            MD5:EBD66FAEA63E1B90122CC1EB21634ECE
                                                                                                                                                                                                            SHA1:C6487BB8AB2A6A72B2170B220F383ADB6B9AC91C
                                                                                                                                                                                                            SHA-256:95AFA61E439CA38551306D8FDB11C2788D935C42768D0407C9E4337F105A3E93
                                                                                                                                                                                                            SHA-512:25A8D0ED9BBE6BF23A1A76CC6D5378CF4D50544AA22DA97DDCD0673D7A5CCFEFFD81B660A1AEFB254B8BBEA55F6EF734BBBD3F0CB903E0721BE107667CA1E328
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Europe/Zurich) {.. {-9223372036854775808 2048 0 LMT}.. {-3675198848 1786 0 BMT}.. {-2385246586 3600 0 CET}.. {-904435200 7200 1 CEST}.. {-891129600 3600 0 CET}.. {-872985600 7200 1 CEST}.. {-859680000 3600 0 CET}.. {347151600 3600 0 CET}.. {354675600 7200 1 CEST}.. {370400400 3600 0 CET}.. {386125200 7200 1 CEST}.. {401850000 3600 0 CET}.. {417574800 7200 1 CEST}.. {433299600 3600 0 CET}.. {449024400 7200 1 CEST}.. {465354000 3600 0 CET}.. {481078800 7200 1 CEST}.. {496803600 3600 0 CET}.. {512528400 7200 1 CEST}.. {528253200 3600 0 CET}.. {543978000 7200 1 CEST}.. {559702800 3600 0 CET}.. {575427600 7200 1 CEST}.. {591152400 3600 0 CET}.. {606877200 7200 1 CEST}.. {622602000 3600 0 CET}.. {638326800 7200 1 CEST}.. {654656400 3600 0 CET}.. {670381200 7200 1 CEST}.. {686106000 3600 0 CET}.. {701830800 7200 1 CEST}.. {717555600 3600 0
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):170
                                                                                                                                                                                                            Entropy (8bit):4.8978035005721265
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVxKL823vXHAIgoqyKL8H6RL/wox6QavKL81n:SlSWB9vsM3ymvKA2PHAIgovKAH6N/wRj
                                                                                                                                                                                                            MD5:68667037110E713DB3F51922DDE929FE
                                                                                                                                                                                                            SHA1:2EB02BE3FD35F105B59847892A78F1AA21754541
                                                                                                                                                                                                            SHA-256:E20D829C605A7C5B2A96B83C3480DF28C964A13381A8BD2C72C2A37295131FA7
                                                                                                                                                                                                            SHA-512:3A8CC2EC9E3053283F996CA2C4B422061D47F1D16CA07985CBA2C838DF322C23CC9DD28033646F22EAE0E401781480B9D3AF82A539444166A4DD9B7BCCAE45FE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/London)]} {.. LoadTimeZoneFile Europe/London..}..set TZData(:GB) $TZData(:Europe/London)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):175
                                                                                                                                                                                                            Entropy (8bit):4.90874180513438
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVxKL823vXHAIgoqyKL8H6RL/w4b/h8QavKL81n:SlSWB9vsM3ymvKA2PHAIgovKAH6N/w4E
                                                                                                                                                                                                            MD5:625520BAAB774520AC54BFB9EDCF9FCA
                                                                                                                                                                                                            SHA1:C72F0FD45F448901C6B2E24243175729591B9A54
                                                                                                                                                                                                            SHA-256:C9334480D0A970254B6BA6FF22E958DC8DD8BF06288229461A551C7C094C3F1D
                                                                                                                                                                                                            SHA-512:1B672218FF9C86168E065A98C3B5F67DAB710D1C2A319E9D6599B397C4B4C00D3721B76C735C8AB04BCB618C1832B07F6CCDAF4266CC0D12A461A3A862D1AEB2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/London)]} {.. LoadTimeZoneFile Europe/London..}..set TZData(:GB-Eire) $TZData(:Europe/London)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):153
                                                                                                                                                                                                            Entropy (8bit):4.867609984313873
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqSsM4DovXHAIgexovYovHRL/wZ8RDMovn:SlSWB9vsM3yFXHAIgnvVHN/wZ8RQy
                                                                                                                                                                                                            MD5:A01FE6FC260711F0E11C85DC3DE3550A
                                                                                                                                                                                                            SHA1:988311B71498591425C63669DC3F802F270B2C44
                                                                                                                                                                                                            SHA-256:747C15CDC239855D5380B7A7F47112F2A26C61B0BF300EEB9711E6521550D189
                                                                                                                                                                                                            SHA-512:BE4678DCBAE5DBC72865665413206C1909F28BA54F4943257870EFFBA6525457866DED7A985E89F2689C810B314DE4AA2FA3A0A1826A664727F5F7113AA56595
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:GMT) $TZData(:Etc/GMT)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):155
                                                                                                                                                                                                            Entropy (8bit):4.917182390229381
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqSsM4DovXHAIgexovYovHRL/we7/8RDMovn:SlSWB9vsM3yFXHAIgnvVHN/wI8RQy
                                                                                                                                                                                                            MD5:3327B1BF3118AC6AFC02C31DF5B67CD9
                                                                                                                                                                                                            SHA1:3932577E66801AD31519B0BB56CCE7B9E36221A9
                                                                                                                                                                                                            SHA-256:BE48462CCFBB3AEE19597F082A17C2C5D2FD8BB1C9122245EFAB0A51F8F413B0
                                                                                                                                                                                                            SHA-512:53866FD513B039E8203E51FF3434D5736D3A4C4E0A46874D1C99A17115181AF749F0D079C2E14C5B0538D3DFA52B1645C977CD6599DA3EDA57CC7F84EEAB2D06
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:GMT+0) $TZData(:Etc/GMT)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):155
                                                                                                                                                                                                            Entropy (8bit):4.904279164422928
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqSsM4DovXHAIgexovYovHRL/w4Hp8RDMovn:SlSWB9vsM3yFXHAIgnvVHN/w4J8RQy
                                                                                                                                                                                                            MD5:0CFFC5655F031D954BD623CC4C74DC9C
                                                                                                                                                                                                            SHA1:CE5E7AD67252F52D7E70719725FF5BE393DD6EF0
                                                                                                                                                                                                            SHA-256:944C86F516141DDC3AEC1AE4A963E9769879C48ED12DADDF4ED63A01313ACD00
                                                                                                                                                                                                            SHA-512:C7352D1394E8B8AC90CD19EE753D5277259BE5512ADDCAED2A2DEF144762CF20BE7A9FA09AAA1829EE401DD195C2AED8C967A7FF46739236E042AF4298EC84A2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:GMT-0) $TZData(:Etc/GMT)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):154
                                                                                                                                                                                                            Entropy (8bit):4.892526720357546
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqSsM4DovXHAIgexovYovHRL/wPHp8RDMovn:SlSWB9vsM3yFXHAIgnvVHN/wvp8RQy
                                                                                                                                                                                                            MD5:565B41A5DB28F9FE7D220E9BA39062A4
                                                                                                                                                                                                            SHA1:5183689210F07C8A71F880DCE8E5C2CB62CEB17D
                                                                                                                                                                                                            SHA-256:54850A5F488205DB01FBB46E2DA9FFF951C4571029EA64D35932DDEA5346DAAF
                                                                                                                                                                                                            SHA-512:BD6E5141F06B03D62DCF725E9E48D6AA8ECD6E8E47A4015B25DC3F672392065FFFD80D688C6695324DC105EA528025CF447FA77E6D17E15D438E61DC51879CB7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:GMT0) $TZData(:Etc/GMT)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):159
                                                                                                                                                                                                            Entropy (8bit):4.917976058206477
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqSsM4DovXHAIgexovYovHRL/wE+FB5yRDMovn:SlSWB9vsM3yFXHAIgnvVHN/wE6BURQy
                                                                                                                                                                                                            MD5:443FA76F107ED438F9571A044B848C6A
                                                                                                                                                                                                            SHA1:1CF508429DFC40643B1FAB336A249A3A287D8C7C
                                                                                                                                                                                                            SHA-256:9E7A8DAA26CE36E8F7D7F13460915C063EE98E2A4DB276AD9D15CA5C7C06815F
                                                                                                                                                                                                            SHA-512:6C0C5FF513A742FBDA349AC3A2581D456701B5348A54ECF38E496DAA1EFC74D937982B6F69F1761CC2FC4B88D9A971EFA2B16096E71EAF002EC5CE4130B533DE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/GMT)]} {.. LoadTimeZoneFile Etc/GMT..}..set TZData(:Greenwich) $TZData(:Etc/GMT)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):111
                                                                                                                                                                                                            Entropy (8bit):4.90682088010982
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x//LhdNMXGm2OH1V90v:SlSWB9eg/jJDm2OH1VGv
                                                                                                                                                                                                            MD5:79C82A5F8B034E71D0582371E3218DBB
                                                                                                                                                                                                            SHA1:1476CE8EA223095094B6D25D171E6319C96669F4
                                                                                                                                                                                                            SHA-256:8D710699AF319E0DDB83E9F3A32D07AE8082EA2F7EABBD345EFFFFB0F563062E
                                                                                                                                                                                                            SHA-512:ADEE55581D1A158929F09A63B03883ABE9193337DDF225C61AFDBB8A2C7D0BD248ADC4714E0EEFD334826C54C1AFFC8B1E6C2B0D6EF830C3CCA50CC79834F473
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:HST) {.. {-9223372036854775808 -36000 0 HST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):179
                                                                                                                                                                                                            Entropy (8bit):4.913328649996328
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8Li0vXHAIgN2qfvRL//XF1p4WFKQyvn:SlSWB9vsM3yW2HAIgAOvN///p4wKlvn
                                                                                                                                                                                                            MD5:6A307B229C302B1BAE783C8143809269
                                                                                                                                                                                                            SHA1:EA169AF81AD12380A69FB6B7A12479BA8B82878B
                                                                                                                                                                                                            SHA-256:359C9C02A9FA3DE10BA48FA0AB47D8D7AFF3B47F950CFAF5EB68F842EA52AB21
                                                                                                                                                                                                            SHA-512:505445FD0B3E140384EDC27993923BBF9ACD23A244B0F14D58804BFAA946D0BC4C0D301FBCCB492BAFDA42C8A92F4163FB96F4D75DD7374858D1C66183BEC24B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Hong_Kong)]} {.. LoadTimeZoneFile Asia/Hong_Kong..}..set TZData(:Hongkong) $TZData(:Asia/Hong_Kong)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):178
                                                                                                                                                                                                            Entropy (8bit):4.853280551555672
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqss1kovXHAIgNGE4pHRL/+GAKyx/2DcsS:SlSWB9vsM3y7s3HAIgNT4pHN/+XZx+D4
                                                                                                                                                                                                            MD5:710D3A32EA8EAD11B45D4911DA8F2676
                                                                                                                                                                                                            SHA1:146D2A6D48940E58567EFA3BCA134D195E4649E6
                                                                                                                                                                                                            SHA-256:8A531293F672D8FE38996989FC4EEB22B5EFE6E046E2F58E94D01DA9CE56EF68
                                                                                                                                                                                                            SHA-512:70432973549C1A83036E0658AEE81C883F19D0D631E35F4C70F2EC69C9384E99340004618EF8B414D8EA9090C6C3120CF46A5D9ABDE4113917995B2844337988
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Abidjan)]} {.. LoadTimeZoneFile Africa/Abidjan..}..set TZData(:Iceland) $TZData(:Africa/Abidjan)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):190
                                                                                                                                                                                                            Entropy (8bit):4.807410166086502
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/+L6EL/liEi2eDcVVMB:SlSWB9vsM3y7VTHAIgNTxcAN/+LzM2eV
                                                                                                                                                                                                            MD5:0F20CBF1F7600D05F85D4D90FDAB2465
                                                                                                                                                                                                            SHA1:2F3C9479C4F4CD7999B19C07359B89A5FB1B9839
                                                                                                                                                                                                            SHA-256:1B1177CE4D59D7CBCAE9B0421EB00AD341ECB299BD15773D4ED077F0F2CE7B38
                                                                                                                                                                                                            SHA-512:657341FC2CCD6A4F7B405ABC8E24C651F6FFEFD68EBD6E2086ADF44834DCBF21D1B9D414436E42C8DCE46FFB88116B98C1D073782E214B3996D49EC00DFF4383
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Indian/Antananarivo) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):180
                                                                                                                                                                                                            Entropy (8bit):4.853088038233057
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/+L6EL9WJx3vFNMXGm2OHi/FvoHscfJ7XH0VQVFV6VVFSTVV:SlSWB9eg/+LxWJxPDm2OHqFvoH9+VQV3
                                                                                                                                                                                                            MD5:06143C3DFD86B3FE4F2A3060C0E05BB6
                                                                                                                                                                                                            SHA1:88E0E30CEE4AB8117860A35AD03B16AF48988789
                                                                                                                                                                                                            SHA-256:11044AD7CB0848CC734D2A67128AA6AC07CB89268399AA0A71A99024DE4B8879
                                                                                                                                                                                                            SHA-512:79195D3D0D475BEA982F40683D4BA14AC33B3FA91311F513DCED955C9297C2B0F12D94CCA930FAE0FB7F95DB34CD4E74B5AF0233E792122646592B7EFF0F3163
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Indian/Chagos) {.. {-9223372036854775808 17380 0 LMT}.. {-1988167780 18000 0 +05}.. {820436400 21600 0 +06}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):181
                                                                                                                                                                                                            Entropy (8bit):4.910217468889087
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8VLYO5YFfXHAIgN8ELYOJARL/+L6EL9FBIEWoxp4Wx:SlSWB9vsM3y1LePHAIgKELtAN/+LxpWg
                                                                                                                                                                                                            MD5:39CB9E58C0086B80FB12AC10A6D371E2
                                                                                                                                                                                                            SHA1:2A9A5CCA411779615A62D9E82023B6A066CB3CF3
                                                                                                                                                                                                            SHA-256:78A208B73426A1B6D7CF2FE89A0EF3F01721F877D569BC43F2E5B6625A947299
                                                                                                                                                                                                            SHA-512:BB6C8CF2B6AF9F93A7F7382A453261FA43E6E42E9ED1223F25A70DAD2ABBBF2F5777288553F4BC0155944754655D2C3F81BD81E5B1F611C4B2CCDB729B67AAC5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Bangkok)]} {.. LoadTimeZoneFile Asia/Bangkok..}..set TZData(:Indian/Christmas) $TZData(:Asia/Bangkok)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):174
                                                                                                                                                                                                            Entropy (8bit):4.818886812441817
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8nv3vXHAIgNnDA6RL/+L6EL9dEh4WFKsyn:SlSWB9vsM3yHvPHAIg15N/+Lxah4wKsy
                                                                                                                                                                                                            MD5:9462E9CFC88C3DA3CCCDA18C92E49A97
                                                                                                                                                                                                            SHA1:B50C82C6C7361BD6F028F82E2FEAF8486D798137
                                                                                                                                                                                                            SHA-256:EB301EE97A9FDE8ACE0243941C0FAC9ED0E3ACFD6497ABE408F08E95FAE3B732
                                                                                                                                                                                                            SHA-512:A48EBDA0A93C3505BC6149863F4A7B1043F856A8EB516CF42C050A95E81CD152BC1C0313B3DD115D53DABA95413AF34902D7D11C984DE5A03FC5FFADAF8EA89F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Yangon)]} {.. LoadTimeZoneFile Asia/Yangon..}..set TZData(:Indian/Cocos) $TZData(:Asia/Yangon)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):184
                                                                                                                                                                                                            Entropy (8bit):4.825881690094318
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/+L6EL9TKlBx+DcVVMB:SlSWB9vsM3y7VTHAIgNTxcAN/+LxGV+V
                                                                                                                                                                                                            MD5:7EBDFA311C7852AFADF880395071DE48
                                                                                                                                                                                                            SHA1:F6EC21FDFB75EC1BE45B1C4170147CBA3E870E7B
                                                                                                                                                                                                            SHA-256:53FA58E32DC2E4ABB574B2F78011815EEB7F89F453CC63C6B6C1460ABBB4CA5C
                                                                                                                                                                                                            SHA-512:DFBCD4EA4AFFA1D1CAE7308168874527FD36B5CAE76153AADA9C5E5F628258AB26654A16C8A5F8906FC5918398FD880B15B6DD4E3EF6AD3BE63D4A2455701FA8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Indian/Comoro) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):190
                                                                                                                                                                                                            Entropy (8bit):4.822075418239496
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqKGE4YF3vXHAIgnGED9HRL/+L6EL12h6hwL6ELzEov:SlSWB9vsM3ypGEVFPHAIgnGEtN/+L5Ry
                                                                                                                                                                                                            MD5:9AB222C67E079B55DDF3ACAE67BD0261
                                                                                                                                                                                                            SHA1:F9E6C34A00F9F1B152CEA729F087BD24993CA2E8
                                                                                                                                                                                                            SHA-256:138C7FFBFC520372658CA0CD1B42C4E5A240E9D9B98A277B02481DE5701222FC
                                                                                                                                                                                                            SHA-512:5F3EFF78506056F981DB0446436B39953D90265227890176D8287E2149B176B9DCCA14E795083B1EBC202D02AA88D584A9BB49868F30895EF17E92AA98ACB7C7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Indian/Maldives)]} {.. LoadTimeZoneFile Indian/Maldives..}..set TZData(:Indian/Kerguelen) $TZData(:Indian/Maldives)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):170
                                                                                                                                                                                                            Entropy (8bit):4.84472938642971
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8DeXHAIgN6S7ARL/+L6ELzJM1h4WFKQ3n:SlSWB9vsM3yj+HAIgMS7AN/+L/Yh4wKC
                                                                                                                                                                                                            MD5:C866B2A879786B7D9341FA904FC7D01A
                                                                                                                                                                                                            SHA1:DAF7B405E6DAA0C88C6F3A26AAA172E38CE5CAF3
                                                                                                                                                                                                            SHA-256:613C5C05A8867E4B59A97A3D8C7235DDC0CA23239F2D57A5BFD42E4AB94FD510
                                                                                                                                                                                                            SHA-512:BB01A464366F1F93591F48C42F300421AF774E50E5B5232AB0C755482E3306EDDB54A9BCF6E9D325EAE63AAC6D3857F4D754FC28A34F90AC728B7158B61E2C57
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Dubai)]} {.. LoadTimeZoneFile Asia/Dubai..}..set TZData(:Indian/Mahe) $TZData(:Asia/Dubai)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):183
                                                                                                                                                                                                            Entropy (8bit):4.883092265054605
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/+L6ELzE5FNMXGm2OHnz8eoHvZT5lxV/uUQwGN0VQVFv:SlSWB9eg/+L/EJDm2OHnz8eoHvZT5rdI
                                                                                                                                                                                                            MD5:4DF975C040D78FA8F9C92E5565D63A73
                                                                                                                                                                                                            SHA1:48488F076871530D32278084F1C9CB90CB1E6AB4
                                                                                                                                                                                                            SHA-256:9FAC69DC609CC6074ECD67E0BE8AE62E33D8D9C7F055A3E0DEE1430C7FFC54F6
                                                                                                                                                                                                            SHA-512:880B920FB51F48731BA8C741B9583038A3276221C55F1CE0B464D2797D71EF9D22B4E166841BAB0544B7091CE683697BFCA5A4235FF1E6264B0619DBDD4BB619
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Indian/Maldives) {.. {-9223372036854775808 17640 0 LMT}.. {-2840158440 17640 0 MMT}.. {-315636840 18000 0 +05}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):272
                                                                                                                                                                                                            Entropy (8bit):4.5144164346164715
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/+L/GDm2OHlNnoH9SvulvSNFF+c0FSFFMVhvSNFFVBjvVFSFFVGlvSN:MB86+L/CmdHlNnCy6qB0FScZq9BjVFSL
                                                                                                                                                                                                            MD5:05362B6A17C5F4F4E8CBE5A676D5D0DE
                                                                                                                                                                                                            SHA1:84675D5E8D1425A5E9DB07D1BC1E6A5921B5AC91
                                                                                                                                                                                                            SHA-256:A2B1B93CBEECBD900ED71E61A4932509EB52688E97A6015DAD067066D0D42072
                                                                                                                                                                                                            SHA-512:351D2BC5F5888D8E842BF160D11D57E059811186D63B0413061768C7FE348CECB700748A0C0125F0ABCBB039FC74FF7BEEFDD42088BA1E28C785E545ED2CDF24
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Indian/Mauritius) {.. {-9223372036854775808 13800 0 LMT}.. {-1988164200 14400 0 +04}.. {403041600 18000 1 +04}.. {417034800 14400 0 +04}.. {1224972000 18000 1 +04}.. {1238274000 14400 0 +04}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):185
                                                                                                                                                                                                            Entropy (8bit):4.828945679595274
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsVVMMvfXHAIgNGExVMeWARL/+L6ELzO1h4DcVVMMyn:SlSWB9vsM3y7VTHAIgNTxcAN/+L/O1hm
                                                                                                                                                                                                            MD5:8ABBEC0E138C1A68CB5D096E822DE75E
                                                                                                                                                                                                            SHA1:E9C5CE1A249F6DC0F6EDBB3F5B00F3106E3BD6CA
                                                                                                                                                                                                            SHA-256:845C45FD7B6F0604B03A3C72DB117878B568FB537BCA078304727964157B96AB
                                                                                                                                                                                                            SHA-512:15790CCA70140D3139F3E2A202DC8F12E68466A367C68458D6A78CDDC7822FB5EDB87D630926B51F3DE48D95DE7CA3FCB946CD7B762FE5B15866DAA9DBA40B46
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Nairobi)]} {.. LoadTimeZoneFile Africa/Nairobi..}..set TZData(:Indian/Mayotte) $TZData(:Africa/Nairobi)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):173
                                                                                                                                                                                                            Entropy (8bit):4.825214661273383
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8DeXHAIgN6S7ARL/+L6ELsAceh4WFKQ3n:SlSWB9vsM3yj+HAIgMS7AN/+Lj4wKQ3
                                                                                                                                                                                                            MD5:7B22FE05231A5721C939B6018F8A2814
                                                                                                                                                                                                            SHA1:E272C25E79ABE705B2DB106D70DEAB3245EA9D35
                                                                                                                                                                                                            SHA-256:5560B0D4A2D8A13D9FE9787FFFE31200D405A8C875F046C8FDDF850AF98662B6
                                                                                                                                                                                                            SHA-512:26244855D029151B84A4D57E2FA69632B4F19F8C00B2E500A394D76A29857BE2A412344794BA0DFF50A2863FF17889210A151D0E231A67E55091F4909EC4AE79
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Dubai)]} {.. LoadTimeZoneFile Asia/Dubai..}..set TZData(:Indian/Reunion) $TZData(:Asia/Dubai)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):166
                                                                                                                                                                                                            Entropy (8bit):4.809541513808179
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8g5YFeovXHAIgNqjyVHRL/+XiMr4WFKBpv:SlSWB9vsM3yA5oPHAIgcjeHN/+Xvr4wY
                                                                                                                                                                                                            MD5:A90C26358FEF60E49044E3BE02866FAC
                                                                                                                                                                                                            SHA1:137AC8CCA23F39E7A16C4050EA9A3A8731E9AAD7
                                                                                                                                                                                                            SHA-256:FE7F4453CB5F6B81B23C1C795356B91FE319F0762BE7868FAFE361DB1F9C2A2B
                                                                                                                                                                                                            SHA-512:D6C74CACF69D29E14CB46E5DD885234AC50EE2E258E0C5E3AC76465061622F064F974D33E91A6A020B9D618D90799DDA6EB1EA53022EDB6E26A9CB6ADFE0AA30
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Tehran)]} {.. LoadTimeZoneFile Asia/Tehran..}..set TZData(:Iran) $TZData(:Asia/Tehran)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):177
                                                                                                                                                                                                            Entropy (8bit):4.8290104377288925
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq85zFFfXHAIgN0AzFFVHRL/+WXnMr4WFKYzFgn:SlSWB9vsM3yZbPHAIgCAXRN/+zr4wKY+
                                                                                                                                                                                                            MD5:6BCC43951637D86ED54585BE0819E39C
                                                                                                                                                                                                            SHA1:6F04F306B3AB2A6419377294238B3164F86EF4A3
                                                                                                                                                                                                            SHA-256:805105F5F17B78929F8476BAE83ED972128633FF6F74B7748B063E3C810C27A6
                                                                                                                                                                                                            SHA-512:ABB9F4308BF4BD5C62C215A7ECD95042CBFB3005AF1E75F640962B022574C930DD5A12CD0CE0AF8A3D7E38B999E37C3A45A55091683F6A87E9D0CDA9EE417293
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Jerusalem)]} {.. LoadTimeZoneFile Asia/Jerusalem..}..set TZData(:Israel) $TZData(:Asia/Jerusalem)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):181
                                                                                                                                                                                                            Entropy (8bit):4.722012123002917
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx00EIECWXHAIg200EIE/vHRL/9S//2IAcGE0EIESvn:SlSWB9vsM3y795VHAIgp95HN/029095c
                                                                                                                                                                                                            MD5:1F020341AD51AA82794B8018F214DE0D
                                                                                                                                                                                                            SHA1:4414E56C1277B4D31FE557F8652D522C0594F4B2
                                                                                                                                                                                                            SHA-256:F01B00D52BD7B2694BF5CB55A17028C30A41BD22A774CA54740E8B1DDE4FCB2E
                                                                                                                                                                                                            SHA-512:CC41848A851D4992AE9F27C38669CB87CE2FD05A33AB6989EA21AFCB1A2707DE0CB4D62BCC45E536DD944859991D7564847205F47509A42D41932370496A77D7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Jamaica)]} {.. LoadTimeZoneFile America/Jamaica..}..set TZData(:Jamaica) $TZData(:America/Jamaica)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):164
                                                                                                                                                                                                            Entropy (8bit):4.8422204749795545
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8aofXHAIgNqsRL/9hM7/4WFK9vn:SlSWB9vsM3ypPHAIgcsN/4r4wKNn
                                                                                                                                                                                                            MD5:9554A65BFFCFFCFB2C1588569BB4638E
                                                                                                                                                                                                            SHA1:B377ECB04586396D37093856AEF8BBDC93192F66
                                                                                                                                                                                                            SHA-256:98DBD07AE3B9251B9091F4D265336CE98BDFB492AF863C1F3FF25248A2CADF35
                                                                                                                                                                                                            SHA-512:E2E761B8B1995B68721BC714A546E0F45EEC025FAF81DE579FF0D73D37783D0E031B9E78BA2FAC6B097E3673C47AFB8761FBC58E42E33018FD44B77F2871E0C6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Tokyo)]} {.. LoadTimeZoneFile Asia/Tokyo..}..set TZData(:Japan) $TZData(:Asia/Tokyo)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):189
                                                                                                                                                                                                            Entropy (8bit):4.810216093939366
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQG1/EOM23vXHAIgObT1/EOMH6RL/8/FMKpUDH1/Ex:SlSWB9vsM3yc1EiPHAIgOb1E+N/8xMEx
                                                                                                                                                                                                            MD5:05C0C40F2AA456F580EAAFC4F7E49B56
                                                                                                                                                                                                            SHA1:5796A9122693B2D6010BC5E617A6091F46330B0C
                                                                                                                                                                                                            SHA-256:85E95363ACF468043CD5146927A97B2D9E3B141EDA0A7993DADA9382D1D6DD54
                                                                                                                                                                                                            SHA-512:2155F8E3EB73312F0AFD5CDDF4B19EBB67A15658101870C2CEDF96955470DBC7B30F34E143D9C14CBFA7A138F63324009581BD0B807AE295C68588CA0470D7AD
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Kwajalein)]} {.. LoadTimeZoneFile Pacific/Kwajalein..}..set TZData(:Kwajalein) $TZData(:Pacific/Kwajalein)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):176
                                                                                                                                                                                                            Entropy (8bit):4.829980800076139
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqsbKJqYkyXHAIgNGEnKJp0ARL/7beDcbKJ6v:SlSWB9vsM3y7JSHAIgNTxAN/PeDE
                                                                                                                                                                                                            MD5:4D44D88336212E162CCEFADE6321EDBC
                                                                                                                                                                                                            SHA1:B9EE7AFE26DC61AA9EA37EB99A3C10DD176E8063
                                                                                                                                                                                                            SHA-256:F776839C1999056E6A0D2ECFDF9054FC309454AFDFF8E8BC803F33EC423B7361
                                                                                                                                                                                                            SHA-512:FDDCBD194DE07B51DEBBDEF4FD96762EE3507117443FB9F7975FB56E0AE97B0D1F8657FE26B092021FB12B5A5D3EFFAB9E0A54B1C2AFCEC1029855442A0A95AB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Africa/Tripoli)]} {.. LoadTimeZoneFile Africa/Tripoli..}..set TZData(:Libya) $TZData(:Africa/Tripoli)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7736
                                                                                                                                                                                                            Entropy (8bit):3.799706947156251
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:aJCP8D3pCS2JWk55EyqJNSPTub3NDOyFyJYVtLbTxdqs0xcQVq+O7JSAmwQZjltB:FSyWBSPTujlOyqc3JuzVNvTN
                                                                                                                                                                                                            MD5:02B993B4A6956014A2DB844E8A5498C0
                                                                                                                                                                                                            SHA1:378333547254AC43BEB4FA2CBC24B8DE241B3078
                                                                                                                                                                                                            SHA-256:DF45F5414F1636B1856C7534BB5F3D4387C32D56283A68BB47D8C48C1DDAD5BC
                                                                                                                                                                                                            SHA-512:CC3ABCC1FB5ABD10A685F140931DE38D6875142D3595F8D9A581F5B31A7F354FA4CCC9727B69F58E0D2F773EA0F76D9ACFDF7ACBAFC6BAA6E93A46EAE8F18672
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:MET) {.. {-9223372036854775808 3600 0 MET}.. {-1693706400 7200 1 MEST}.. {-1680483600 3600 0 MET}.. {-1663455600 7200 1 MEST}.. {-1650150000 3600 0 MET}.. {-1632006000 7200 1 MEST}.. {-1618700400 3600 0 MET}.. {-938905200 7200 1 MEST}.. {-857257200 3600 0 MET}.. {-844556400 7200 1 MEST}.. {-828226800 3600 0 MET}.. {-812502000 7200 1 MEST}.. {-796777200 3600 0 MET}.. {-781052400 7200 1 MEST}.. {-766623600 3600 0 MET}.. {228877200 7200 1 MEST}.. {243997200 3600 0 MET}.. {260326800 7200 1 MEST}.. {276051600 3600 0 MET}.. {291776400 7200 1 MEST}.. {307501200 3600 0 MET}.. {323830800 7200 1 MEST}.. {338950800 3600 0 MET}.. {354675600 7200 1 MEST}.. {370400400 3600 0 MET}.. {386125200 7200 1 MEST}.. {401850000 3600 0 MET}.. {417574800 7200 1 MEST}.. {433299600 3600 0 MET}.. {449024400 7200 1 MEST}.. {465354000 3600 0 MET}.. {481078800 7200
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):111
                                                                                                                                                                                                            Entropy (8bit):4.902637155364683
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/6xtNMXGm2OHrXV4foAov:SlSWB9eg/6lDm2OHrCAAov
                                                                                                                                                                                                            MD5:36119516E87814F3C219193069CD6A90
                                                                                                                                                                                                            SHA1:BDB25531B30E6FC454100F37177EC9D4A0FB4E39
                                                                                                                                                                                                            SHA-256:E57746D5DB479A8B30973F2BC16E2B8DFB6E2BFAECBFF0FB956F04526E4B935B
                                                                                                                                                                                                            SHA-512:2730C5DABA0B2CCFD32A799C48EE07351659F51B9C2B91DCD145675AF276F2D0B5AA51ACF7D283C0DC236D3AFA3A75E58EB9F970B1831A6E36F02139CAF6A655
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:MST) {.. {-9223372036854775808 -25200 0 MST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8505
                                                                                                                                                                                                            Entropy (8bit):3.8405400251137207
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:T1ktwmGaLV911sF7Lv/PCewtA8CzSPyDLbrcUia:TswDPlLv/PCenJzS6cy
                                                                                                                                                                                                            MD5:87B3BCD4A793BA383889ECFDB44C846E
                                                                                                                                                                                                            SHA1:3EA34B5E6E3078A9501653BA069D5E5E879D7FE4
                                                                                                                                                                                                            SHA-256:A5DEB89D59613D9A54C1E146056A805B3DE9F2A2593AEC2B8A25F863328699C0
                                                                                                                                                                                                            SHA-512:AA4DAC2614661EF18A2A60A5BD4D5BBBCCB5D721F90A25E9D11C5B6AF8C39FD475B3E23894719E2F8F74469F13D5492FF31DDD193D9E3172182FBCBCDD860A41
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:MST7MDT) {.. {-9223372036854775808 -25200 0 MST}.. {-1633273200 -21600 1 MDT}.. {-1615132800 -25200 0 MST}.. {-1601823600 -21600 1 MDT}.. {-1583683200 -25200 0 MST}.. {-880210800 -21600 1 MWT}.. {-769395600 -21600 1 MPT}.. {-765388800 -25200 0 MST}.. {-84380400 -21600 1 MDT}.. {-68659200 -25200 0 MST}.. {-52930800 -21600 1 MDT}.. {-37209600 -25200 0 MST}.. {-21481200 -21600 1 MDT}.. {-5760000 -25200 0 MST}.. {9968400 -21600 1 MDT}.. {25689600 -25200 0 MST}.. {41418000 -21600 1 MDT}.. {57744000 -25200 0 MST}.. {73472400 -21600 1 MDT}.. {89193600 -25200 0 MST}.. {104922000 -21600 1 MDT}.. {120643200 -25200 0 MST}.. {126694800 -21600 1 MDT}.. {152092800 -25200 0 MST}.. {162378000 -21600 1 MDT}.. {183542400 -25200 0 MST}.. {199270800 -21600 1 MDT}.. {215596800 -25200 0 MST}.. {230720400 -21600 1 MDT}.. {247046400 -25200 0 MST}.. {262774800
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):190
                                                                                                                                                                                                            Entropy (8bit):4.884776849010803
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0qfSfXHAIg20qfORL/6AdMSKBbh4IAcGEqfBn:SlSWB9vsM3y7ekHAIgpeON/68K5h490m
                                                                                                                                                                                                            MD5:3050A0100A2313C1D3AB4278B464F17A
                                                                                                                                                                                                            SHA1:1A140447B3972900F13768659FD6979F68126E97
                                                                                                                                                                                                            SHA-256:F8CA38A845CD01BF785EE222277DAD9325AB6BD17E44A362C450855AEB522814
                                                                                                                                                                                                            SHA-512:C91C4BF2318C50D473E6051855C12F0E11CBAA8580B88115CDDE054D36476A1D8DDC5D17A7A123BD84148C20B96BD839511EAD573F5FD2C9A8556646B9CDE5E5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Tijuana)]} {.. LoadTimeZoneFile America/Tijuana..}..set TZData(:Mexico/BajaNorte) $TZData(:America/Tijuana)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):191
                                                                                                                                                                                                            Entropy (8bit):4.8897674180962145
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0zjRJ+ovXHAIg20zjRJ8yHRL/6AdMPCoQIAcGEzjy:SlSWB9vsM3y7zjRJvHAIgpzjRJ8yHN/Z
                                                                                                                                                                                                            MD5:FAFD9727A0E153AFCB726690D215DA76
                                                                                                                                                                                                            SHA1:3CD3B2737FC781F38DE26E255968CBB88B773CBF
                                                                                                                                                                                                            SHA-256:2E6E32A40487F0146B59150B66FF74901CA853B12D47922819AF23EEA5B4149C
                                                                                                                                                                                                            SHA-512:76D110494D4EB76961C818B2A2CCB2303B31DA161664FA712C87B95B81DE7B8F3E50DC7B2836C6ECC6437AE9595668E62E4E706F1B343EFEA12C32210F113540
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Mazatlan)]} {.. LoadTimeZoneFile America/Mazatlan..}..set TZData(:Mexico/BajaSur) $TZData(:America/Mazatlan)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):200
                                                                                                                                                                                                            Entropy (8bit):4.877941255622543
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y7zBDSHAIgpzBx6N/6BXl490zBf:MByMYzppzH6t6Bi90z1
                                                                                                                                                                                                            MD5:29ACBFCD0FD521EC0C9523906B9E2252
                                                                                                                                                                                                            SHA1:BBC1AD3F78CAA634A2F0BC38059975EF8E4A2CE9
                                                                                                                                                                                                            SHA-256:2DFF1B83FECFAD5C27EC47B206696C29B91398F8185B5D406A66FA9E0AECA93F
                                                                                                                                                                                                            SHA-512:802502010CFB6F1F4E60C22ECB0E6CA22750975E5838BE7E7DC9D12EA019CB6508F0F87465A113A98356CC9E145E32E6633AE2B45B93412A358C4AD13E923EFE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Mexico_City)]} {.. LoadTimeZoneFile America/Mexico_City..}..set TZData(:Mexico/General) $TZData(:America/Mexico_City)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):179
                                                                                                                                                                                                            Entropy (8bit):4.888611285267583
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQG/u4WXHAIgObT/KvRRL/5E1nUDH/uov:SlSWB9vsM3ycqXHAIgObOvRN/iy
                                                                                                                                                                                                            MD5:92548E239012515D756E002768CA876A
                                                                                                                                                                                                            SHA1:6BDC73DBD7356C3F82C5C76E6E2D58656FA9E21D
                                                                                                                                                                                                            SHA-256:E22D629D53C54960AD156C377DE0AE461C27F554990A3D1305724CA8F869BCE4
                                                                                                                                                                                                            SHA-512:42AD074EE08E083EE91270F203707698A8B3308005C94514B8B2D950F4C6F0B37D7D32973EC9F6AB49A0875209076FB40341B31433A27E47B3CC0EA711ECE321
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Auckland)]} {.. LoadTimeZoneFile Pacific/Auckland..}..set TZData(:NZ) $TZData(:Pacific/Auckland)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):181
                                                                                                                                                                                                            Entropy (8bit):4.881663364410736
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQG9WQ+DyXHAIgObT9WQiovRL/5AmtBFB/pUDH9WQg:SlSWB9vsM3ycwQ+DSHAIgObwQTN/zzJ7
                                                                                                                                                                                                            MD5:3811C133C6311E33FDAF93660E1EAED5
                                                                                                                                                                                                            SHA1:64756FF877B2EB91BAED2889B3924DAB6784DF43
                                                                                                                                                                                                            SHA-256:83F4CA3522B64F9B151EDEFAE53E0F28C2E6C4CE16D0982186B3344F2A268724
                                                                                                                                                                                                            SHA-512:7724D6CD08E13E116CCDF073F86CE317C0D4A849C5FE81DF3127D435704507FBF554BFC6E7A50CCA3852F6001D8654B7FF90466878DB8C3298338BE16149FD32
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Chatham)]} {.. LoadTimeZoneFile Pacific/Chatham..}..set TZData(:NZ-CHAT) $TZData(:Pacific/Chatham)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):177
                                                                                                                                                                                                            Entropy (8bit):4.8545620422964015
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx06RGFfXHAIg206RORL/5vf1+IAcGE6RB:SlSWB9vsM3y7+SPHAIgp+ON/pd+90+B
                                                                                                                                                                                                            MD5:5E9F3294F68873BF503F3DDDDF6713B0
                                                                                                                                                                                                            SHA1:954CD6F123C043E64F5E49733327E2C78877BDFB
                                                                                                                                                                                                            SHA-256:2CC8CE235F2EE3160E6AFD04A4E28AA0312494EBB6FED08D8CC81D414EC540EE
                                                                                                                                                                                                            SHA-512:200FC489989CA57219D5B28FB135BE5BDAC67239F3D243C496545D86D68089E51856CEAC4D2E700C0E47BAE4D5FEAB18A367C554235615B2B860F4E5E1BB08C3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Denver)]} {.. LoadTimeZoneFile America/Denver..}..set TZData(:Navajo) $TZData(:America/Denver)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):171
                                                                                                                                                                                                            Entropy (8bit):4.902914099699953
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8qvfXHAIgNtaYFARL/nL75h4WFKdy:SlSWB9vsM3yMPHAIgO8AN/H5h4wKU
                                                                                                                                                                                                            MD5:87C439DC623BF5C7EB01ADA6E67FB63A
                                                                                                                                                                                                            SHA1:1CC357558E09CDEA49F821826D2AEA9A6EF2C824
                                                                                                                                                                                                            SHA-256:6A5BAA9CA54B2A2C6D21287443BE0B1064AA79B5C4C62939933F8A0AD842B73E
                                                                                                                                                                                                            SHA-512:E628B8F1C967AABAEFBB68A33416F6FE47422970BA18414BB3396AC063E65A4DC892595D4071395194AF320633EE915A494E1F8D4216EE8194A034739D275C49
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Shanghai)]} {.. LoadTimeZoneFile Asia/Shanghai..}..set TZData(:PRC) $TZData(:Asia/Shanghai)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8505
                                                                                                                                                                                                            Entropy (8bit):3.836877329152454
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:0KhTG0hjvZkR/bvtw+N6IkWq/WHQlb/RYRWVIKr7cRRL:0sG0U9bFzN6IkWq/WHQt/RY4yP
                                                                                                                                                                                                            MD5:45E7E9E183A990F56E17C04FA48CE620
                                                                                                                                                                                                            SHA1:A1F39E0ECEA3C64E761A9A3159E331FA51B625F9
                                                                                                                                                                                                            SHA-256:D148708F1E70EEFA51E88E5823776CBE710535D4D6D6356E7753A44463A1C5AB
                                                                                                                                                                                                            SHA-512:1D1F4BA90D07D7EE12DFD0E37DBFD5410A4EAFFBA8960B816FDD5963CD6B20938080A4248E7B249AAE02F068E817AB9A85735D226F7DA8DD2C5462A70B18E8EF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:PST8PDT) {.. {-9223372036854775808 -28800 0 PST}.. {-1633269600 -25200 1 PDT}.. {-1615129200 -28800 0 PST}.. {-1601820000 -25200 1 PDT}.. {-1583679600 -28800 0 PST}.. {-880207200 -25200 1 PWT}.. {-769395600 -25200 1 PPT}.. {-765385200 -28800 0 PST}.. {-84376800 -25200 1 PDT}.. {-68655600 -28800 0 PST}.. {-52927200 -25200 1 PDT}.. {-37206000 -28800 0 PST}.. {-21477600 -25200 1 PDT}.. {-5756400 -28800 0 PST}.. {9972000 -25200 1 PDT}.. {25693200 -28800 0 PST}.. {41421600 -25200 1 PDT}.. {57747600 -28800 0 PST}.. {73476000 -25200 1 PDT}.. {89197200 -28800 0 PST}.. {104925600 -25200 1 PDT}.. {120646800 -28800 0 PST}.. {126698400 -25200 1 PDT}.. {152096400 -28800 0 PST}.. {162381600 -25200 1 PDT}.. {183546000 -28800 0 PST}.. {199274400 -25200 1 PDT}.. {215600400 -28800 0 PST}.. {230724000 -25200 1 PDT}.. {247050000 -28800 0 PST}.. {262778400
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):909
                                                                                                                                                                                                            Entropy (8bit):4.042826306713664
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB86HbmdH2oVCvcCfdf3NaDyTb6Dye78ubUt1NEUtszIVbUtoUtoUt3mbUt4qUt6:Yekv5fcfem+Cuy
                                                                                                                                                                                                            MD5:E5B913965F72AB807BAE67BD20C0A699
                                                                                                                                                                                                            SHA1:2161B73EC868C8D18C09970766D19A8583FF7981
                                                                                                                                                                                                            SHA-256:983884249ACC11C3FE740D78E72B1A89BE9C8B077283549BF6BCD8C93FA71731
                                                                                                                                                                                                            SHA-512:F8807C52DB852C48C62F25569C990C31D977BC7D0DF502CF2B92F9ED6BCB89A6DD8A6758FBD1185E0B5C34DE5450D5C748B71760AC93E72DC3976B3B31D1A605
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Apia) {.. {-9223372036854775808 45184 0 LMT}.. {-2445424384 -41216 0 LMT}.. {-1861878784 -41400 0 -1130}.. {-631110600 -39600 0 -11}.. {1285498800 -36000 1 -11}.. {1301752800 -39600 0 -11}.. {1316872800 -36000 1 -11}.. {1325239200 50400 0 +13}.. {1333202400 46800 0 +13}.. {1348927200 50400 1 +13}.. {1365256800 46800 0 +13}.. {1380376800 50400 1 +13}.. {1396706400 46800 0 +13}.. {1411826400 50400 1 +13}.. {1428156000 46800 0 +13}.. {1443276000 50400 1 +13}.. {1459605600 46800 0 +13}.. {1474725600 50400 1 +13}.. {1491055200 46800 0 +13}.. {1506175200 50400 1 +13}.. {1522504800 46800 0 +13}.. {1538229600 50400 1 +13}.. {1554559200 46800 0 +13}.. {1569679200 50400 1 +13}.. {1586008800 46800 0 +13}.. {1601128800 50400 1 +13}.. {1617458400 46800 0 +13}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8772
                                                                                                                                                                                                            Entropy (8bit):3.900078030355782
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:pj4hKuZaqaaiFKgjGeGV3atL67G9kJGsU+mpe7Vy:Cla1KgjGeGcQMsa
                                                                                                                                                                                                            MD5:8174D7205622711F58E0B515246FE89D
                                                                                                                                                                                                            SHA1:9777B2633ACF5588268D5072F817E65C879358AC
                                                                                                                                                                                                            SHA-256:201CFADB00FBCD3283249DAD73872ED75C5BEC07F5A5B157726638C20728B833
                                                                                                                                                                                                            SHA-512:64121ED1EE70D5423710319E806B19261576AECC89A64CBEC44A29BF4AC9FEE21C6484CC3C4550CC92C315B3855BE265F696F8CD4D95027226D608B3ADD022F1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Auckland) {.. {-9223372036854775808 41944 0 LMT}.. {-3192435544 41400 0 NZMT}.. {-1330335000 45000 1 NZST}.. {-1320057000 41400 0 NZMT}.. {-1300699800 43200 1 NZST}.. {-1287396000 41400 0 NZMT}.. {-1269250200 43200 1 NZST}.. {-1255946400 41400 0 NZMT}.. {-1237800600 43200 1 NZST}.. {-1224496800 41400 0 NZMT}.. {-1206351000 43200 1 NZST}.. {-1192442400 41400 0 NZMT}.. {-1174901400 43200 1 NZST}.. {-1160992800 41400 0 NZMT}.. {-1143451800 43200 1 NZST}.. {-1125914400 41400 0 NZMT}.. {-1112607000 43200 1 NZST}.. {-1094464800 41400 0 NZMT}.. {-1081157400 43200 1 NZST}.. {-1063015200 41400 0 NZMT}.. {-1049707800 43200 1 NZST}.. {-1031565600 41400 0 NZMT}.. {-1018258200 43200 1 NZST}.. {-1000116000 41400 0 NZMT}.. {-986808600 43200 1 NZST}.. {-968061600 41400 0 NZMT}.. {-955359000 43200 1 NZST}.. {-936612000 41400 0 NZMT}.. {-923304600 4320
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):280
                                                                                                                                                                                                            Entropy (8bit):4.715653436088026
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/FtTfDm2OHHhp5oHvZiuo2HvDVeEU8vScH9syZEizy:MB86FtTLmdHf5CvZiIvJeJ8HH9F6izy
                                                                                                                                                                                                            MD5:4E858B3754BD8864719A61839ACA64E6
                                                                                                                                                                                                            SHA1:597025A8DAFD5AE75EBD162AC0E9DA71815816BA
                                                                                                                                                                                                            SHA-256:2D3BFDED297214BA25CFD8C6F508D0C8B1A1CD7D46701A78EC5E510076185EB6
                                                                                                                                                                                                            SHA-512:720F301B73C852EA8EEFA79DEF6B6762554E50222DE114FE87EB5178507F1895A9A39B3872A1A4B9DFF58D1CC6460BA4A82F2C165E3659E13036451F22E389C3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Bougainville) {.. {-9223372036854775808 37336 0 LMT}.. {-2840178136 35312 0 PMMT}.. {-2366790512 36000 0 +10}.. {-868010400 32400 0 +09}.. {-768906000 36000 0 +10}.. {1419696000 39600 0 +11}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8165
                                                                                                                                                                                                            Entropy (8bit):3.6566720439018874
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:gpvlGCcn6AadFurBrioCdL49mq9X4a2t3I/KVE:gOCBdFurBr0soaz
                                                                                                                                                                                                            MD5:8105A806A1762932897AB59C47BBE89E
                                                                                                                                                                                                            SHA1:386E41A4A83FA84DBFCA994F679242D067CEED64
                                                                                                                                                                                                            SHA-256:CA0EEF84DBC5964EF2265E9252237BE58BB8D75C34817CC2305CCCFAEC7E690C
                                                                                                                                                                                                            SHA-512:8A609E7F4868BD455DA811E62142FECD792D0CA0DAAF7C10C4E4254C9EC44B8EB92D388D9224C8FD3CC3FB326A106D831B80F5E1264CCF3EABBCE177BB82E9D6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Chatham) {.. {-9223372036854775808 44028 0 LMT}.. {-3192437628 44100 0 +1215}.. {-757426500 45900 0 +1245}.. {152632800 49500 1 +1245}.. {162309600 45900 0 +1245}.. {183477600 49500 1 +1245}.. {194968800 45900 0 +1245}.. {215532000 49500 1 +1245}.. {226418400 45900 0 +1245}.. {246981600 49500 1 +1245}.. {257868000 45900 0 +1245}.. {278431200 49500 1 +1245}.. {289317600 45900 0 +1245}.. {309880800 49500 1 +1245}.. {320767200 45900 0 +1245}.. {341330400 49500 1 +1245}.. {352216800 45900 0 +1245}.. {372780000 49500 1 +1245}.. {384271200 45900 0 +1245}.. {404834400 49500 1 +1245}.. {415720800 45900 0 +1245}.. {436284000 49500 1 +1245}.. {447170400 45900 0 +1245}.. {467733600 49500 1 +1245}.. {478620000 45900 0 +1245}.. {499183200 49500 1 +1245}.. {510069600 45900 0 +1245}.. {530632800 49500 1 +1245}.. {541519200 45900 0 +1245}.. {56208
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):202
                                                                                                                                                                                                            Entropy (8bit):4.943709180393636
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3yci/452HAIgObi/4oA6N/ZE/4pv:MByMdNXiU5tVv
                                                                                                                                                                                                            MD5:7D9980F68F044EB9B7FA7ED2883645F2
                                                                                                                                                                                                            SHA1:9444DA9D3139F51C6DFDA174C8C52A231215D71E
                                                                                                                                                                                                            SHA-256:F324CA637180F50DB79FFA25204D974C6A7A6FAEFDA69FD1A280B9F366349A09
                                                                                                                                                                                                            SHA-512:850577ABD3A3653076797D46AF481343CDF8103AC597EB68F575C5FF4931242C6ACEB054D14E0F6A9A90E5D22069F78027215A4E44FC900292445FDEAFB8F92D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Port_Moresby)]} {.. LoadTimeZoneFile Pacific/Port_Moresby..}..set TZData(:Pacific/Chuuk) $TZData(:Pacific/Port_Moresby)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8203
                                                                                                                                                                                                            Entropy (8bit):3.5469404823178463
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:QXn3AWkHkPp2YXaVU+POtUn4n6MSmSmiTpk9eL6Z5waKkhWILTc:QXn3AWJB2m+POtUnOSmSmS6ZaILg
                                                                                                                                                                                                            MD5:002F3607DE2061A2E1A8EB8EBCB6E492
                                                                                                                                                                                                            SHA1:6521B47847CFA76FE45AE5CC649109E4AD6C5262
                                                                                                                                                                                                            SHA-256:D79A2A67606F25D6420F31129FAE966A54287DE96C661003CCE5F82B618014BC
                                                                                                                                                                                                            SHA-512:03F3F262538FAF5A1B38832EFA62E3CC41A70BF54E73DE59BC99DCCA035AB002142F42BEDA5BFC2102CD556601E0A278908FDCC838A2211AC63C49A8483CE72B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Easter) {.. {-9223372036854775808 -26248 0 LMT}.. {-2524495352 -26248 0 EMT}.. {-1178124152 -25200 0 -07}.. {-36619200 -21600 1 -07}.. {-23922000 -25200 0 -07}.. {-3355200 -21600 1 -07}.. {7527600 -25200 0 -07}.. {24465600 -21600 1 -07}.. {37767600 -25200 0 -07}.. {55915200 -21600 1 -07}.. {69217200 -25200 0 -07}.. {87969600 -21600 1 -07}.. {100666800 -25200 0 -07}.. {118209600 -21600 1 -07}.. {132116400 -25200 0 -07}.. {150868800 -21600 1 -07}.. {163566000 -25200 0 -07}.. {182318400 -21600 1 -07}.. {195620400 -25200 0 -07}.. {213768000 -21600 1 -07}.. {227070000 -25200 0 -07}.. {245217600 -21600 1 -07}.. {258519600 -25200 0 -07}.. {277272000 -21600 1 -07}.. {289969200 -25200 0 -07}.. {308721600 -21600 1 -07}.. {321418800 -25200 0 -07}.. {340171200 -21600 1 -07}.. {353473200 -25200 0 -07}.. {371620800 -21600 1 -07}.. {384922800
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):789
                                                                                                                                                                                                            Entropy (8bit):4.0457106900970325
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB86HmdH6mvCON3Xj/kw2eX/xtDedjX24ots0FX2ud5KRGkpFxy:uegazZBzCdXUFQzy
                                                                                                                                                                                                            MD5:6841B8A2FB9BBF464AA00088CBDCEC80
                                                                                                                                                                                                            SHA1:26CC5CCE00A765F8B6493ED24F50957AA7F0089B
                                                                                                                                                                                                            SHA-256:332372E5EFB46123FBB66F9F32F91B59EBD88ADB956249DB3F14CAAB01CE2655
                                                                                                                                                                                                            SHA-512:A6C67A0F7361E599369597E9A8A52FC7D5C96DE6B5A7C1BE1D02F5DF11051F448289786C7F0E82E71CDEB825215E64E072CF034C45D6E2F822D7201AB8B41B57
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Efate) {.. {-9223372036854775808 40396 0 LMT}.. {-1829387596 39600 0 +11}.. {125409600 43200 1 +11}.. {133876800 39600 0 +11}.. {433256400 43200 1 +11}.. {448977600 39600 0 +11}.. {464706000 43200 1 +11}.. {480427200 39600 0 +11}.. {496760400 43200 1 +11}.. {511876800 39600 0 +11}.. {528210000 43200 1 +11}.. {543931200 39600 0 +11}.. {559659600 43200 1 +11}.. {575380800 39600 0 +11}.. {591109200 43200 1 +11}.. {606830400 39600 0 +11}.. {622558800 43200 1 +11}.. {638280000 39600 0 +11}.. {654008400 43200 1 +11}.. {669729600 39600 0 +11}.. {686062800 43200 1 +11}.. {696340800 39600 0 +11}.. {719931600 43200 1 +11}.. {727790400 39600 0 +11}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):188
                                                                                                                                                                                                            Entropy (8bit):4.82787610497142
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQG11avXHAIgObT11ORL/nUDH7/UDH11B:SlSWB9vsM3yckHAIgObON/h
                                                                                                                                                                                                            MD5:CD1AC50AADC3CF9C0E7A055D587E790D
                                                                                                                                                                                                            SHA1:BEE0E16D3954DF33C697DEA469A130BD9875AB8B
                                                                                                                                                                                                            SHA-256:790E6B48B261D6DEF7D183CC8F38FB8D8A6E3EFB8844281EFABB2DFD621E53B5
                                                                                                                                                                                                            SHA-512:B6A93DFB4CBE2F35268AACA88FDCC4D19949A2E8DC9464D8341C38065C6FF48A3C49FE756FFCE777C8F806DE309C8AFC4CE4BC4ABD183C28808F995A0F89B091
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Kanton)]} {.. LoadTimeZoneFile Pacific/Kanton..}..set TZData(:Pacific/Enderbury) $TZData(:Pacific/Kanton)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):185
                                                                                                                                                                                                            Entropy (8bit):4.913439535905759
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/nUDH4ErKYofMXGm2OH18VkeoHvmUENBBy/aCPFVFv7Dy:SlSWB9eg/BE3ofDm2OH1VeoHvmH7y/Fy
                                                                                                                                                                                                            MD5:6250F332356787613A2D1853EF6D1AC3
                                                                                                                                                                                                            SHA1:0464B9EE8B691990022295D2DEFE1AAE4B247E63
                                                                                                                                                                                                            SHA-256:336058DCA4802C79ED43F6177ADB73085D4FA0754B94051CAE2A19346B0C4904
                                                                                                                                                                                                            SHA-512:B8FAB5E128D2EF3CB7050DA717D80247045BE09F7F6542AA154CB85F4A56884F195EE2776421890A3F86D133106DCA4672D7D9329E0DE6F4A7CF8F4030822988
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Fakaofo) {.. {-9223372036854775808 -41096 0 LMT}.. {-2177411704 -39600 0 -11}.. {1325242800 46800 0 +13}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):986
                                                                                                                                                                                                            Entropy (8bit):3.950865906618592
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:CKeaEa+TkUqOL1X7dMUhSXUmxY8yiUKEMH0Mkxu:9pW15Mmk59NQMk0
                                                                                                                                                                                                            MD5:E329ACBF859B35950B27F434D725B3F8
                                                                                                                                                                                                            SHA1:9B46C4318CA0F03E016F8FF68FEE50EA93B22360
                                                                                                                                                                                                            SHA-256:0FF7AF55C92806751473CBF7A55E860850719BA7255CD65FD630B99E05C7C177
                                                                                                                                                                                                            SHA-512:84A7491E2C8A6866B40A3673C084ABF3F1E344CB0290C607A0BB06FF19D43EF0B9648CDA6489D10C410D39C700D8C62A8BA11EEF07AD36F5A9AD85C596205939
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Fiji) {.. {-9223372036854775808 42944 0 LMT}.. {-1709985344 43200 0 +12}.. {909842400 46800 1 +12}.. {920124000 43200 0 +12}.. {941896800 46800 1 +12}.. {951573600 43200 0 +12}.. {1259416800 46800 1 +12}.. {1269698400 43200 0 +12}.. {1287842400 46800 1 +12}.. {1299333600 43200 0 +12}.. {1319292000 46800 1 +12}.. {1327154400 43200 0 +12}.. {1350741600 46800 1 +12}.. {1358604000 43200 0 +12}.. {1382796000 46800 1 +12}.. {1390050000 43200 0 +12}.. {1414850400 46800 1 +12}.. {1421503200 43200 0 +12}.. {1446300000 46800 1 +12}.. {1452952800 43200 0 +12}.. {1478354400 46800 1 +12}.. {1484402400 43200 0 +12}.. {1509804000 46800 1 +12}.. {1515852000 43200 0 +12}.. {1541253600 46800 1 +12}.. {1547301600 43200 0 +12}.. {1573308000 46800 1 +12}.. {1578751200 43200 0 +12}.. {1608386400 46800 1 +12}.. {1610805600 43200 0 +12}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):187
                                                                                                                                                                                                            Entropy (8bit):4.770127787944403
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQGqhyXHAIgObTq0vFvRL/nUDH4QwyFPUDHqNn:SlSWB9vsM3ycmhSHAIgObmSN/BCLNn
                                                                                                                                                                                                            MD5:BBB00369FA8DCC23A7824EDB964BF48D
                                                                                                                                                                                                            SHA1:A97E42B3CC45860CC0DFC62F468B24A628B43973
                                                                                                                                                                                                            SHA-256:AFFB0A5D9CBD5949F2FC5047820FA2A2798F7C303F7BC972EC49CCF27837B00E
                                                                                                                                                                                                            SHA-512:2D4C8616308522C987437C39C74E250973C2AC7AA1499C60321F42E84CE52C28D1F6AE81E6390B116C92C7B208EA0F211EB3C5A86E6E4CEE0620014DE5359F4F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Tarawa)]} {.. LoadTimeZoneFile Pacific/Tarawa..}..set TZData(:Pacific/Funafuti) $TZData(:Pacific/Tarawa)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):247
                                                                                                                                                                                                            Entropy (8bit):4.687336389955113
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/fEGDm2OHvQYeoHTie7KVQRncRvinrN5/uFifriX:MB86fhmdH0CTV7OcdrN5/uFiGX
                                                                                                                                                                                                            MD5:0557D164DCD8DF5D99F7AF5A2AB1AD4F
                                                                                                                                                                                                            SHA1:68AFD04303E5F541480425405D82E1827F78A8DF
                                                                                                                                                                                                            SHA-256:192545659F971084ADC8489A2B96A6439FF391599DC962AA13375ACCFB3C09D9
                                                                                                                                                                                                            SHA-512:1DA004E51F8E7A712EDE920CBB62E81F9F55450FB52B62F78F1CD4F8F4E342B4DAB2C28AA5161E8B24942A7A5BD55F978AFDA1C5E1949241E71D738079DEF9B8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Galapagos) {.. {-9223372036854775808 -21504 0 LMT}.. {-1230746496 -18000 0 -05}.. {504939600 -21600 0 -06}.. {722930400 -18000 1 -06}.. {728888400 -21600 0 -06}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):155
                                                                                                                                                                                                            Entropy (8bit):4.976931060677737
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/nUDH5hBYfMXGm2OHKToxYoHsdNfis:SlSWB9eg/DDm2OHPxYoH4qs
                                                                                                                                                                                                            MD5:45330CE0FA604304C6ACF8EF8CAF51EC
                                                                                                                                                                                                            SHA1:20EEF9646996C2EC9B2641EBCCBE4766BF38B17B
                                                                                                                                                                                                            SHA-256:190E02A0C00D165FA45C73AEF9C0D6C82B1720E7406E5610DD860AED10A021A5
                                                                                                                                                                                                            SHA-512:51C7931B503405DA0B4078F6BE411895DD00E86AC7C5BE475030664D5302AD614293541DEE7FFC3D86A9DDB1BDA32BCAA746CF1D207DB063FBA2F9E9BE12836C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Gambier) {.. {-9223372036854775808 -32388 0 LMT}.. {-1806678012 -32400 0 -09}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):157
                                                                                                                                                                                                            Entropy (8bit):4.9796189407775255
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/nUDH5RyJTLJ5FNMXGm2OHddHvpoxYoHsdMWdHPVtyn:SlSWB9eg/LJHjXDm2OHdFGxYoHgHPLy
                                                                                                                                                                                                            MD5:DF09960360D8CEDCA2A4DC19A177C4A6
                                                                                                                                                                                                            SHA1:9F73F271B8C85B25FE6392B8BF7465C92EFFE621
                                                                                                                                                                                                            SHA-256:161762334DFF48B1D58824911E1FF4171386EA18234DD3DD5B0798515593086A
                                                                                                                                                                                                            SHA-512:1BE9E0F90DA529C99E317F399BFDB913A076651CF8801A1849247B26A350A76D8B5807AB139F3DBB97790DDFC332BDBEB57B364BF67FA2BB440AFEDC4130A648
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Guadalcanal) {.. {-9223372036854775808 38388 0 LMT}.. {-1806748788 39600 0 +11}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):733
                                                                                                                                                                                                            Entropy (8bit):4.244282318063802
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB862mdHanCTCtBCv1yWQkHHLTaWJ+x+87W0x+8+yWSi+JW7+sWU0dwaW1j+FaW2:FeaC2twvY3knLGs+I87p+8d9i+J7s70c
                                                                                                                                                                                                            MD5:BA319E451BE323C852A8ABFC299DDA28
                                                                                                                                                                                                            SHA1:FC9314C162FF1FE1ED5E2C5DF962A55D4D6D8115
                                                                                                                                                                                                            SHA-256:42CB69ABC83415F63CA7D2A3E5314A41817AEE3206ECCC7172C50A74B1597DB0
                                                                                                                                                                                                            SHA-512:3BF733B9ED2A57B01BE173A8421B2D5A45888A230461EA0BD8C5B4AC7DC010BB527346731196141C70AFECDF88DD47AFE48636243DFC395D88E58231BEDF7D2A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Guam) {.. {-9223372036854775808 -51660 0 LMT}.. {-3944626740 34740 0 LMT}.. {-2177487540 36000 0 GST}.. {-885549600 32400 0 +09}.. {-802256400 36000 0 GST}.. {-331891200 39600 1 GDT}.. {-281610000 36000 0 GST}.. {-73728000 39600 1 GDT}.. {-29415540 36000 0 GST}.. {-16704000 39600 1 GDT}.. {-10659600 36000 0 GST}.. {9907200 39600 1 GDT}.. {21394800 36000 0 GST}.. {41356800 39600 1 GDT}.. {52844400 36000 0 GST}.. {124819200 39600 1 GDT}.. {130863600 36000 0 GST}.. {201888000 39600 1 GDT}.. {209487660 36000 0 GST}.. {230659200 39600 1 GDT}.. {241542000 36000 0 GST}.. {977493600 36000 0 ChST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):344
                                                                                                                                                                                                            Entropy (8bit):4.640604617840767
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/PeDDm2OHsVVoHvBrai3UNFv+rUXaWFvAHovj/0nvCv7p+v:MB86WXmdH0VCvBz0GOTA0/0y74v
                                                                                                                                                                                                            MD5:F3F0E64655FAA79E40860765EEBB5B77
                                                                                                                                                                                                            SHA1:7F6C2FC100AEABC26B7205AB53C1E016B12E4D60
                                                                                                                                                                                                            SHA-256:69319015799D32D3CF7C0A3E9991B4B1F3E0C5D1B4FBF400517350CCA9D2C3B7
                                                                                                                                                                                                            SHA-512:7C9238BCCB13B90D4DC9B5E776C421A42C25D21B4E026406F57FA1E70983E8F6BF1CE927AB9D0D6261C5C1802A8B810399F506915262F82F487417CFD704B2F1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Honolulu) {.. {-9223372036854775808 -37886 0 LMT}.. {-2334101314 -37800 0 HST}.. {-1157283000 -34200 1 HDT}.. {-1155436200 -34200 0 HST}.. {-880201800 -34200 1 HWT}.. {-769395600 -34200 1 HPT}.. {-765376200 -37800 0 HST}.. {-712150200 -36000 0 HST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):193
                                                                                                                                                                                                            Entropy (8bit):4.844454917943834
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3yc6e8SHAIgOb6eKAN/NWyVheo:MByMdniinbtNWzo
                                                                                                                                                                                                            MD5:4244078A03C2493009EF2F6BDA2F326F
                                                                                                                                                                                                            SHA1:AC2FF3E91A8831A479B33DF32A0118BC2EB255D0
                                                                                                                                                                                                            SHA-256:6E52B361AC8A6A578C709F6D58AA7535F06C0CB1707081C2D5A63FA8545D955C
                                                                                                                                                                                                            SHA-512:398B32E0FAF80E40DF3ACD203DF380D61DC39322F0BA0388A18281BC26973945F45683A104B9A785BB9DF5E514322F6994F934289E4B56B7982F94D4528D4272
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Honolulu)]} {.. LoadTimeZoneFile Pacific/Honolulu..}..set TZData(:Pacific/Johnston) $TZData(:Pacific/Honolulu)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):208
                                                                                                                                                                                                            Entropy (8bit):4.669308556946547
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/KyXDm2OHEMmzQwXy29BVyv7y/fTVVFty:MB86KyTmdHEZzQUBVyDy/fZvty
                                                                                                                                                                                                            MD5:544A0A83241333805192A6F03888E359
                                                                                                                                                                                                            SHA1:99D2BE79D57B44BD538386F9E7551C9E1874D7E3
                                                                                                                                                                                                            SHA-256:0B1345555EC2B4738CC4DEBFE496C287966F238386263032FF1E27912CCBFBA6
                                                                                                                                                                                                            SHA-512:61C91265632D01FBB7F4C739368756C428258FA6C141E49E88B6C78ABEA6150A74B8DFCF14C5AADDA03C1EA6F04D122734654495C26B8614561786B1C5C7EF10
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Kanton) {.. {-9223372036854775808 0 0 -00}.. {-1020470400 -43200 0 -12}.. {307627200 -39600 0 -11}.. {788871600 46800 0 +13}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):219
                                                                                                                                                                                                            Entropy (8bit):4.739672105601744
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/iSDm2OHjkeoHvmLVFFz4YWXfSzvjNv:MB86iGmdHpCvU4VfSbxv
                                                                                                                                                                                                            MD5:1B695BBB9C50F6AFC05F67DE30374160
                                                                                                                                                                                                            SHA1:08AD8BBB6C99EB36FC3E462DB41C6896F52F150C
                                                                                                                                                                                                            SHA-256:4F7235B956A5A01676BE05275E086D5157EBC24FD91022E87817020669F915F7
                                                                                                                                                                                                            SHA-512:DC35CB1C2E5E035A82F91D1B1F4B48D7B112D9B7A1A7DB9C4A4C42C4D58002E1ECD9D24B2EA5B624DBB526ADDF9A8AB37D4315843207C34C16B2EFE33A254752
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Kiritimati) {.. {-9223372036854775808 -37760 0 LMT}.. {-2177415040 -38400 0 -1040}.. {307622400 -36000 0 -10}.. {788868000 50400 0 +14}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):394
                                                                                                                                                                                                            Entropy (8bit):4.441317927120857
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB869nmdHlCTvrvCvKcHwzHHI/HKOjHHwZaLYkcy:2ecrrqvGznISknwZaLxcy
                                                                                                                                                                                                            MD5:B489D7BDE8EB805B2A24726A6FB0C441
                                                                                                                                                                                                            SHA1:7997A33AA56857EC52B1198DBEF4CE1DB50D69FD
                                                                                                                                                                                                            SHA-256:B528E5E712E5F878603183E7CCFF55E5DB97CB47D7628BCB635342796317B899
                                                                                                                                                                                                            SHA-512:4898AC2747FB8620BE29933CC7AA344AF1A3B7777D1AFF08BB4C6CE6E7AF205581937CCB488F3CB39CC8CA7FB42EDC8E1CAD8BADC9FCA40E3CAD23271CD66FCB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Kosrae) {.. {-9223372036854775808 -47284 0 LMT}.. {-3944631116 39116 0 LMT}.. {-2177491916 39600 0 +11}.. {-1743678000 32400 0 +09}.. {-1606813200 39600 0 +11}.. {-1041418800 36000 0 +10}.. {-907408800 32400 0 +09}.. {-770634000 39600 0 +11}.. {-7988400 43200 0 +12}.. {915105600 39600 0 +11}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):304
                                                                                                                                                                                                            Entropy (8bit):4.5947337310364835
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/yEyDm2OH4T2eoHvmfKnOjvScHrkL/Xy2185k0YAov:MB86XmmdHWCv6KOjHHgLN8tby
                                                                                                                                                                                                            MD5:7D1FC9913941693ACBD6A3CCB2F34555
                                                                                                                                                                                                            SHA1:D07C8AAED1DF9614BCA6EEF0F72FB98BE46CF5EF
                                                                                                                                                                                                            SHA-256:38133BE70100D7DC244A680827879E6B240646C7C0B68F58652051E681A71985
                                                                                                                                                                                                            SHA-512:419F0A1D1D71C8F84765C7B54271D7EFD6A81F428751523A214ABB24A8770DD5A7666F634A20AF97D5AAB8F21C0DEF23DCDE068CF4C1CCC7639ABC43864A9DBC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Kwajalein) {.. {-9223372036854775808 40160 0 LMT}.. {-2177492960 39600 0 +11}.. {-1041418800 36000 0 +10}.. {-907408800 32400 0 +09}.. {-817462800 39600 0 +11}.. {-7988400 -43200 0 -12}.. {745934400 43200 0 +12}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):185
                                                                                                                                                                                                            Entropy (8bit):4.7986219497241995
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQGqhyXHAIgObTq0vFvRL/nUDHznHlUDHqNn:SlSWB9vsM3ycmhSHAIgObmSN/QxNn
                                                                                                                                                                                                            MD5:EB409C340A475B60993965A0E2892B6E
                                                                                                                                                                                                            SHA1:819881A078F34EF8FC55D71D829B82C56E6723D7
                                                                                                                                                                                                            SHA-256:935BC00C13863715D09463E54DC2A6FF0F1A7EEA8D5895C87836AA59716CBD57
                                                                                                                                                                                                            SHA-512:A28AF85022F8B3C2EE5F93BF6FDC0C349B73F25D88BA151ACE424EED1A95FA29608A6B1AD3D5FD952B2FB7F48DF6FDF8E6504F2B53E6782E4FF73335AF9A15C0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Tarawa)]} {.. LoadTimeZoneFile Pacific/Tarawa..}..set TZData(:Pacific/Majuro) $TZData(:Pacific/Tarawa)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):159
                                                                                                                                                                                                            Entropy (8bit):4.976348164850869
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/nUDHzrHeWNMXGm2OHOx5oHsdNpNFvvIVVFvYy:SlSWB9eg/cHeSDm2OHOnoH4/FvQVVFAy
                                                                                                                                                                                                            MD5:80CB45F42BAB1AA72CD7C7BC394DF3F8
                                                                                                                                                                                                            SHA1:8B5ED2BCCA1AEB41F22AFD14F46533959828B2BE
                                                                                                                                                                                                            SHA-256:AE0B5055C6E57516F23749B13681205EAD376E682959716A457B1377AF8160BA
                                                                                                                                                                                                            SHA-512:71562E340B7A96B91D04FCBCAF71B66EA725CA1BD1094343C4442F8F9A8C67A3BE378034849197407D21C3EE74E2C753B1FD3BAFF2378714B993AD9336236A0E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Marquesas) {.. {-9223372036854775808 -33480 0 LMT}.. {-1806676920 -34200 0 -0930}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):194
                                                                                                                                                                                                            Entropy (8bit):4.81307101485774
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQGurKeTnXHAIgObTurKefVHRL/nUDHz0HvUDHurKv:SlSWB9vsM3yciemHAIgObiecN/Zevn
                                                                                                                                                                                                            MD5:13CE48F8FF74BFCEFCB8D217D6357E38
                                                                                                                                                                                                            SHA1:296D31E3F868934C6EB34BF1BF4C23F3E1839294
                                                                                                                                                                                                            SHA-256:F62C6A2DEC1E9EC78115D5F14E5B9DB7C86F788662D2E68F7E6714F4A05DC974
                                                                                                                                                                                                            SHA-512:778813FC08EF803743F392000BECE73C1C079883DAFC26FAC0AF8FA3FA4AE1D94BA8F3CAA5E82DD4DB1A5F12AD49E123901908F5483E0E325952622AB4C4A26A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Pago_Pago)]} {.. LoadTimeZoneFile Pacific/Pago_Pago..}..set TZData(:Pacific/Midway) $TZData(:Pacific/Pago_Pago)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):244
                                                                                                                                                                                                            Entropy (8bit):4.702705620563736
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/JdDm2OHceoHx6sCH/ZdqvScH9cd0YAov:MB86J5mdH9CMhcHHauby
                                                                                                                                                                                                            MD5:30A8285FCCE2E98889E53DF60B906C3D
                                                                                                                                                                                                            SHA1:C7789CB11A2C8FE3861FF3C0A7A41F6CAFD87631
                                                                                                                                                                                                            SHA-256:22C367F3219B5FC736260D9DBFEF5FCB767F1A6BDA991C9352F790A3D1FFE884
                                                                                                                                                                                                            SHA-512:02DA82680588839B06F820979AECC78B7FBEAB9D6D49176B513B80F1C8BA2D55FB3674B19EFDD574EE6FC01539EF7C3081A4B34D14A54DACF367D816B62E5843
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Nauru) {.. {-9223372036854775808 40060 0 LMT}.. {-1545131260 41400 0 +1130}.. {-862918200 32400 0 +09}.. {-767350800 41400 0 +1130}.. {287418600 43200 0 +12}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):184
                                                                                                                                                                                                            Entropy (8bit):4.846897598147338
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/nUDHwMQA3WNMXGm2OH0SNoHoRWVGXyOyovFaSUGFAZvBByV:SlSWB9eg/Jm3SDm2OHJoHFGXCodZUGFd
                                                                                                                                                                                                            MD5:6E8EC957423917AE7A7EF503661C1A77
                                                                                                                                                                                                            SHA1:B4FA3C3E3F96C28B7DB87BFD441D2EE99CC81B6F
                                                                                                                                                                                                            SHA-256:869CCA656BE88E4E7481C75737C3656BAB6924AD1751505815AC719C59269842
                                                                                                                                                                                                            SHA-512:9047ABE673259699C7A548BC7B5636DD646DD382C751B796522F65404162AB1B0BB022FD274653921E5B23C847EE248AEF6749E15ED2CFC1DCE35BBA294D8251
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Niue) {.. {-9223372036854775808 -40780 0 LMT}.. {-543069620 -40800 0 -1120}.. {-173623200 -39600 0 -11}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):5139
                                                                                                                                                                                                            Entropy (8bit):3.65794255179185
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:K/yg8hZbeS07HbbYTqge+gDrWnAxhejtB0e+Pwn1UVimqNQrKvyXrStkCDv:K/y7hNeS07sq0Erk10lINQrKvyXrwv
                                                                                                                                                                                                            MD5:E19700A894AA64715D14F501D8D2FA98
                                                                                                                                                                                                            SHA1:57CFC96E2EBB985720DB290F59181860AF2AC1AA
                                                                                                                                                                                                            SHA-256:5D16C3EF1DB996C1B8E33AD884C33946F77DA872F35F41EC3BD5B288F43CC9AF
                                                                                                                                                                                                            SHA-512:E11EAF2A7B217CDBEECB57635184F04171F0DB088FCC4702AA8D40A3A5453904592F5869849913E2EB02DC5941C84203A76D270E8930B0B691A3B9C39B78BF30
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Norfolk) {.. {-9223372036854775808 40312 0 LMT}.. {-2177493112 40320 0 +1112}.. {-599656320 41400 0 +1130}.. {152029800 45000 1 +1230}.. {162916200 41400 0 +1130}.. {1443882600 39600 0 +11}.. {1561899600 39600 0 +12}.. {1570287600 43200 1 +12}.. {1586012400 39600 0 +12}.. {1601737200 43200 1 +12}.. {1617462000 39600 0 +12}.. {1633186800 43200 1 +12}.. {1648911600 39600 0 +12}.. {1664636400 43200 1 +12}.. {1680361200 39600 0 +12}.. {1696086000 43200 1 +12}.. {1712415600 39600 0 +12}.. {1728140400 43200 1 +12}.. {1743865200 39600 0 +12}.. {1759590000 43200 1 +12}.. {1775314800 39600 0 +12}.. {1791039600 43200 1 +12}.. {1806764400 39600 0 +12}.. {1822489200 43200 1 +12}.. {1838214000 39600 0 +12}.. {1853938800 43200 1 +12}.. {1869663600 39600 0 +12}.. {1885993200 43200 1 +12}.. {1901718000 39600 0 +12}.. {1917442800 43200 1 +12}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):326
                                                                                                                                                                                                            Entropy (8bit):4.531117764974758
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9eg/JcSDm2OHTYoHgnX2czO/FxgV62JFy:MB86JcGmdHTYCgX2czUjgM2ny
                                                                                                                                                                                                            MD5:2F1E92A11DF44C72DC305C13111DEA35
                                                                                                                                                                                                            SHA1:847F551C3D6C75CD2D0D6D87FCF3294CA8DD90B2
                                                                                                                                                                                                            SHA-256:238683C027D2319C33D975A837E9FC9D24DD53B1A67108EDBF7ABDF0DB050881
                                                                                                                                                                                                            SHA-512:E35D8C71AFDBB9A7507E873925001AEDE3734B1D235F509D19952E85279CBCC233A73412EA1F79CB534A45D36FEAA8AFDA98D9964DC93C7892B318F4AFC9A076
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Noumea) {.. {-9223372036854775808 39948 0 LMT}.. {-1829387148 39600 0 +11}.. {250002000 43200 1 +11}.. {257342400 39600 0 +11}.. {281451600 43200 1 +11}.. {288878400 39600 0 +11}.. {849366000 43200 1 +11}.. {857228400 39600 0 +11}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):188
                                                                                                                                                                                                            Entropy (8bit):4.985607855830399
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/nUDHurKeTFfXMXGm2OH2ivkeoHvUPi1TsYoHsdfWTVvvVFv:SlSWB9eg/XecDm2OH23eoHvWieYoHiWB
                                                                                                                                                                                                            MD5:E86D90DAA694B0EAC42F8C01346BC95B
                                                                                                                                                                                                            SHA1:CD29DEFC291C939296E86DC7EF5D0654D85285E8
                                                                                                                                                                                                            SHA-256:CCA96640AB3BC707224FA86D9AF66F9D53A204A97B370B2785BA8208688BF8B6
                                                                                                                                                                                                            SHA-512:937BA420061E3781F831779B458E914A0FC465C4B41796F8B7CB1E548822F5777A6450FC6002AB13EBC5C9F54E374D3ED731D05B2B302B95359BE34094E5062B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Pago_Pago) {.. {-9223372036854775808 45432 0 LMT}.. {-2445424632 -40968 0 LMT}.. {-1861879032 -39600 0 SST}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):183
                                                                                                                                                                                                            Entropy (8bit):4.919381181565273
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/nUDHugEZF3fMXGm2OHKvkeoHucRbgnJnoHvmdQ4+vScFAy:SlSWB9eg/Xg2PDm2OHK8eoHTWJnoHvmi
                                                                                                                                                                                                            MD5:2E6C7EC61C7E29A147475C223B163F6B
                                                                                                                                                                                                            SHA1:3A98D3441335224E7EBC0648990BCA1DE3BDF5C6
                                                                                                                                                                                                            SHA-256:97DE6C2C717BFEAD00F83B5D39D654C32CEE580226F5F084484EBAD57BBCE7FF
                                                                                                                                                                                                            SHA-512:5868C43966DDEBA8EC4BBBB29CDFDDFF0C7B01FD4D579FF655F3363029059F969B39C9221190672B6A2F7938583594AA0B103FC2A7ED573E2BC1C3A1623DE8DD
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Palau) {.. {-9223372036854775808 -54124 0 LMT}.. {-3944624276 32276 0 LMT}.. {-2177485076 32400 0 +09}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):188
                                                                                                                                                                                                            Entropy (8bit):4.809907977056877
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/nUDHuQTWLMbNMXGm2OHUVFvoHvmXUlgloWkcyf/vGpn:SlSWB9eg/XQyLMJDm2OHUVVoHvmXUKm2
                                                                                                                                                                                                            MD5:3F4987676F9C461895EDF9985AD22E06
                                                                                                                                                                                                            SHA1:A96E470209010B837EF5BB3AC93BAE74BF2CCF64
                                                                                                                                                                                                            SHA-256:5D363729A986E24C79F4B817CC88D2B22ACCCE3ADD20138D51C4422C4297AD6F
                                                                                                                                                                                                            SHA-512:988FB98EFD3F57F5D66A932CC6B9D0387E9B0951FC590E08DAF19ACF5E4F39BC1B25265F16E14930BCF394902F5F0EF507E0E91C98902DFB10FA16D716091AB0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Pitcairn) {.. {-9223372036854775808 -31220 0 LMT}.. {-2177421580 -30600 0 -0830}.. {893665800 -28800 0 -08}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):201
                                                                                                                                                                                                            Entropy (8bit):4.7682565894416005
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3ycaJHNPHAIgObaJHa6N/XyopJHYn:MByMdaJyiaJrtCopJ4n
                                                                                                                                                                                                            MD5:1B418E3A4239AAFE1E15B57FFF913FA1
                                                                                                                                                                                                            SHA1:0E278FCC058DE1B3F4715771819F14568A6C10BB
                                                                                                                                                                                                            SHA-256:F744CD8337C5C72023D61F348DD03F48824F817D62F54ACC6A23DDD8B0F9EDC4
                                                                                                                                                                                                            SHA-512:8E3E10B41CF64A07411B272C0BCA6DC7AA9FFBF625B31075651603B7D0A52A719F7174A67593BFDE45725C243D347D01560B2BC7813C2ABD2F4BF4B1BAD57E56
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Guadalcanal)]} {.. LoadTimeZoneFile Pacific/Guadalcanal..}..set TZData(:Pacific/Pohnpei) $TZData(:Pacific/Guadalcanal)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):200
                                                                                                                                                                                                            Entropy (8bit):4.742862539020017
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3ycaJHNPHAIgObaJHa6N/X3HpBJHYn:MByMdaJyiaJrtHpBJ4n
                                                                                                                                                                                                            MD5:514C399D990C87271812440A4B19FB21
                                                                                                                                                                                                            SHA1:E1512482D10C8984DCD69C883F07C412E144081A
                                                                                                                                                                                                            SHA-256:5BB11553F711BD591617F657A9D1811CC3E3FB46374F6867316A7C8F6B3765D9
                                                                                                                                                                                                            SHA-512:DB227134822EA73407B6C0259FF7413D4961B558F3018BFF51E4E426DDB2DF581DCF7A6DE9E4890CE35F785BC3D07CC880DA883C93D73FFB249F403701BD8023
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Guadalcanal)]} {.. LoadTimeZoneFile Pacific/Guadalcanal..}..set TZData(:Pacific/Ponape) $TZData(:Pacific/Guadalcanal)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):190
                                                                                                                                                                                                            Entropy (8bit):4.945354510868153
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/nUDHuwKXI3SMXGm2OHwdvoHvZUeQTnoo3v/vnqMVVMUMy:SlSWB9eg/X/43SDm2OHwdvoHvZZQTnoQ
                                                                                                                                                                                                            MD5:2CFB7C2A3D26D7AF0F6AE32ADD81C364
                                                                                                                                                                                                            SHA1:80C96E50D23A9A9531E4EE33744CF445C054B901
                                                                                                                                                                                                            SHA-256:124C137B091D9D54D5E0579131485428FAAE040ACC978D20D6A8C8E4DE9889AA
                                                                                                                                                                                                            SHA-512:A215FF5A69BD3E786BD3F8C952C8593396402EFA85005F5342093028617A6862EAE8BFD7B6D5737F90D90897AB62CF785544A4157A222AE4D0F70797FFBEC2CB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Port_Moresby) {.. {-9223372036854775808 35320 0 LMT}.. {-2840176120 35312 0 PMMT}.. {-2366790512 36000 0 +10}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):969
                                                                                                                                                                                                            Entropy (8bit):3.943959457262612
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB86VrjmdHI5Cvn9HCFkN00hjNFq++UE+q0hwA+A7VxVnDEFn:IeZv8w0MNFq+xE+uAtx1c
                                                                                                                                                                                                            MD5:64AD3A103F4D145C48484BF8FACF41C2
                                                                                                                                                                                                            SHA1:40C00CFA56C87E506C254A93A164D7227DFF3BD5
                                                                                                                                                                                                            SHA-256:5AB006A686E564E30C94884FF8A9D728AEC74681DA8772E9722B6FE203630B5D
                                                                                                                                                                                                            SHA-512:D1088C3B673B5456A8706B69BE4D7AB18615EE53A82BF4ABE76E86700837E6BAD0BD79C13EDA9B04776B08A95B835BA755AA565F86E45BFE507E8783896C1EE2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Rarotonga) {.. {-9223372036854775808 48056 0 LMT}.. {-2209555256 -38344 0 LMT}.. {-543072056 -37800 0 -1030}.. {279714600 -34200 0 -10}.. {289387800 -36000 0 -10}.. {309952800 -34200 1 -10}.. {320837400 -36000 0 -10}.. {341402400 -34200 1 -10}.. {352287000 -36000 0 -10}.. {372852000 -34200 1 -10}.. {384341400 -36000 0 -10}.. {404906400 -34200 1 -10}.. {415791000 -36000 0 -10}.. {436356000 -34200 1 -10}.. {447240600 -36000 0 -10}.. {467805600 -34200 1 -10}.. {478690200 -36000 0 -10}.. {499255200 -34200 1 -10}.. {510139800 -36000 0 -10}.. {530704800 -34200 1 -10}.. {541589400 -36000 0 -10}.. {562154400 -34200 1 -10}.. {573643800 -36000 0 -10}.. {594208800 -34200 1 -10}.. {605093400 -36000 0 -10}.. {625658400 -34200 1 -10}.. {636543000 -36000 0 -10}.. {657108000 -34200 1 -10}.. {667992600 -36000 0 -10}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):179
                                                                                                                                                                                                            Entropy (8bit):4.854594370903023
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQG5RFeyXHAIgObT5RV5RL/nUDHtluKpUDH5Rgn:SlSWB9vsM3ycdeSHAIgOb7N/vKbn
                                                                                                                                                                                                            MD5:EFC985F07B24BEDA22993C9D0EA7E022
                                                                                                                                                                                                            SHA1:6D05D12925621F1D05999A5DCC81B8C6F4D18945
                                                                                                                                                                                                            SHA-256:4F6A1C20A11E186012466091CD4B3C09D89D35E7560F93874DEC2D7F99365589
                                                                                                                                                                                                            SHA-512:5FB4D8784D2EB8AEF660D6CBC7C403561EE5874BEC0439762F3688C64830B52B1F557B467CA65B64B1210E82F385E134BF676F3CA443FB480702A2C90B3C3757
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Guam)]} {.. LoadTimeZoneFile Pacific/Guam..}..set TZData(:Pacific/Saipan) $TZData(:Pacific/Guam)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):193
                                                                                                                                                                                                            Entropy (8bit):4.78073436515702
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQGurKeTnXHAIgObTurKefVHRL/nUDHthA5nUDHurK:SlSWB9vsM3yciemHAIgObiecN/NXevn
                                                                                                                                                                                                            MD5:8E335F5D0A2082BB673E7FEB56167A89
                                                                                                                                                                                                            SHA1:EF37235922D4477AC9B3D9576888CDE41E700741
                                                                                                                                                                                                            SHA-256:98D06302EFC18FAD7751F7E5A059FE4ABAFBC361FDC365FE1EB576209D92C658
                                                                                                                                                                                                            SHA-512:2572D99EE8BAF264B8A2EF3D7647D33A387EE83E036F9E7BDB21F64C2FCB43317AF9C899C8CDD822A2A5A207EF17504E71B217370473ED95AE925BBA2CFA90F9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Pago_Pago)]} {.. LoadTimeZoneFile Pacific/Pago_Pago..}..set TZData(:Pacific/Samoa) $TZData(:Pacific/Pago_Pago)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):154
                                                                                                                                                                                                            Entropy (8bit):4.946903999617555
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/nUDHqhFPMXGm2OHl/oeoHsdNqRU7vV:SlSWB9eg/TTPDm2OHloeoH4qRW9
                                                                                                                                                                                                            MD5:341B0F535043051A91A21297BFA39DC0
                                                                                                                                                                                                            SHA1:6AD9177FC237503E6D36DE5408790A68D5D36E2C
                                                                                                                                                                                                            SHA-256:440A87DDB4F304DCBEAED1B0DE8F6058840E597918B688E0782F584DA03B1BBC
                                                                                                                                                                                                            SHA-512:D97D399A0F1B4347F8AE5F15E43A8787697339AB0EFB4E1106C790528FFC529ADC5B44B231D95449D39DB464D84A5DDF7B61E7D190E3E2B0091D1EC204B530A2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Tahiti) {.. {-9223372036854775808 -35896 0 LMT}.. {-1806674504 -36000 0 -10}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):152
                                                                                                                                                                                                            Entropy (8bit):4.969953728206455
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QF08x/nUDHqQ3fMXGm2OHyyFpoeoHvmciRrWFN0UIoAov:SlSWB9eg/T+Dm2OHyyFGeoHvmbu0YAov
                                                                                                                                                                                                            MD5:AA67FBBB6A02F5B30486C54E3A5C11D7
                                                                                                                                                                                                            SHA1:C64FD3654A47A0ECDD681B8A4D9B621AC6D97DBE
                                                                                                                                                                                                            SHA-256:91AA5DA8D5D1E72B1F561D0AEAB4B07E02EDD4EB95AE8C9F1C503C820460599F
                                                                                                                                                                                                            SHA-512:FC170904098011C091622A263CA554CEE952D64888D3573EB324E0A262E1A0C0885C059429F0FFF9219FEB8F1B6B97EC34661DD8DD547124D0C6C0A1C8EE24B7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Tarawa) {.. {-9223372036854775808 41524 0 LMT}.. {-2177494324 43200 0 +12}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):451
                                                                                                                                                                                                            Entropy (8bit):4.343299747430587
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:MB86PmdHmCdC/V7XZXw8Ut2rbUtGiAUtb4bUtqVy:iemn/VbKeOSy
                                                                                                                                                                                                            MD5:87CFDA2399A8126117E5BFC018B06518
                                                                                                                                                                                                            SHA1:6291611BCFB34293F9C20BA77170A13C1502C2ED
                                                                                                                                                                                                            SHA-256:ECC9D2E7AD7B5E5D6599CF442941595C99C4D69E802A4DDB4DA321898CDDE91D
                                                                                                                                                                                                            SHA-512:846FE07FEB82EC5F87FAE137D23074934246DBB7C7EE30F44F6C5373183B5FD2211B58E5CF1AB9A47938D282CA322FBDE80B58054FE6517CDC549992439F19A8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:Pacific/Tongatapu) {.. {-9223372036854775808 44352 0 LMT}.. {-767189952 44400 0 +1220}.. {-284041200 46800 0 +13}.. {915102000 46800 0 +13}.. {939214800 50400 1 +13}.. {953384400 46800 0 +13}.. {973342800 50400 1 +13}.. {980596800 46800 0 +13}.. {1004792400 50400 1 +13}.. {1012046400 46800 0 +13}.. {1478350800 50400 1 +13}.. {1484398800 46800 0 +13}..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):201
                                                                                                                                                                                                            Entropy (8bit):4.903352083734246
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3yci/452HAIgObi/4oA6N/TAOA/4pv:MByMdNXiU5trv
                                                                                                                                                                                                            MD5:443F5FFA58C5DB1F02695C5B76DF4F5E
                                                                                                                                                                                                            SHA1:115AFE9C3EB36F836E2DF95AF42C43EA5C21C1E6
                                                                                                                                                                                                            SHA-256:323A858946A2E8EC67C28176977D646C0A0F6DC8B48F9C4A3F8E7112C9B1B71D
                                                                                                                                                                                                            SHA-512:33717F3423CE06D827445FEA85BE8A989712CF8C06C54A17B9610A4DAD50BF64CAE80DE15AB12AB0610CD6B5582A897DD9C543098108543FA3E6273AAD9467DE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Port_Moresby)]} {.. LoadTimeZoneFile Pacific/Port_Moresby..}..set TZData(:Pacific/Truk) $TZData(:Pacific/Port_Moresby)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):183
                                                                                                                                                                                                            Entropy (8bit):4.771810884789573
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQGqhyXHAIgObTq0vFvRL/nUDHpbhpUDHqNn:SlSWB9vsM3ycmhSHAIgObmSN/0h9Nn
                                                                                                                                                                                                            MD5:992D44D728747D79E1F7EF47E3CB2EF2
                                                                                                                                                                                                            SHA1:8F05E8DA2A2A45F04B9B89BB34F0B7833B56A261
                                                                                                                                                                                                            SHA-256:B6041BC18B595E38953632ACAD1D25F7394BF7C759A72FCCD81AF637F8016373
                                                                                                                                                                                                            SHA-512:C59D360941240C8B11D892A930B6CFE141B1A55007483683AF400B1A0C98EF0BBBE7EF595EF6BA73A6EECB8E3D0658A681CF3203E5E32DE80DD61EDB9C6CBDB0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Tarawa)]} {.. LoadTimeZoneFile Pacific/Tarawa..}..set TZData(:Pacific/Wake) $TZData(:Pacific/Tarawa)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):185
                                                                                                                                                                                                            Entropy (8bit):4.752883303864462
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQGqhyXHAIgObTq0vFvRL/nUDHpEsppUDHqNn:SlSWB9vsM3ycmhSHAIgObmSN/t+9Nn
                                                                                                                                                                                                            MD5:862ADA129322E53235ED5099A72FE8EE
                                                                                                                                                                                                            SHA1:7DAB7BF451CF0FE483EA512C0C733B090FF22EFF
                                                                                                                                                                                                            SHA-256:9601B749413D591D820AFAD431B3C30E577ACAB000EA11EC03DEB36EF0738DC3
                                                                                                                                                                                                            SHA-512:D9C94BE2F08220E49A336A5760DBF43FCB889ADA95E29117AE5E237E33E9EE50BD32203D2743346A21354AF3F1ADDA43A2953FB55205B6FA998A6294CC57F063
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Tarawa)]} {.. LoadTimeZoneFile Pacific/Tarawa..}..set TZData(:Pacific/Wallis) $TZData(:Pacific/Tarawa)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):200
                                                                                                                                                                                                            Entropy (8bit):4.896778032757086
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3yci/452HAIgObi/4oA6N/eP/4pv:MByMdNXiU5teev
                                                                                                                                                                                                            MD5:343CCAC12AEB0DD78FC60405DF938729
                                                                                                                                                                                                            SHA1:B7B4DF0178DEEC2BA6F23AF5CD896CF16CEAF224
                                                                                                                                                                                                            SHA-256:16CF9FAB116E5E1732B4B601DA919798985A0C15803F0964844C7040894C5DBA
                                                                                                                                                                                                            SHA-512:041609C63E95322460A31AC83BCC4F8F90B8D44B2740A5CF7E37F66CCD9F928416D74D313370516D7B1780DF2C9C9A78B7069CE2DA6BFFE88C46FB47CE1A4CB2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Port_Moresby)]} {.. LoadTimeZoneFile Pacific/Port_Moresby..}..set TZData(:Pacific/Yap) $TZData(:Pacific/Port_Moresby)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):174
                                                                                                                                                                                                            Entropy (8bit):4.940195299412468
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVqEGIV5XHAIgoqpEGYvWARL/nSi67x/yQa0EGIy:SlSWB9vsM3ymc4HAIgocVAN/27x6qF
                                                                                                                                                                                                            MD5:E6AA2F6A05B57AA9B4AEF8E98552EEB2
                                                                                                                                                                                                            SHA1:22470C204152702D8826CA52299E942F572C85ED
                                                                                                                                                                                                            SHA-256:C27E1179B55BF0C7DB6F1C334C0C20C4AFA4DBB84DB6F46244B118F7EAB9C76E
                                                                                                                                                                                                            SHA-512:B28A264907C32F848D356FB0F5776C2CE819DCB6BC08A5E2DCD4FA455EE1616966E816748079C7A55485BABFFB292D567E6F958168F945889E33A267B0E7EDA9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Warsaw)]} {.. LoadTimeZoneFile Europe/Warsaw..}..set TZData(:Poland) $TZData(:Europe/Warsaw)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):176
                                                                                                                                                                                                            Entropy (8bit):4.9353841548970205
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVxMvLS3vXHAIgoqyMvLL6RL/nM24h8QavMvLBn:SlSWB9vsM3ymvMv2PHAIgovMvH6N/e8i
                                                                                                                                                                                                            MD5:7D7BD6E40D3ADCA04754255D69B5CC9D
                                                                                                                                                                                                            SHA1:EE32167B450DE7B0F1A15199795AEF9524BE623B
                                                                                                                                                                                                            SHA-256:EFD666F3062D52C5D0B4F83B1A206E6840C1EAEC356CD77A0A71C7EDFA78C964
                                                                                                                                                                                                            SHA-512:6056AAF078316A89079D19555F0BAEFB4C1CDBAA5426A8BEE76E0BFA5C69A5DAAFD199DEF978ABD67287AE1B80F754B7845EAFD5CC0995FE10E44D1F34D5435C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Lisbon)]} {.. LoadTimeZoneFile Europe/Lisbon..}..set TZData(:Portugal) $TZData(:Europe/Lisbon)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):165
                                                                                                                                                                                                            Entropy (8bit):4.795776391333205
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8qMveyXHAIgNqBLFARL/lOr4WFKfMy:SlSWB9vsM3yKMveSHAIgcBJAN/S4wKfB
                                                                                                                                                                                                            MD5:C5AE3A1DAD32C870651C74E367F604CF
                                                                                                                                                                                                            SHA1:9FF81383C43D98441841E182BC783381EF565204
                                                                                                                                                                                                            SHA-256:9AEC39777013B23D63D0509EBB2F01D57A2C1592264DBB19CE2C61C7D7DDD8DE
                                                                                                                                                                                                            SHA-512:3A7217ED885011972262B71DB7F5D7E4C9C6E82B4BEEF0718BCB9452E49FDBDD5ED78564156577AB09150140B862E1944B4B739BCE0C50E63667050C35329503
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Taipei)]} {.. LoadTimeZoneFile Asia/Taipei..}..set TZData(:ROC) $TZData(:Asia/Taipei)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):162
                                                                                                                                                                                                            Entropy (8bit):4.900717350092823
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq8ZQckovXHAIgNtvQMHRL/lmFeWFKKQ7:SlSWB9vsM3yJJHAIgbHN/pwKv
                                                                                                                                                                                                            MD5:59E4C80F97FAFC92987B08BFA03B5EE5
                                                                                                                                                                                                            SHA1:4F86FCE17A51C3789DEB887BE01A1A0E6EA3D2DE
                                                                                                                                                                                                            SHA-256:63153B40225270ADB7CD248788CA9F18C6DEBAF222B3165BBAB633337592DF44
                                                                                                                                                                                                            SHA-512:9FCC0F747096775D0FB8DD252A73E6F47C16BF2D7DB0C3FBDFD206EE57393276FB40F65C1441296AE2AC115CFEE11098474DF3FEF8EE1FABE139427A8991F052
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Seoul)]} {.. LoadTimeZoneFile Asia/Seoul..}..set TZData(:ROK) $TZData(:Asia/Seoul)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):180
                                                                                                                                                                                                            Entropy (8bit):4.85623787837429
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyq801c3vXHAIgNtK1tyHRL/kZ8O5h4WFKf1z:SlSWB9vsM3yUgHAIgWv6N/kth4wKf9
                                                                                                                                                                                                            MD5:5EABBAAF3B29B5DFF9E54136F7ABC654
                                                                                                                                                                                                            SHA1:44615F03264012D97512F9AB386413DD72BE1090
                                                                                                                                                                                                            SHA-256:B9443FB17F0128DDB9F2DF657DC5D2DF176F64C61B0D02B272E5DFB108537678
                                                                                                                                                                                                            SHA-512:B930D637A1E69E0847ADDEAB013B2C25BC27EBB9CDF20B9CDDFDAC111E9F26BB5EBC83194E845ACC3E1B9A08C386C94FCC4FDE32292EB558E3F7463832BB38B9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Asia/Singapore)]} {.. LoadTimeZoneFile Asia/Singapore..}..set TZData(:Singapore) $TZData(:Asia/Singapore)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):201
                                                                                                                                                                                                            Entropy (8bit):4.996391010176349
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSNJB9vsM3y7p5oeSHAIgppON/kjx+90ppv:JByMYbpwt8+90b
                                                                                                                                                                                                            MD5:1AC81E2C60D528A6C5BF2E6867146813
                                                                                                                                                                                                            SHA1:73D2D24FE6D56CA34ABF11B9A95DC22F809C5158
                                                                                                                                                                                                            SHA-256:978C4E5256057CE7374AD7929605090FC749B55558495BD0112FB0BB743FA9C2
                                                                                                                                                                                                            SHA-512:DB2673FB54C1308BBEB298A186F9130FB9090CE33B958C82D62B9BD88EE39BAB9A1BE40645547BA4167FD475892A323CF8EBA16C97F6FDF5693F1BF7A313FE9A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Puerto_Rico)]} {.. LoadTimeZoneFile America/Puerto_Rico..}..set TZData(:SystemV/AST4) $TZData(:America/Puerto_Rico)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):192
                                                                                                                                                                                                            Entropy (8bit):4.9470542553730255
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFLLJJT8QFtFb+MuUyqx02NEO/vXHAIg202NEqA6RL/kRDwh4IAcGE2NEOyn:SlSNJB9vsM3y7UEOXHAIgpUEqA6N/k+H
                                                                                                                                                                                                            MD5:2AB4B896957F26B114A990F69989F3FB
                                                                                                                                                                                                            SHA1:8048C99F5EE02C021F311709B30EB28D650D884D
                                                                                                                                                                                                            SHA-256:0114C111F5BCD838A28F2E16E01ECB79D8AFC8CBF639A672889ED0D692FC6CDC
                                                                                                                                                                                                            SHA-512:353744359CD94B1E8184A8B83F762459C69D3AEEA43DA638C1F4CC34E01E9D86C2EBCF7F7BFD059CB23B64051510D1C4556A49D180F8A92DE8449139194DCDC9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Halifax)]} {.. LoadTimeZoneFile America/Halifax..}..set TZData(:SystemV/AST4ADT) $TZData(:America/Halifax)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):186
                                                                                                                                                                                                            Entropy (8bit):4.957831162100758
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFLLJJT8QFtFb+MuUyqx0sAzE5Y5XHAIg20sAzEo5RL/kR/eIAcGEsAzEpv:SlSNJB9vsM3y7hzi2HAIgphznN/kc90q
                                                                                                                                                                                                            MD5:3EC0B09EAB848821D48849673B24401C
                                                                                                                                                                                                            SHA1:41599CBA78E124A7DA9744D2B4EA8CDC10008E0B
                                                                                                                                                                                                            SHA-256:30428B85B37898AD98B65BE5B6A8BD599331D9A1B49605FC6521464228E32F8F
                                                                                                                                                                                                            SHA-512:9A3303B3338C01B281A40BB48B93C446ADB92BBDC45371667F09EDA92F9EE2AEC60CE8E98CE15C0112B823799C76AEF14895B15DC997DA506494D75BBE58D662
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Regina)]} {.. LoadTimeZoneFile America/Regina..}..set TZData(:SystemV/CST6) $TZData(:America/Regina)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):192
                                                                                                                                                                                                            Entropy (8bit):4.975428048518589
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFLLJJT8QFtFb+MuUyqx096yXHAIg20961yHRL/kRwx/h4IAcGE967:SlSNJB9vsM3y796SHAIgp9616N/kyxpQ
                                                                                                                                                                                                            MD5:D85CCC5EFAA1ED549D02F09A38A53C68
                                                                                                                                                                                                            SHA1:642ED571E4C6F60A953D42DA4F756F2262E4E709
                                                                                                                                                                                                            SHA-256:44BEF7D4660A9A873EB762E3FDC651D31D97893545DE643FA1B2D05991C090A1
                                                                                                                                                                                                            SHA-512:3CC6A14A17EA4833958A7D444073D6C2709FD61BF54387E5C362151E9143F795B2432B621080DD53E0FC9BDD7C58F406E046E3D0A2BBA4132D99E7C705E6D645
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Chicago)]} {.. LoadTimeZoneFile America/Chicago..}..set TZData(:SystemV/CST6CDT) $TZData(:America/Chicago)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):204
                                                                                                                                                                                                            Entropy (8bit):4.928128138328689
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSNJB9vsM3y73G7JHAIgp3GZRN/kkp4903G8:JByMY3G7Kp3GntVp4903G8
                                                                                                                                                                                                            MD5:506D15E2F37F501F5A592154142A5296
                                                                                                                                                                                                            SHA1:5ACA12E0BA0FFF9734ED978A9C60AAA9D1E05A59
                                                                                                                                                                                                            SHA-256:798F92E5DDA65818C887750016D19E6EE9445ADFE0FCB7ACB11281293A09C2C7
                                                                                                                                                                                                            SHA-512:2EE08D39461CAD3492BE88B421BA463B4CEB8497F036518794BCF605F477057FEA218A9DFBB6335A28A5120750EA06AED9D2EA84CD0007D34CDE562DCD79CC0C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Indianapolis)]} {.. LoadTimeZoneFile America/Indianapolis..}..set TZData(:SystemV/EST5) $TZData(:America/Indianapolis)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):195
                                                                                                                                                                                                            Entropy (8bit):5.113680059406992
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSNJB9vsM3y71RHAIgp1aAN/krp4901Yn:JByMY4pltw+90q
                                                                                                                                                                                                            MD5:AAD8EF3067E97785D4052B80F5C4ACE1
                                                                                                                                                                                                            SHA1:3EF0A06FCC41119F4A60A32CED0E5A1E0E8B4300
                                                                                                                                                                                                            SHA-256:D159140114A13C69F073CFE9AD0B67D713E8811CBFF773A3D1681FC38EA0E699
                                                                                                                                                                                                            SHA-512:A8774ADF6818D85476A6C147A45E55B338F413CD9B61BF9FDB0CB7A335C0CE8F8C6D1970783FEFECC2CE18388DF91304CB295BD4DFD29FB538D74F6A414A441D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/New_York)]} {.. LoadTimeZoneFile America/New_York..}..set TZData(:SystemV/EST5EDT) $TZData(:America/New_York)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):193
                                                                                                                                                                                                            Entropy (8bit):4.9733028894475195
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSNJB9vsM3yc6e8SHAIgOb6eKAN/kQmrheo:JByMdniinbtRTo
                                                                                                                                                                                                            MD5:458061B3F3C8F06C61B5726393A26BA2
                                                                                                                                                                                                            SHA1:E894F5615654D1110C9964B8F6A54C048442D8EB
                                                                                                                                                                                                            SHA-256:BF62C8650BBA258000F62F16B0C7CBB66F4FD63F8CFDAF54273BB88A02A6C8D6
                                                                                                                                                                                                            SHA-512:6A161A7AE44CBF8CE4C704C94456A5B714AAF2A3FAF30731254C9FE056F9DDF207119D516CC6A4C44AE76EC078F5C59F5EC6DD6701FAA3A36F061AF3953B7C7D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Honolulu)]} {.. LoadTimeZoneFile Pacific/Honolulu..}..set TZData(:SystemV/HST10) $TZData(:Pacific/Honolulu)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):189
                                                                                                                                                                                                            Entropy (8bit):4.999038624718282
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFLLJJT8QFtFb+MuUyqx0utLaDovXHAIg20utLRYovHRL/kRgFfh4IAcGEuto:SlSNJB9vsM3y7OBHAIgpONYyHN/kch4y
                                                                                                                                                                                                            MD5:B06AB4998A57446FC4D5A5B986BCA0A9
                                                                                                                                                                                                            SHA1:5E4A28466383CBAB2067B9B6D22882CF6D83C3FB
                                                                                                                                                                                                            SHA-256:FEBE49FAE260E5595B6F1B21A0A3458D8A50ACA72F4551BF10C1EDB2758E0304
                                                                                                                                                                                                            SHA-512:9E44174C4E348E1B768039585BA6393FD001B606E111092EEC57C75210A1E87BF3C72728321945D584CA60D4C848D88EB8B2F82CB88F38F90224A43FDCFEA9AA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Phoenix)]} {.. LoadTimeZoneFile America/Phoenix..}..set TZData(:SystemV/MST7) $TZData(:America/Phoenix)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):189
                                                                                                                                                                                                            Entropy (8bit):4.956231227702093
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFLLJJT8QFtFb+MuUyqx06RGFfXHAIg206RORL/kRMMFfh4IAcGE6RB:SlSNJB9vsM3y7+SPHAIgp+ON/kD490+B
                                                                                                                                                                                                            MD5:5D3C1ADB8AC4EAC9E9A31734CD6884BD
                                                                                                                                                                                                            SHA1:535B024EA088B9B192BE4206CBDD56BC5B163762
                                                                                                                                                                                                            SHA-256:64556A7B20E425C79375C2A7CCF72B2B5223A7DE4FF4C99A5C039DB3456C63F6
                                                                                                                                                                                                            SHA-512:FB799A42880613752AD6010D7B4E97ACCF7F6AE281D9A37057F6423AEF2607B608DB2AC52176F1653D8B2D086223C9658B101E73125F0FF7D6D9E8CD876EEC53
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Denver)]} {.. LoadTimeZoneFile America/Denver..}..set TZData(:SystemV/MST7MDT) $TZData(:America/Denver)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):192
                                                                                                                                                                                                            Entropy (8bit):4.831981174214766
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFLLJJT8QFtFb+MuUyqTQGuQTWLM4YkovXHAIgObTuQTWLovFvHRL/kRQB5nv:SlSNJB9vsM3yciQyLM4YJHAIgObiQyLQ
                                                                                                                                                                                                            MD5:B568B46A0207800D9C022BAB1E48709B
                                                                                                                                                                                                            SHA1:71CE3F0E75E440D5BBA219BCBB92AF9C1F5A7466
                                                                                                                                                                                                            SHA-256:0B8227AFC94082C985E8E125DF83E5EFADE7CD9CA399800D7B8E8B2BEAE22C7D
                                                                                                                                                                                                            SHA-512:5067AAD0CD02EBDECA6980F9C7CCC80D076C34D6463C5B6B19B678D76B5E69C1C3639D046F56FE9D6255CBEA49189EDD735F66AD9EE2CB0389BE020E7ED3AD50
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Pitcairn)]} {.. LoadTimeZoneFile Pacific/Pitcairn..}..set TZData(:SystemV/PST8) $TZData(:Pacific/Pitcairn)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):204
                                                                                                                                                                                                            Entropy (8bit):5.003766957083974
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSNJB9vsM3y7DvPHAIgp5N/kQ1p490Dy:JByMY8p5th090W
                                                                                                                                                                                                            MD5:7E587175CA0F938C47FA920D787C57BD
                                                                                                                                                                                                            SHA1:C3F7D8576C0AC74D6B70F4363EE2C174FADC70B0
                                                                                                                                                                                                            SHA-256:D51D9549835E9C058F836C8952932CB53C10F7F194CD87452E9B13494D1C54C9
                                                                                                                                                                                                            SHA-512:4460686AAA470F07A6DB1F8957FA4DB600E116273497F46E8A2D3FDECF622122DF753556B78C39FA2ADFDB2AF3C3ABB3C330ADA79B35C6A3CD8C498A0319CEE6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Los_Angeles)]} {.. LoadTimeZoneFile America/Los_Angeles..}..set TZData(:SystemV/PST8PDT) $TZData(:America/Los_Angeles)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):189
                                                                                                                                                                                                            Entropy (8bit):4.9524733332469095
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFLLJJT8QFtFb+MuUyqTQG5hB5WXHAIgObT5hByY6RL/kRKlUDH5hBpvn:SlSNJB9vsM3ycT2HAIgOboN/kNv
                                                                                                                                                                                                            MD5:5970A466367825D72D9672293FCD4656
                                                                                                                                                                                                            SHA1:1A736D61A6797295EEC8C094AED432171E98578E
                                                                                                                                                                                                            SHA-256:55710EFDED5B5830B2F3A2A072037C5251E1766F318707ED7CD5EB03037FED43
                                                                                                                                                                                                            SHA-512:1F2A1B2A7D0A3E410652546C174D9EC18C91C9327F11C384A0AA1EB12D7EFE85C4D53CA3C2A6C347C0068A4CE92A3138EB17232B0DEC88D52465C5DEDEEE6827
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Gambier)]} {.. LoadTimeZoneFile Pacific/Gambier..}..set TZData(:SystemV/YST9) $TZData(:Pacific/Gambier)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):198
                                                                                                                                                                                                            Entropy (8bit):4.994125896811442
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSNJB9vsM3y7/9EtDSHAIgp/9Ef6N/kB490/9E9v:JByMY/947p/9XtN90/9s
                                                                                                                                                                                                            MD5:560B18DFB138DAF821CFDAE017B94473
                                                                                                                                                                                                            SHA1:0BB0312C742CC0097DF033656AE3D10723035C30
                                                                                                                                                                                                            SHA-256:DA20018DE301F879E4F026405C69FA0370EB10184FE1C84A4F1504079D5DAFA1
                                                                                                                                                                                                            SHA-512:B1D4EAD5F549E319DAD55EE67DAFD732E755164748C08633AA8F07C280B2CF617380D6F886304142D0E4D50026E63678DACFBE2DC809F780BA4CFF35A90DE906
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by ../tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Anchorage)]} {.. LoadTimeZoneFile America/Anchorage..}..set TZData(:SystemV/YST9YDT) $TZData(:America/Anchorage)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):180
                                                                                                                                                                                                            Entropy (8bit):4.9295990493611495
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxV0XaDovXHAIgoq3XRFvHRL/jCl1yQaqXKv:SlSWB9vsM3ymQa2HAIgoQ/HN/SymKv
                                                                                                                                                                                                            MD5:1FABF2DFD4BFD0184AE22ED76F7569E5
                                                                                                                                                                                                            SHA1:5859266B26357B4FCADD7EC65847667631E303EB
                                                                                                                                                                                                            SHA-256:8471A5575B9D9E47412D851A18A26C4405480540AABC8DAED5F81BE0C714C07C
                                                                                                                                                                                                            SHA-512:1DCBECEF6D1F923E6C9CEA70CB10F1FF4E453265966AA88FBC8739E93EF40F8A16AAD85AF4ECC5CC1E52F22F49E5D3F4EE01A97DE2302FC4FBC063FE814F3851
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Istanbul)]} {.. LoadTimeZoneFile Europe/Istanbul..}..set TZData(:Turkey) $TZData(:Europe/Istanbul)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):153
                                                                                                                                                                                                            Entropy (8bit):4.844017562912325
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqAxmS3vXHAIgELyHRL/iGMFfh8RFB:SlSWB9vsM3yzTHAIgm6N/iP8RX
                                                                                                                                                                                                            MD5:DA060D2F397C978E0842631B4EC73376
                                                                                                                                                                                                            SHA1:649BC85430B04662BE079C0AAD43DF5D5D499D28
                                                                                                                                                                                                            SHA-256:356A9BB6F831971C295CF4DCE0F0CDC9EDF94FD686CA3D3195E5F031A0B67CBA
                                                                                                                                                                                                            SHA-512:3359BFC6F0837D2DA9D72DA8053773CE0C1A1B1A47C33163BF38965E2104F57BC147F9EEC228A3591B75BF1BA93285AB83E8427E8E2E697AB18501DC017B6E6A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:UCT) $TZData(:Etc/UTC)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):189
                                                                                                                                                                                                            Entropy (8bit):4.911775112130145
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0/VXEtDovXHAIg20/VXEfovRL/iOGl0IAcGE/VXEN:SlSWB9vsM3y7/9EtDSHAIgp/9Ef6N/i4
                                                                                                                                                                                                            MD5:4379C0BF618649AA07CC4BDAC75F62EF
                                                                                                                                                                                                            SHA1:7813B54BF2BD0C40A39CA9A29CC50C6D034880A3
                                                                                                                                                                                                            SHA-256:CED56F09D68BE00555219594C7B2F3E7EFE8323201FB3E2AA0E1FA9A6467D5AF
                                                                                                                                                                                                            SHA-512:AC822061F5C9743120A66E11C02B199253A40460A87F78DC154B0BDD91E410EDDA581E889F5D2A74670939034F39A7F6C7E814E038A1371DAB71EF79A8911AE7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Anchorage)]} {.. LoadTimeZoneFile America/Anchorage..}..set TZData(:US/Alaska) $TZData(:America/Anchorage)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):176
                                                                                                                                                                                                            Entropy (8bit):4.8886795125313585
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0/yO5WXHAIg20/yOoNvWARL/iObMEIB/4IAcGE/y2:SlSWB9vsM3y7/yrHAIgp/yH0AN/itE8h
                                                                                                                                                                                                            MD5:AB14CF1840CBDA2B326660DBD51273B4
                                                                                                                                                                                                            SHA1:78144B3A2C75568307E4E86AE3B01EA7F541B011
                                                                                                                                                                                                            SHA-256:A4F1398CF84D0AE09BF19288770756622D1710CCBFBFE79E0D3239497731287D
                                                                                                                                                                                                            SHA-512:557A3ED9D1401E76291DC41524A1FD04AFF0829CEF66E103CEF9D10CD751F04FDEB6B7C0490302C71297F53AA8DC42930649AD274215D5DF068BCDE837E73756
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Adak)]} {.. LoadTimeZoneFile America/Adak..}..set TZData(:US/Aleutian) $TZData(:America/Adak)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):184
                                                                                                                                                                                                            Entropy (8bit):4.9334626069754455
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0utLaDovXHAIg20utLRYovHRL/iQMfQfBx+IAcGEB:SlSWB9vsM3y7OBHAIgpONYyHN/iZfQfl
                                                                                                                                                                                                            MD5:30ED80335BE37C7CBA672C33FDE23490
                                                                                                                                                                                                            SHA1:B627E86F023FE02A5590FE8D55FF41946BE6D24B
                                                                                                                                                                                                            SHA-256:9503403F231BA33415A5F2F0FDD3771CE7FF78534CE83C16A8DB5BC333B4AD8A
                                                                                                                                                                                                            SHA-512:C1352612EC0B4FF2F6F279CDB6008D7E9DA7F94F0009EFD959AD3092393150ECA83A09E72C724E1A4BFC3A057B9218D54A87FFA1102E2D9BF058B78AC0A0B1AB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Phoenix)]} {.. LoadTimeZoneFile America/Phoenix..}..set TZData(:US/Arizona) $TZData(:America/Phoenix)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):184
                                                                                                                                                                                                            Entropy (8bit):4.90255068822036
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx096yXHAIg20961yHRL/ibXgox/h4IAcGE967:SlSWB9vsM3y796SHAIgp9616N/iB490+
                                                                                                                                                                                                            MD5:7770A6B85B2FE73BCCE9D803E0200F23
                                                                                                                                                                                                            SHA1:784AD1082FF1569961C2AC44F6D6F7605FBBE766
                                                                                                                                                                                                            SHA-256:B6AC9FAE0AB69D58ECFD6B9A84F3C6D3E1A594E40CEEC94E2A0A7855781E173A
                                                                                                                                                                                                            SHA-512:EEE79D37D77E6B80B91E8F30CE48B107371F6A58F0C91785E3C74EF210AE1011D0EB913113F1873BE6099B0BE1260410F0C74650446CB377F8FDB5505A44F266
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Chicago)]} {.. LoadTimeZoneFile America/Chicago..}..set TZData(:US/Central) $TZData(:America/Chicago)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):228
                                                                                                                                                                                                            Entropy (8bit):4.7645631776966715
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y73GK7JHAIgp3GKZRN/i3E0903GK8:MByMY3GK7Kp3GKnti3t903GK8
                                                                                                                                                                                                            MD5:96828B6BA17CA96723794F4B3744B494
                                                                                                                                                                                                            SHA1:C3A824A925AEFE2A13A0E65548078D9842C2C7D7
                                                                                                                                                                                                            SHA-256:5D86F8D36598516FB2342A18A87DB2701BABD265B0671CC9321C48DB22C7ECA5
                                                                                                                                                                                                            SHA-512:2A27A455787DEAC3EC78A2784FB989DAB178E9D6DD7721CD3F5D3337231A3C651994B964D6CE040B7858E0127D7F70C0C48CB0D553D5B725B649C828288224B5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Indiana/Indianapolis)]} {.. LoadTimeZoneFile America/Indiana/Indianapolis..}..set TZData(:US/East-Indiana) $TZData(:America/Indiana/Indianapolis)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):187
                                                                                                                                                                                                            Entropy (8bit):5.0345860115708785
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0wAy0vfXHAIg20wAyGWARL/i37oxp4IAcGEwAy0yn:SlSWB9vsM3y71RHAIgp1aAN/i37oxp4P
                                                                                                                                                                                                            MD5:375DB249106C5D351CA0E84848835EDB
                                                                                                                                                                                                            SHA1:ECC5C0C9DA68773B94C9013F4F1A8800D511CC4C
                                                                                                                                                                                                            SHA-256:2FFCAD8CBEF5ECDC74DB3EE773E4B18ABC8EFA9C09C4EA8F3A45A08BADAF91A9
                                                                                                                                                                                                            SHA-512:21550743BF4E1A79754F76AB201F0EB6BA6B265F43855901640054316A4A32A5D01D266B2441E4A6415720715A2ABD367D82E3D40949A7A66BE9F8366E47A8DD
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/New_York)]} {.. LoadTimeZoneFile America/New_York..}..set TZData(:US/Eastern) $TZData(:America/New_York)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):186
                                                                                                                                                                                                            Entropy (8bit):4.88075715646936
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQG2fWGYFeyXHAIgObT2fWKARL/ioMN75nUDH2fWWv:SlSWB9vsM3yc6e8SHAIgOb6eKAN/ioER
                                                                                                                                                                                                            MD5:C0475756CFEC302F737967468804846E
                                                                                                                                                                                                            SHA1:85C13CA0A908C69B8BBB6040FC502AFF96B8F8C7
                                                                                                                                                                                                            SHA-256:529BB43EFDA6C1584FEAEA789B590CEF1397E33457AB3845F3101B1FC126E0FB
                                                                                                                                                                                                            SHA-512:D3FF374443344E8438D50803872E8A8EA077B2299B38C1BD155386B4D2C6008BBD0C0B0B26DE9680812D4AFC9A187B644BDCCB04C23880337228BCEC06D5D61B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Honolulu)]} {.. LoadTimeZoneFile Pacific/Honolulu..}..set TZData(:US/Hawaii) $TZData(:Pacific/Honolulu)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):206
                                                                                                                                                                                                            Entropy (8bit):4.87340978435866
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:SlSWB9vsM3y73GKaHAIgp3GKIN/iGIfh4903GKT:MByMY3GKDp3GKItiBfh4903GKT
                                                                                                                                                                                                            MD5:00AAFD60A0B1146274981FAB6336AFD9
                                                                                                                                                                                                            SHA1:20AD47ED52874202585C90FE362663F060E064D3
                                                                                                                                                                                                            SHA-256:5827B6A6D50CF0FB75D6BA6E36282591AD25E1F0BE636DCFC5D09BDA29A107FD
                                                                                                                                                                                                            SHA-512:61113AB72B7D671D7B429106709E73DB57D5B8A382680BA37A54126C7F54BC2D6B47A2584177CE6B434793546DA7EB9B8B7DF9163816DBFC67C83D9930D6A158
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Indiana/Knox)]} {.. LoadTimeZoneFile America/Indiana/Knox..}..set TZData(:US/Indiana-Starke) $TZData(:America/Indiana/Knox)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):185
                                                                                                                                                                                                            Entropy (8bit):4.83459089067994
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx06FQGFfXHAIg206FQJARL/iHaMCELMr4IAcGE6FQB:SlSWB9vsM3y74PFPHAIgp4KAN/iHaMHs
                                                                                                                                                                                                            MD5:D955A5A943B203DC4B87A91ED196B82A
                                                                                                                                                                                                            SHA1:C7ACC48AB2033C372C60C741F68B12FFAEA147DE
                                                                                                                                                                                                            SHA-256:B4E4269C4FEBFEFF26750B297A590226C0A6872519A6BFDE36F6DC3F6F756349
                                                                                                                                                                                                            SHA-512:445DC9A50487A4BA0A7F79078441696DCAA31F9988E5B515B5A827AC9275776B22DE303040900C1726EB99CABA8AD09E57AA674F798EA3FDEBC580E4B87D9439
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Detroit)]} {.. LoadTimeZoneFile America/Detroit..}..set TZData(:US/Michigan) $TZData(:America/Detroit)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):182
                                                                                                                                                                                                            Entropy (8bit):4.892777905787396
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx06RGFfXHAIg206RORL/iBOlLo/4IAcGE6RB:SlSWB9vsM3y7+SPHAIgp+ON/iBY8/49Z
                                                                                                                                                                                                            MD5:E53EDD55E6448C624DD03A8A100EF5AF
                                                                                                                                                                                                            SHA1:1D266553CAFA23A3375CFAF7AFE6636553CC7B70
                                                                                                                                                                                                            SHA-256:3763BF520D3C97148C34DCFBDF70DEC2636D4E38241555900C058EFEE3BD1256
                                                                                                                                                                                                            SHA-512:B7FCF01DBB4231F30FEFA77C339B2CD7D984D6E6182F3BD15D6B64AC9525994E7CBF90C3F1F520FD22B54E19831B3CBAE1C22F04F60244C0C60A1809942422A4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Denver)]} {.. LoadTimeZoneFile America/Denver..}..set TZData(:US/Mountain) $TZData(:America/Denver)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):196
                                                                                                                                                                                                            Entropy (8bit):4.932311644026309
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqx0ydJg4o3vXHAIg20ydJPyHRL/iP+e2IAcGEydJgov:SlSWB9vsM3y7DvPHAIgp5N/ip290Dy
                                                                                                                                                                                                            MD5:37AF94FAB52D80AF32C766644892E36D
                                                                                                                                                                                                            SHA1:03CE96A3B3EBFC16C9ED192DD2127FB265A7ED49
                                                                                                                                                                                                            SHA-256:54E5F126D4E7CC13555841A61FF66C0350621C089F475638A393930B3FB4918C
                                                                                                                                                                                                            SHA-512:405A7F414FA0864111E5E9F06FCA675BF4EF11FE0F82F5438416273BEF820A030A50E4D43E4E522ED79C08C0C243E9DD3692971DC912C9ADFB1BEABEB935CDDC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(America/Los_Angeles)]} {.. LoadTimeZoneFile America/Los_Angeles..}..set TZData(:US/Pacific) $TZData(:America/Los_Angeles)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):188
                                                                                                                                                                                                            Entropy (8bit):4.838968615416201
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqTQGurKeTnXHAIgObTurKefVHRL/i6A5nUDHurKeTyn:SlSWB9vsM3yciemHAIgObiecN/idXevn
                                                                                                                                                                                                            MD5:509CF35F5F7C9567FD19CC5C137DC070
                                                                                                                                                                                                            SHA1:AA5F27D36BC617A6A4107E3CA0CB0C10A71A1D9E
                                                                                                                                                                                                            SHA-256:E51FC51C65FFEAB514D7636271157EE8941BDACF602CBC380F5D60B5FA674E87
                                                                                                                                                                                                            SHA-512:E23633A16F11015F3FE2F4E675B5A60B4FDC61F8CF152FDB9BA7ED4C213B8897117721A78C5470296DAFB0FD4F0DDC019DD0DB8C28C1F1B2BE0D3A289F53D5B3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Pacific/Pago_Pago)]} {.. LoadTimeZoneFile Pacific/Pago_Pago..}..set TZData(:US/Samoa) $TZData(:Pacific/Pago_Pago)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):153
                                                                                                                                                                                                            Entropy (8bit):4.844017562912325
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqAxmS3vXHAIgELyHRL/iLB5h8RFB:SlSWB9vsM3yzTHAIgm6N/iLfh8RX
                                                                                                                                                                                                            MD5:3402C8784654C24F7E956731866B833F
                                                                                                                                                                                                            SHA1:C34F3CCA074A50E6564B8C78683C8763B37A3002
                                                                                                                                                                                                            SHA-256:DEE28FF84E3FC495ED3547D5E5E9FAFDACC36A67329E747D434248ED45BF1755
                                                                                                                                                                                                            SHA-512:FBA2840B0FA0F084EE9840BCF56E497F8A7ABF509FA10FA66FB26BA3D80079C4F9A363577A453CD68557080EAF9DD7F1F7B5AF957B64BDA2A897B1E08C85DD19
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:UTC) $TZData(:Etc/UTC)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):159
                                                                                                                                                                                                            Entropy (8bit):4.879221007428352
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqAxmS3vXHAIgELyHRL/iL7DJMFfh8RFB:SlSWB9vsM3yzTHAIgm6N/iL7VMr8RX
                                                                                                                                                                                                            MD5:5F24A249884C241D1E03D758C2641675
                                                                                                                                                                                                            SHA1:63AAC15A68659006F8A14FEC3F2A66B55A8AC398
                                                                                                                                                                                                            SHA-256:B7B0B82F471D64704E1D6F84646E6B7B2BD9CAB793FAD00F9C9B0595143C0AB7
                                                                                                                                                                                                            SHA-512:A7AB5E26A2C23BA296942D7C524C6EE6708A9A38CDD88022EA92E2180BC3CCFE930758FC20A24A0D271AD70733EB924B0E530FBF83CC0FC49EAD411B28503CC0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:Universal) $TZData(:Etc/UTC)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):172
                                                                                                                                                                                                            Entropy (8bit):4.999171213761279
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqxVwTwWXHAIgoqzTbNOARL/gIuyQauTgvn:SlSWB9vsM3ymSHAIgoXAN/gXy5n
                                                                                                                                                                                                            MD5:5444E85070CA2E7A52D38D6D53216B88
                                                                                                                                                                                                            SHA1:0F9A4FB1156312EBD0B9C81DA2164E89D21878E1
                                                                                                                                                                                                            SHA-256:F7DA75B585F45AB501B2889E272FF47B1C4A1D668E40AED7463EB0E8054028C2
                                                                                                                                                                                                            SHA-512:BBC94F98C84641392D3A4B67C152E92EDB3011DA329319ADB2485DBEAFD44DED328D80FBCA89E58687E1F0EB6BED8580BBB0075CA42284B6206A8641D76F2DE5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Europe/Moscow)]} {.. LoadTimeZoneFile Europe/Moscow..}..set TZData(:W-SU) $TZData(:Europe/Moscow)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):6945
                                                                                                                                                                                                            Entropy (8bit):3.7806395604065135
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:v6PgDGfXCiZoFtFPIaFF1w0urfva946ZGsE3f2Sf+aCNmSv+kznl4klEp8OT:rQbkIaFF1w0us4qE3+sSGjT
                                                                                                                                                                                                            MD5:1EC38B05B53ECF2DD3A90164C4693934
                                                                                                                                                                                                            SHA1:00900F0ADDB7526C63C67CA1662C038E95A79245
                                                                                                                                                                                                            SHA-256:7E6E2369C19DD19A41BE27BB8AD8DF5BE8B0096ED045C8B2C2D2F0916D494079
                                                                                                                                                                                                            SHA-512:47A8DAAB1B891FF09A94AF01B6673213392F70C6C1EE53D95A59D6E238FD06B0E80FA21C7279A9ADA891F5CA5B86E4D6B696EE8CFE14BFEF0ACCC9759AF1419A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit....set TZData(:WET) {.. {-9223372036854775808 0 0 WET}.. {228877200 3600 1 WEST}.. {243997200 0 0 WET}.. {260326800 3600 1 WEST}.. {276051600 0 0 WET}.. {291776400 3600 1 WEST}.. {307501200 0 0 WET}.. {323830800 3600 1 WEST}.. {338950800 0 0 WET}.. {354675600 3600 1 WEST}.. {370400400 0 0 WET}.. {386125200 3600 1 WEST}.. {401850000 0 0 WET}.. {417574800 3600 1 WEST}.. {433299600 0 0 WET}.. {449024400 3600 1 WEST}.. {465354000 0 0 WET}.. {481078800 3600 1 WEST}.. {496803600 0 0 WET}.. {512528400 3600 1 WEST}.. {528253200 0 0 WET}.. {543978000 3600 1 WEST}.. {559702800 0 0 WET}.. {575427600 3600 1 WEST}.. {591152400 0 0 WET}.. {606877200 3600 1 WEST}.. {622602000 0 0 WET}.. {638326800 3600 1 WEST}.. {654656400 0 0 WET}.. {670381200 3600 1 WEST}.. {686106000 0 0 WET}.. {701830800 3600 1 WEST}.. {717555600 0 0 WET}.. {733280400 3600 1 WEST}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):154
                                                                                                                                                                                                            Entropy (8bit):4.8800842076244715
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:SlEVFRKvJT8QFtFb+MuUyqAxmS3vXHAIgELyHRL/taFBURFB:SlSWB9vsM3yzTHAIgm6N/YFaRX
                                                                                                                                                                                                            MD5:DDB6F69CA4F0EF6A708481F53F95EAB9
                                                                                                                                                                                                            SHA1:A63E900A9257E9D73B4BB4BACBA8133C3D1DC41B
                                                                                                                                                                                                            SHA-256:A06E8CCCF97CC8FB545DFDB4C89B5E5C8EDF0360547BDC1823B4AC47B1556C31
                                                                                                                                                                                                            SHA-512:C8EA1039BE001F5EF52662B28DBF46D02E4848F08F05923850DEA1994732037B4C8D6030B742D97FA4276AF5FEE3F17C47C7DDA4F44DD23244F9976A076D5CC4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# created by tools/tclZIC.tcl - do not edit..if {![info exists TZData(Etc/UTC)]} {.. LoadTimeZoneFile Etc/UTC..}..set TZData(:Zulu) $TZData(:Etc/UTC)..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):5030
                                                                                                                                                                                                            Entropy (8bit):4.838527643033185
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:HgTQWiZuhdFQJmuldFQofsGP3R1hF9Dl19arB0E9Dl1YoaEhHe2Gu/q1ZFyJRpqk:8iZUroxvR197ABr971h5GIqrmbqIc+b/
                                                                                                                                                                                                            MD5:70450A0CF04EF273EFF2B070053FCFA6
                                                                                                                                                                                                            SHA1:47974D6C0FC986EE1273C4E13DDB9E1288CEF0FF
                                                                                                                                                                                                            SHA-256:678F891615E2209A8ECBA17857922A9723E78709ADB983032E89CA706000C44D
                                                                                                                                                                                                            SHA-512:AFD3E47324D1497CC46AC6141191FCEB843977D0B0285C807FF8985DCC56FDE10977F57D503D986CD2C1EDC6C62F01E405A0EB483340B247B129FC8D6D9FE689
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# word.tcl --..#..# This file defines various procedures for computing word boundaries in..# strings. This file is primarily needed so Tk text and entry widgets behave..# properly for different platforms...#..# Copyright (c) 1996 Sun Microsystems, Inc...# Copyright (c) 1998 Scritpics Corporation...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....# The following variables are used to determine which characters are..# interpreted as white space.....if {$::tcl_platform(platform) eq "windows"} {.. # Windows style - any but a unicode space char.. if {![info exists ::tcl_wordchars]} {...set ::tcl_wordchars {\S}.. }.. if {![info exists ::tcl_nonwordchars]} {...set ::tcl_nonwordchars {\s}.. }..} else {.. # Motif style - any unicode word char (number, letter, or underscore).. if {![info exists ::tcl_wordchars]} {...set ::tcl_wordchars {\w}.. }.. if {![info exists ::tcl_nonwordchar
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8806
                                                                                                                                                                                                            Entropy (8bit):4.863085192885279
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:RpwYLapGk1BlM4UBIHpJFVUXUziMJ5Kxyk55qxUr7Vdk5vNR:RuYfvMdOXyj+01f
                                                                                                                                                                                                            MD5:C5E9A2E32AE83A79DF422D1145B692DF
                                                                                                                                                                                                            SHA1:08350F930FB97A95970122920C91FB9CED8329E9
                                                                                                                                                                                                            SHA-256:8822365EE279BEBF7A36CFDEDBA1114762F894781F4635170CC5D85FF5B17923
                                                                                                                                                                                                            SHA-512:71420E15A3D63329560074F6FFAD42CB464401284BC29D0DC8E34D83F8F77079F26BB4C5703E656A48E6931C3DBF6B873756FB212D0860483E0301B29EDE1212
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# bgerror.tcl --..#..#.Implementation of the bgerror procedure. It posts a dialog box with..#.the error message and gives the user a chance to see a more detailed..#.stack trace, and possible do something more interesting with that..#.trace (like save it to a log). This is adapted from work done by..#.Donal K. Fellows...#..# Copyright (c) 1998-2000 by Ajuba Solutions...# Copyright (c) 2007 by ActiveState Software Inc...# Copyright (c) 2007 Daniel A. Steffen <das@users.sourceforge.net>..# Copyright (c) 2009 Pat Thoyts <patthoyts@users.sourceforge.net>....namespace eval ::tk::dialog::error {.. namespace import -force ::tk::msgcat::*.. namespace export bgerror.. option add *ErrorDialog.function.text [mc "Save To Log"] \...widgetDefault.. option add *ErrorDialog.function.command [namespace code SaveToLog].. option add *ErrorDialog*Label.font TkCaptionFont widgetDefault.. if {[tk windowingsystem] eq "aqua"} {...option add *ErrorDialog*background systemAlertBackgroundActi
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):21612
                                                                                                                                                                                                            Entropy (8bit):4.947590677310969
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:Tv7cBCAsj9oqlFFSsB3VfRt+lMpWaNwJgzCHarc6gAsj9oqlFFSsB3VlRtYlMpBz:TvweHBBTfIZxHBnZWqbJPBFIaVlCj26+
                                                                                                                                                                                                            MD5:AEB53F7F1506CDFDFE557F54A76060CE
                                                                                                                                                                                                            SHA1:EBB3666EE444B91A0D335DA19C8333F73B71933B
                                                                                                                                                                                                            SHA-256:1F5DD8D81B26F16E772E92FD2A22ACCB785004D0ED3447E54F87005D9C6A07A5
                                                                                                                                                                                                            SHA-512:ACDAD4DF988DF6B2290FC9622E8EACCC31787FECDC98DCCA38519CB762339D4D3FB344AE504B8C7918D6F414F4AD05D15E828DF7F7F68F363BEC54B11C9B7C43
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# button.tcl --..#..# This file defines the default bindings for Tk label, button,..# checkbutton, and radiobutton widgets and provides procedures..# that help in implementing those bindings...#..# Copyright (c) 1992-1994 The Regents of the University of California...# Copyright (c) 1994-1996 Sun Microsystems, Inc...# Copyright (c) 2002 ActiveState Corporation...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# The code below creates the default class bindings for buttons...#-------------------------------------------------------------------------....if {[tk windowingsystem] eq "aqua"} {.... bind Radiobutton <Enter> {...tk::ButtonEnter %W.. }.. bind Radiobutton <1> {...tk::ButtonDown %W.. }.. bind Radiobutton <ButtonRelease-1> {...tk::ButtonUp %W.. }.. bind Checkbutton <Enter> {...tk::ButtonEnter %W
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Nim source code, ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):9960
                                                                                                                                                                                                            Entropy (8bit):4.802555950168837
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:HKOdkMpU9YUp8UIhMYYicln9Die0luVZat3pIp5Y3sF1P8Bg8p6trIOzvKsOiCLU:HyMm9J8wPx70luex4C8Fygq6tohef+0J
                                                                                                                                                                                                            MD5:818E4F0112931F12B4FAC4CAD262814C
                                                                                                                                                                                                            SHA1:AC7060DF952F9DB52C3687B8F5E6AA4ADF06992E
                                                                                                                                                                                                            SHA-256:35B208E8570B0D1E0CA1C911D4FE02EE3B0CFE5667CF1BDEC006CF9D043122BA
                                                                                                                                                                                                            SHA-512:0C535B6621BC83412B7A64CB6AC2BA526B8E49BB5F6BC5EBEDA41D223D68DEB031DB9C8A31F8671BC5F327D720942E7FDAE3328334B0B550AC991191F96909D6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# choosedir.tcl --..#..#.Choose directory dialog implementation for Unix/Mac...#..# Copyright (c) 1998-2000 by Scriptics Corporation...# All rights reserved.....# Make sure the tk::dialog namespace, in which all dialogs should live, exists..namespace eval ::tk::dialog {}..namespace eval ::tk::dialog::file {}....# Make the chooseDir namespace inside the dialog namespace..namespace eval ::tk::dialog::file::chooseDir {.. namespace import -force ::tk::msgcat::*..}....# ::tk::dialog::file::chooseDir:: --..#..#.Implements the TK directory selection dialog...#..# Arguments:..#.args..Options parsed by the procedure...#..proc ::tk::dialog::file::chooseDir:: {args} {.. variable ::tk::Priv.. set dataName __tk_choosedir.. upvar ::tk::dialog::file::$dataName data.. Config $dataName $args.... if {$data(-parent) eq "."} {.. set w .$dataName.. } else {.. set w $data(-parent).$dataName.. }.... # (re)create the dialog box if necessary.. #.. if {![winfo exis
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):22103
                                                                                                                                                                                                            Entropy (8bit):5.03166227244502
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:lJGidpe3JQDUd6hgp6EQstzQf+a9DPbS43/H//cO802UeeVnZmM6BA0kyVJv9Qpu:Gep6JCwQDPbLPaRCzTdMAe
                                                                                                                                                                                                            MD5:AD86E0265C307348A16E9E4B64D8F235
                                                                                                                                                                                                            SHA1:66EC6726DF997EE6096F642EBBBDB8C3201BA571
                                                                                                                                                                                                            SHA-256:D210DCFA9ADB4C23E44EBF744839158CAB4E21EACF9483C6BA91BA6EC4660EB8
                                                                                                                                                                                                            SHA-512:A0C9DF815FE54C26EED69C84B29FD829EB1B7E43D2787E98C71D091607226532F6F0E9213E83FF8263FCB6DA892178029D5EF475FD46D22F9BB8AB31B87BF438
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# clrpick.tcl --..#..#.Color selection dialog for platforms that do not support a..#.standard color selection dialog...#..# Copyright (c) 1996 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#..# ToDo:..#..#.(1): Find out how many free colors are left in the colormap and..#. don't allocate too many colors...#.(2): Implement HSV color selection...#....# Make sure namespaces exist..namespace eval ::tk {}..namespace eval ::tk::dialog {}..namespace eval ::tk::dialog::color {.. namespace import ::tk::msgcat::*..}....# ::tk::dialog::color:: --..#..#.Create a color dialog and let the user choose a color. This function..#.should not be called directly. It is called by the tk_chooseColor..#.function when a native color selector widget does not exist..#..proc ::tk::dialog::color:: {args} {.. variable ::tk::Priv.. set dataName __tk__color.. upvar ::tk::dialog::color::$da
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8690
                                                                                                                                                                                                            Entropy (8bit):5.098389551322902
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:u4R7+/gFw/MEN55fO7eyjt4bjC+gR8e3vwLln/+LVtUw0tXK4jA:u4l+/gFeMI55Xyjt4bjC+gOe3Ih/+LV1
                                                                                                                                                                                                            MD5:ABF277E4F62423F4345B6AD65640B8C2
                                                                                                                                                                                                            SHA1:E66A4E37D51C7827C9ACA449A42E0966AACBC8C8
                                                                                                                                                                                                            SHA-256:C7DA292CCF5F413E599C3491C331FFD58CF273F8477FACB097E6F36CF1F32A08
                                                                                                                                                                                                            SHA-512:AA9F75D7C5C915B5FCD2F454856D080D186AB9BA149DC139FEAF7F4AC3DC51E6769E138E3B1BE45B3FEC3AE744189DE44DB2B748F0628FF13E4E733B9CD68BD5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# comdlg.tcl --..#..#.Some functions needed for the common dialog boxes. Probably need to go..#.in a different file...#..# Copyright (c) 1996 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# tclParseConfigSpec --..#..#.Parses a list of "-option value" pairs. If all options and..#.values are legal, the values are stored in..#.$data($option). Otherwise an error message is returned. When..#.an error happens, the data() array may have been partially..#.modified, but all the modified members of the data(0 array are..#.guaranteed to have valid values. This is different than..#.Tk_ConfigureWidget() which does not modify the value of a..#.widget record if any error occurs...#..# Arguments:..#..# w = widget record to modify. Must be the pathname of a widget...#..# specs = {..# {-commandlineswitch resourceName ResourceClass defaultValue verifier}..# {....}..# }..#..# flags
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):33347
                                                                                                                                                                                                            Entropy (8bit):4.995865221021151
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:jMpwGU6OGEJemVueuR3fitsHI76Su6qKQjGCy1HyOnmTTRV+po2mBh6S5mDjbHqC:jMpdUDGEJpC6+oVeKQPjnD2jVfV/
                                                                                                                                                                                                            MD5:4CA2E90A125FFD6191D0C5AC6818D18F
                                                                                                                                                                                                            SHA1:855F10234FA1D65521C2508206EA58DC565E452B
                                                                                                                                                                                                            SHA-256:A4B21DBF699C20EA5AC334EC109F731BE8EB2B8F9A34CCC2EBE538F4BF8A05F8
                                                                                                                                                                                                            SHA-512:ED5AE05A7F1D379F8343FF4AD7EF561C5C4D9B7E02399A7281DF8B8930B924B0482FDC5B4E3F90C2214ADA4F87D9A5E64DB2259194C58A2135D969C01BBE64F9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# console.tcl --..#..# This code constructs the console window for an application. It..# can be used by non-unix systems that do not have built-in support..# for shells...#..# Copyright (c) 1995-1997 Sun Microsystems, Inc...# Copyright (c) 1998-2000 Ajuba Solutions...# Copyright (c) 2007-2008 Daniel A. Steffen <das@users.sourceforge.net>..#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# TODO: history - remember partially written command....namespace eval ::tk::console {.. variable blinkTime 500 ; # msecs to blink braced range for.. variable blinkRange 1 ; # enable blinking of the entire braced range.. variable magicKeys 1 ; # enable brace matching and proc/var recognition.. variable maxLines 600 ; # maximum # of lines buffered in console.. variable showMatches 1 ; # show multiple expand matches.. variable useFontchooser [llength [info command ::tk::fontchooser]
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):5988
                                                                                                                                                                                                            Entropy (8bit):4.829498876074983
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:qFR55woFFEciKwKClFEOTIhDHWyzaoj9zza7v0J7:qL55jiKwKCzTIhDbzaojhSG7
                                                                                                                                                                                                            MD5:B2B3AA971D42FDBF92F13B45111EE1D3
                                                                                                                                                                                                            SHA1:A74F2C2707463D6E209D0E0C96D75083AC6920A5
                                                                                                                                                                                                            SHA-256:1C977052C1D8293CC5FE4198A538BECA9BC821AF85E76E4EEFBFB75B33CE8BED
                                                                                                                                                                                                            SHA-512:146F658DA3E6E9176FA51C9836D7C1DCFC14E148A26B224155F6493C195A7FB20C2DC4EE21994E5A193B8DA8561C75374E830304F94F0C844E52AD829F6810D5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# dialog.tcl --..#..# This file defines the procedure tk_dialog, which creates a dialog..# box containing a bitmap, a message, and one or more buttons...#..# Copyright (c) 1992-1993 The Regents of the University of California...# Copyright (c) 1994-1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#..# ::tk_dialog:..#..# This procedure displays a dialog box, waits for a button in the dialog..# to be invoked, then returns the index of the selected button. If the..# dialog somehow gets destroyed, -1 is returned...#..# Arguments:..# w -..Window to use for dialog top-level...# title -.Title to display in dialog's decorative frame...# text -.Message to display in dialog...# bitmap -.Bitmap to display in dialog (empty string means none)...# default -.Index of button that is to display the default ring..#..(-1 means none)...# args -.One or more strings to display in buttons
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):18440
                                                                                                                                                                                                            Entropy (8bit):4.982597499983157
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:mDfyPIlBk3yrt8qLjtpa+qh+rA4rsWRWrrMUtCPnkKYNlPp64ZnCD:mDfyPIlBk3yJ8mtpaplcp6o
                                                                                                                                                                                                            MD5:007F42FBCDC57652AC8381F11AF7FB67
                                                                                                                                                                                                            SHA1:1BB1B0FCAD6F5633D1BEB8903112F180B1C4BA7F
                                                                                                                                                                                                            SHA-256:65BA33A1E0B21E8E074780A51189CEE6FD9926C85273E9E7633987FC212A17B2
                                                                                                                                                                                                            SHA-512:A27089719ADAFC48B5ABB905E40D0C6A0A2507526223D72C1CFF36AB7C15362C6F0B8EE5775181BA1730852802AFA64631EE3720E624B630E3274BFB32F6A59A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# entry.tcl --..#..# This file defines the default bindings for Tk entry widgets and provides..# procedures that help in implementing those bindings...#..# Copyright (c) 1992-1994 The Regents of the University of California...# Copyright (c) 1994-1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# Elements of tk::Priv that are used in this file:..#..# afterId -..If non-null, it means that auto-scanning is underway..#...and it gives the "after" id for the next auto-scan..#...command to be executed...# mouseMoved -..Non-zero means the mouse has moved a significant..#...amount since the button went down (so, for example,..#...start dragging out a selection)...# pressX -..X-coordinate at which the mouse button was pressed...# selectMode -..The style of selection currently underway:..#...char, word
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):5035
                                                                                                                                                                                                            Entropy (8bit):4.819523401259934
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:J3MRZZ7HWb/6OgRKjtS6Mn9GRZZ7HWb2Y6aO6R5nh76SMoB2kd82KtTpsi2D0DSn:CRZdPul1RZdFaRf0XoB2gZKZpsi2pn
                                                                                                                                                                                                            MD5:63B219BE9AFF1DE7DE2BAF0E941CAE38
                                                                                                                                                                                                            SHA1:A2FEBB31380E12FF01E6F641FE8B4F815941462F
                                                                                                                                                                                                            SHA-256:8872F236D7E824AEC0ACD4BACC00FDD7EC9BC5534814ECF2160610C10647B7C5
                                                                                                                                                                                                            SHA-512:057700F8FDE4B7C3D7AB7CEFD6C531060BF2B1B3B727CAD6A37ECD42EBC557765D94B83ADD438BD5AFA1F6F919D80AE755A8D98918981167B871F31AD42FDF5E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# focus.tcl --..#..# This file defines several procedures for managing the input..# focus...#..# Copyright (c) 1994-1995 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# ::tk_focusNext --..# This procedure returns the name of the next window after "w" in..# "focus order" (the window that should receive the focus next if..# Tab is typed in w). "Next" is defined by a pre-order search..# of a top-level and its non-top-level descendants, with the stacking..# order determining the order of siblings. The "-takefocus" options..# on windows determine whether or not they should be skipped...#..# Arguments:..# w -..Name of a window.....proc ::tk_focusNext w {.. set cur $w.. while {1} {.....# Descend to just before the first child of the current widget......set parent $cur...set children [winfo children $cur]...set i -1.....# Look for the next sibling that isn't a top-leve
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):18232
                                                                                                                                                                                                            Entropy (8bit):4.723225284452692
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:NoRqdguMCeor/4VxgU80zNxWHKVozN5EaKdhsbyM:NoRqdguMCeor/4VxgUnzN0KSDEk
                                                                                                                                                                                                            MD5:CFA99C2D3F02AE6538809774699A9CE7
                                                                                                                                                                                                            SHA1:DADB7B3D1D9531710BA7D3025CE18F6F8149F280
                                                                                                                                                                                                            SHA-256:4EE521F4980A5056077005B748717D91CB6B17342CDD20135962AB92A665B580
                                                                                                                                                                                                            SHA-512:DCF54AAEA439C986AE28CEC0241F204BB5001DE4E98C2E7A9C282F9E47747AD62E9B2CF6FBBAC068BF1F1BB0AAC866F85476E9EE79935CE1E3656F122C2D002D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# fontchooser.tcl -..#..#.A themeable Tk font selection dialog. See TIP #324...#..# Copyright (C) 2008 Keith Vetter..# Copyright (C) 2008 Pat Thoyts <patthoyts@users.sourceforge.net>..#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....namespace eval ::tk::fontchooser {.. variable S.... set S(W) .__tk__fontchooser.. set S(fonts) [lsort -dictionary -unique [font families]].. set S(styles) [list \.. [::msgcat::mc Regular] \.. [::msgcat::mc Italic] \.. [::msgcat::mc Bold] \.. [::msgcat::mc {Bold Italic}] \.. ].. set S(sizes) {8 9 10 11 12 14 16 18 20 22 24 26 28 36 48 72}.. set S(strike) 0.. set S(under) 0.. set S(first) 1.. set S(-parent) ... set S(-title) {}.. set S(-command) "".. set S(-font) TkDefaultFont.. set S(bad) [list ]..}....proc ::tk::fontchooser::Canonical {} {.. variable S.... foreach style $S(styles
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Tcl script, ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):17565
                                                                                                                                                                                                            Entropy (8bit):4.959816621842895
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:FNP8nO9Wo8k5NfQH8EsOy8WMdbffNCvHshPOw7jW:FNf8uNfQH89Z8WMdz1vDW
                                                                                                                                                                                                            MD5:FDB839B85C4CEB34DEC04E0EBD6A3C96
                                                                                                                                                                                                            SHA1:0FD8981093CC6ED9927D1DDE708FECE84B9C5E6F
                                                                                                                                                                                                            SHA-256:07812124D27E47621AF74FDB90C777D3219B02F657FC2F97F606C69EF9468A01
                                                                                                                                                                                                            SHA-512:E65616B3F6BDC3910FC90E9710426370AA4B0A0D9EB6289871B9C30A98A2F2B5CC1E471B63203210AAE89120F20F164A33E01DA45BCCCCCEC7BFC1CCFD70FAC7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# iconlist.tcl..#..#.Implements the icon-list megawidget used in the "Tk" standard file..#.selection dialog boxes...#..# Copyright (c) 1994-1998 Sun Microsystems, Inc...# Copyright (c) 2009 Donal K. Fellows..#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES...#..# API Summary:..#.tk::IconList <path> ?<option> <value>? .....#.<path> add <imageName> <itemList>..#.<path> cget <option>..#.<path> configure ?<option>? ?<value>? .....#.<path> deleteall..#.<path> destroy..#.<path> get <itemIndex>..#.<path> index <index>..#.<path> invoke..#.<path> see <index>..#.<path> selection anchor ?<int>?..#.<path> selection clear <first> ?<last>?..#.<path> selection get..#.<path> selection includes <item>..#.<path> selection set <first> ?<last>?.....package require Tk....::tk::Megawidget create ::tk::IconList ::tk::FocusableWidget {.. variable w canvas sbar accel accelCB fill font index \...itemList itemsPerColumn list
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):11037
                                                                                                                                                                                                            Entropy (8bit):6.048349526382653
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:0nEPytJLl1S47T3YqN5/vkJpnhXqBB4aw2rqZiygTtYTpOq/pc75Mk:xqLz7F5KTqBBLuZ1gTSsqhk
                                                                                                                                                                                                            MD5:995A0A8F7D0861C268AEAD5FC95A42EA
                                                                                                                                                                                                            SHA1:21E121CF85E1C4984454237A646E58EC3C725A72
                                                                                                                                                                                                            SHA-256:1264940E62B9A37967925418E9D0DC0BEFD369E8C181B9BAB3D1607E3CC14B85
                                                                                                                                                                                                            SHA-512:DB7F5E0BC7D5C5F750E396E645F50A3E0CDE61C9E687ADD0A40D0C1AA304DDFBCEEB9F33AD201560C6E2B051F2EDED07B41C43D00F14EE435CDEEE73B56B93C7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# icons.tcl --..#..#.A set of stock icons for use in Tk dialogs. The icons used here..#.were provided by the Tango Desktop project which provides a..#.unified set of high quality icons licensed under the..#.Creative Commons Attribution Share-Alike license..#.(https://creativecommons.org/licenses/by-sa/3.0/)..#..#.See http://tango.freedesktop.org/Tango_Desktop_Project..#..# Copyright (c) 2009 Pat Thoyts <patthoyts@users.sourceforge.net>....namespace eval ::tk::icons {}....image create photo ::tk::icons::warning -data {.. iVBORw0KGgoAAAANSUhEUgAAACAAAAAgCAYAAABzenr0AAAABHNCSVQICAgIfAhkiAAABSZJREFU.. WIXll1toVEcYgL+Zc87u2Yu7MYmrWRuTJuvdiMuqiJd4yYKXgMQKVkSjFR80kFIVJfWCWlvpg4h9.. 8sXGWGof8iKNICYSo6JgkCBEJRG8ImYThNrNxmaTeM7pQ5IlJkabi0/9YZhhZv7///4z/8zPgf+7.. KCNRLgdlJijXwRyuDTlcxV9hbzv8nQmxMjg+XDtiOEplkG9PSfkztGmTgmFQd+FCVzwa3fYN/PHZ.. AcpBaReicW5xcbb64IEQqko8Lc26d/58cxS+/BY6hmJvyEfQBoUpwWCmW1FErKaGWHU13uRk4QkE.. UtxQNFR7QwIoB4eiKD9PWbVKbb10CZmaCqmpxCormRYO26QQx85B0mcD+AeK0
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):329
                                                                                                                                                                                                            Entropy (8bit):4.3973643486226655
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:nVxpJFBmHdeA1xNZgk0dIf3Ju4dFi6/XWrWhr3W7FxmVFraazmVAJFKyVQR7icr8:nj5Bqf1fZgp6A4FDG6dm7FUGAJVVMRmn
                                                                                                                                                                                                            MD5:921245A21F7E783997DC7B859AF1B65B
                                                                                                                                                                                                            SHA1:2EFE3C8F70CF18621006890BF21CC097770D140D
                                                                                                                                                                                                            SHA-256:C6DB098EBD8A622164D37D4AB0A8C205DB1A83AC3065D5CDE3CB5FB61925D283
                                                                                                                                                                                                            SHA-512:CAD823FF3D13A64C00825961E75B5133690556FB1F622834F8B1DF316A9E75BABB63B9F5148DAE7B1391123B4C8D55B4B8B2EB6F8E6E1DA9DE02A5BD7AC0FD6F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:README - images directory....This directory includes images for the Tcl Logo and the Tcl Powered..Logo. Please feel free to use the Tcl Powered Logo on any of your..products that employ the use of Tcl or Tk. The Tcl logo may also be..used to promote Tcl in your product documentation, web site or other..places you so desire...
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PostScript document text conforming DSC level 3.0, type EPS
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):34991
                                                                                                                                                                                                            Entropy (8bit):5.248845410801251
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:0YrY6a0v4uIqYMEKjodQKOfRXMLcSqDGpfTKFVm3AsanMEDzzBHWzaw7XUbTJjoB:0YrY6aeIqYMEKjouzfRXMLcSqDGpfTKo
                                                                                                                                                                                                            MD5:23C4EDED40DEC065F99E6653AEE1BB31
                                                                                                                                                                                                            SHA1:3175E261BE198731DEDB07264CCB84C8DEDF7967
                                                                                                                                                                                                            SHA-256:76207D8DFDE189A29DC0E76ADB7EAAA606B96BC6C1C831F34D1C85B1C5B51DD3
                                                                                                                                                                                                            SHA-512:BA139A64BE72BB681040924C4294E2726BA5AB243E805E60A854D2D23E154705E2431D1AB2DE732BFA393747FD30D8A5C913895CBE1463DBF50CC23CAE5B0454
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:%!PS-Adobe-3.0 EPSF-3.0..%%Creator: Adobe Illustrator(TM) 5.5..%%For: (Bud Northern) (Mark Anderson Design)..%%Title: (TCL/TK LOGO.ILLUS)..%%CreationDate: (8/1/96) (4:58 PM)..%%BoundingBox: 251 331 371 512..%%HiResBoundingBox: 251.3386 331.5616 370.5213 511.775..%%DocumentProcessColors: Cyan Magenta Yellow..%%DocumentSuppliedResources: procset Adobe_level2_AI5 1.0 0..%%+ procset Adobe_IllustratorA_AI5 1.0 0..%AI5_FileFormat 1.2..%AI3_ColorUsage: Color..%%DocumentCustomColors: (TCL RED)..%%CMYKCustomColor: 0 0.45 1 0 (Orange)..%%+ 0 0.25 1 0 (Orange Yellow)..%%+ 0 0.79 0.91 0 (TCL RED)..%AI3_TemplateBox: 306 396 306 396..%AI3_TileBox: 12 12 600 780..%AI3_DocumentPreview: Macintosh_ColorPic..%AI5_ArtSize: 612 792..%AI5_RulerUnits: 0..%AI5_ArtFlags: 1 0 0 1 0 0 1 1 0..%AI5_TargetResolution: 800..%AI5_NumLayers: 1..%AI5_OpenToView: 90 576 2 938 673 18 1 1 2 40..%AI5_OpenViewLayers: 7..%%EndComments..%%BeginProlog..%%BeginResource: procset Adobe_level2_AI5 1.0 0..%%Title: (Adobe Illustrator
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:GIF image data, version 89a, 68 x 100
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2341
                                                                                                                                                                                                            Entropy (8bit):6.9734417899888665
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:qF/mIXn3l7+ejbL/4nZEsKPKer1OPQqVRqJbPpRRKOv/UVO47f:81nHL4T0KorxvRKkc847f
                                                                                                                                                                                                            MD5:FF04B357B7AB0A8B573C10C6DA945D6A
                                                                                                                                                                                                            SHA1:BCB73D8AF2628463A1B955581999C77F09F805B8
                                                                                                                                                                                                            SHA-256:72F6B34D3C8F424FF0A290A793FCFBF34FD5630A916CD02E0A5DDA0144B5957F
                                                                                                                                                                                                            SHA-512:10DFE631C5FC24CF239D817EEFA14329946E26ED6BCFC1B517E2F9AF81807977428BA2539AAA653A89A372257D494E8136FD6ABBC4F727E6B199400DE05ACCD5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:GIF89aD.d...............f..3.............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3.............f..3..........f.3...f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3.............f..3............f..3.............f..3....f..f.f..ff.f3.f..3..3.3..3f.33.3...........f..3...f..f..f..f.ff.3f..f..f..f.f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3.3.f3.33..3..3..3..3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.............f..3.............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...............w..U..D..".....................w..U..D..".....................w..U..D..".................wwwUUUDDD"""......,....D.d........H......*\...z..Ht@Q...92.p...z.$.@@.E..u.Y.2..0c..q.cB.,[..... ..1..qbM.2~*].....s...S.@.L.j..#..\......h..........].D(..m......@.Z....oO...3=.c...G".(..pL...q]..%....[...#...+...X.h....^.....
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:GIF image data, version 89a, 43 x 64
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1670
                                                                                                                                                                                                            Entropy (8bit):6.326462043862671
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:PF/mIXn3l7+ejbL/4xsgq4sNC6JYp6s/pmp76F:/1nHL404raM/op2
                                                                                                                                                                                                            MD5:B226CC3DA70AAB2EBB8DFFD0C953933D
                                                                                                                                                                                                            SHA1:EA52219A37A140FD98AEA66EA54685DD8158D9B1
                                                                                                                                                                                                            SHA-256:138C240382304F350383B02ED56C69103A9431C0544EB1EC5DCD7DEC7A555DD9
                                                                                                                                                                                                            SHA-512:3D043F41B887D54CCADBF9E40E48D7FFF99B02B6FAF6B1DD0C6C6FEF0F8A17630252D371DE3C60D3EFBA80A974A0670AF3747E634C59BDFBC78544D878D498D4
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:GIF89a+.@...............f..3.............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3.............f..3..........f.3...f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3.............f..3............f..3.............f..3....f..f.f..ff.f3.f..3..3.3..3f.33.3...........f..3...f..f..f..f.ff.3f..f..f..f.f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3.3.f3.33..3..3..3..3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.............f..3.............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...............w..U..D..".....................w..U..D..".....................w..U..D..".................wwwUUUDDD"""......,....+.@........H. .z..(tp......@...92....#. A.......C.\.%...)Z..1a.8s..W/..@....3..C...y$.GW.....5.FU..j..;.F(Pc+W.-..X.D-[.*g....F..`.:mkT...Lw...A/.....u.7p..a..9P.....q2..Xg..G....3}AKv.\.d..yL.>..1.#
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:GIF image data, version 89a, 354 x 520
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):11000
                                                                                                                                                                                                            Entropy (8bit):7.88559092427108
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:d+nY6zludc/We/yXy9JHBUoIMSapQdrGlapzmyNMK1vbXkgMmgFW/KxIq3NhZe:YnY6p4c/OCHyowaGUaCcMK1vbXNwFW/l
                                                                                                                                                                                                            MD5:45D9B00C4CF82CC53723B00D876B5E7E
                                                                                                                                                                                                            SHA1:DDD10E798AF209EFCE022E97448E5EE11CEB5621
                                                                                                                                                                                                            SHA-256:0F404764D07A6AE2EF9E1E0E8EAAC278B7D488D61CF1C084146F2F33B485F2ED
                                                                                                                                                                                                            SHA-512:6E89DACF2077E1307DA05C16EF8FDE26E92566086346085BE10A7FD88658B9CDC87A3EC4D17504AF57D5967861B1652FA476B2DDD4D9C6BCFED9C60BB2B03B6F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:GIF89ab.................f..3.............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3..............f..3.............f..3..........f.3...f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3.............f..3............f..3.............f..3....f..f.f..ff.f3.f..3..3.3..3f.33.3...........f..3...f..f..f..f.ff.3f..f..f..f.f.ff.3f..f..f..f..f.ff.3f..ff.ff.ff.fffff3ff.f3.f3.f3.f3ff33f3.f..f..f..f.ff.3f..3..3..3..3.f3.33..3..3..3.3.f3.33..3..3..3..3.f3.33..3f.3f.3f.3ff3f33f.33.33.33.33f33333.3..3..3..3.f3.33.............f..3.............f..3..............f..3....f..f..f..ff.f3.f..3..3..3..3f.33.3............f..3...............w..U..D..".....................w..U..D..".....................w..U..D..".................wwwUUUDDD"""......,....b..........H......*\....#J.H....3j.... '.;p....(.8X..^.0c.I...z8O.\.....:....$..Fu<8`...P.>%I.gO.C.h-..+.`....@..h....dJ.?...K...H.,U.._.#...g..[.*^.x.....J.L.!.'........=+eZ..i..ynF.8...].y|..m.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:GIF image data, version 87a, 120 x 181
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3889
                                                                                                                                                                                                            Entropy (8bit):7.425138719078912
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:9qqbIh+cE4C8ric/jxK5mxsFBu3/0GIJ6Qap1Y5uMiR8pw5rB/SgijDb+TOh:hy+mnZ7xK5IsTwDQmkdiiG5rB/BE+6h
                                                                                                                                                                                                            MD5:BD12B645A9B0036A9C24298CD7A81E5A
                                                                                                                                                                                                            SHA1:13488E4F28676F1E0CE383F80D13510F07198B99
                                                                                                                                                                                                            SHA-256:4D0BD3228AB4CC3E5159F4337BE969EC7B7334E265C99B7633E3DAF3C3FCFB62
                                                                                                                                                                                                            SHA-512:F62C996857CA6AD28C9C938E0F12106E0DF5A20D1B4B0B0D17F6294A112359BA82268961F2A054BD040B5FE4057F712206D02F2E668675BBCF6DA59A4DA0A1BB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:GIF87ax............................................................................z.....{..o.....m..b...`{.X....vy...hk.Um.N...I`.D..Z^.LP.?R.;!....?C.5C.3#.l..,6.*&.15...`..#(.If.y.....l...._..#/...Hm.>_.y..4R.k..#6..._......w..*K.^.."<.....G{.w..3_."C.Q..F....v..!K...v.2m.)_.[..!R.u.1t.g..)f. X.O..E..1z.g. _.Z..D..:..0..Z.. f.D..0..'z..m.N..C../.z.svC.q/.m.ze7.\..P..I..1%.,...............................................................................................................................................................................................................................................................................................................................................................................................,....x..........H.......D..!...7.PAQ...._l8.... C.<.a...*.x....0q.. ..M.%.<.HBe.@.....Q..7..XC..P..<z3..X...P.jA.%'@.J.lV.......R.,..+....t....7h.....(..a...+^.'..7..L.....V...s..$....a.....8`.9..}K......
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PostScript document text conforming DSC level 3.0, type EPS
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):29706
                                                                                                                                                                                                            Entropy (8bit):5.33387357427899
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:0warY6a0v4uIqYMEKjodQKOfRtMLcSqDGpf88KFVmlhEtOI/eE7U0a1:03rY6aeIqYMEKjouzfRtMLcSqDGpfbKc
                                                                                                                                                                                                            MD5:4AE11820D4D592D02CDE458E6F8CE518
                                                                                                                                                                                                            SHA1:A2E8D3D6191B336D43E48A65C3AE6485B07D93C6
                                                                                                                                                                                                            SHA-256:87FD9E46DBB5F2BF1529AFB411182C9FB9C58E23D830C66A233AF0C256BB8EFF
                                                                                                                                                                                                            SHA-512:E0AD4ED570D414BF00931B0F5BBB61FEF981ABDB22ECC42F8E9841905D38874CDFE38F22EDB17ACD0F7539B2932F9C4A865FA73A49BB1458CE05EE10A78BE357
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:%!PS-Adobe-3.0 EPSF-3.0..%%Creator: Adobe Illustrator(TM) 5.5..%%For: (Bud Northern) (Mark Anderson Design)..%%Title: (TCL PWRD LOGO.ILLUS)..%%CreationDate: (8/1/96) (4:59 PM)..%%BoundingBox: 242 302 377 513..%%HiResBoundingBox: 242.0523 302.5199 376.3322 512.5323..%%DocumentProcessColors: Cyan Magenta Yellow..%%DocumentSuppliedResources: procset Adobe_level2_AI5 1.0 0..%%+ procset Adobe_IllustratorA_AI5 1.0 0..%AI5_FileFormat 1.2..%AI3_ColorUsage: Color..%%CMYKCustomColor: 0 0.45 1 0 (Orange)..%%+ 0 0.25 1 0 (Orange Yellow)..%%+ 0 0.79 0.91 0 (PANTONE Warm Red CV)..%%+ 0 0.79 0.91 0 (TCL RED)..%AI3_TemplateBox: 306 396 306 396..%AI3_TileBox: 12 12 600 780..%AI3_DocumentPreview: Macintosh_ColorPic..%AI5_ArtSize: 612 792..%AI5_RulerUnits: 0..%AI5_ArtFlags: 1 0 0 1 0 0 1 1 0..%AI5_TargetResolution: 800..%AI5_NumLayers: 1..%AI5_OpenToView: 102 564 2 938 673 18 1 1 2 40..%AI5_OpenViewLayers: 7..%%EndComments..%%BeginProlog..%%BeginResource: procset Adobe_level2_AI5 1.0 0..%%Title: (Adobe I
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:GIF image data, version 89a, 64 x 100
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1615
                                                                                                                                                                                                            Entropy (8bit):7.461273815456419
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:aE45BzojC3r1WAQ+HT2gAdKhPFZ/ObchgB8:V5Gb1WN+yfcObmgW
                                                                                                                                                                                                            MD5:DBFAE61191B9FADD4041F4637963D84F
                                                                                                                                                                                                            SHA1:BD971E71AE805C2C2E51DD544D006E92363B6C0C
                                                                                                                                                                                                            SHA-256:BCC0E6458249433E8CBA6C58122B7C0EFA9557CBC8FB5F9392EED5D2579FC70B
                                                                                                                                                                                                            SHA-512:ACEAD81CC1102284ED7D9187398304F21B8287019EB98B0C4EC7398DD8B5BA8E7D19CAA891AA9E7C22017B73D734110096C8A7B41A070191223B5543C39E87AF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:GIF89a@.d.............................f.................f...ff.f3.f..33.3.........f..ff.f3.33.3.f..f..ff.ff.ffff3ff333f.3f.33.33f.3...................................................................!.. -dl-.!.......,....@.d....@.pH,..E.... ..(...H$..v..j....K....q..5L......^).3.Y7..r..u.v|g..om...\iHl..p...`G..\~....fn[q...P.g.Z.l....y...\.l......f.Z.g...%%....e...e...)....O.f..e. ....O..qf..%..(.H.u..]..&....#4.......@.).....u!.M..2. ..PJ..#..T..a.....P.Gi... <Hb....x..z.3.X.O..f.........].Bt..lB.Q.r...9pP....&...L. ..,`[.....E6.Q.....?.#L......|g........N....[.._........."4......b....G6.........m.zI].....I.@.......I.9...glew...2.B..c>./..2....x.....<...{...7;.....y.I.....4G.Qj0..7..%.W.V...?!..[...X..=..k.h..[Q<.....0.B....(P.x.,.......8O*Z.8P!.$....u.c..Ea!..eC....CB.. .H..E..#..C..E...z..&.Nu........c.0..#.T.M.U........l.p @..s.|..pf!..&.......8.#.8.....*..J>. .t..h6(........#..0.A...*!..)...x..u.Z....*%..H.....*.......`......|.....1.......&.....T*...f.l...
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:GIF image data, version 89a, 97 x 150
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2489
                                                                                                                                                                                                            Entropy (8bit):7.708754027741608
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:/Ev7JJ+3uvz/Hwbcp7igaIwjBui7qFxIIOdJXcI+Ks:M9oWz/7pZAV7qPIImJXtXs
                                                                                                                                                                                                            MD5:711F4E22670FC5798E4F84250C0D0EAA
                                                                                                                                                                                                            SHA1:1A1582650E218B0BE6FFDEFFD64D27F4B9A9870F
                                                                                                                                                                                                            SHA-256:5FC25C30AEE76477F1C4E922931CC806823DF059525583FF5705705D9E913C1C
                                                                                                                                                                                                            SHA-512:220C36010208A87D0F674DA06D6F5B4D6101D196544ABCB4EE32378C46C781589DB1CE7C7DFE6471A8D8E388EE6A279DB237B18AF1EB9130FF9D0222578F1589
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:GIF89aa...............................f.................f...ff.f3.f..33.3............f..ff.f3.33.3.f..ff.ff.ffff3ff333f.3f.33.33f.3...................................................................!.. -dl-.!.......,....a......@.pH,...r.l:..TB.T..V..z..H.j..h...&.......t"....F...d..gN~Y...g....}..r....g.....o...g.......Y.w..W......N....Z....W....f...tL.~.f....New............W.M.r.........O.q........W-./i.*...`..z..F9.../9..-.......$6..G..S...........zB.,nw.64...e4.......HOt......f.....)..OX..C.eU.(.Qh.....T..<Q.Y.P.L.YxT....2........ji..3.^)zz..O.a..6 ...TZ........^...7.....>|P.....w$...k.ZF.\R.u....F.]Z.--(v+)[Y....=.!.W..+.]..]._.....&..../Ap...j...!..b.:...{.^.=.`...U.....@Hf..\?.(..Lq@.........0..L...a...&.!.....]#..]G \..q...A.H.X[...(.W......,...1a..B...W(.t.8.AdG.)..(P=...Uu.u..A.KM\...'r.R./.W..d2a.0..G...?...B......#H........1Q.0...R....%+...0.I..{.<......QV.tz'.yn.E.p..0i.I.g......L....%....K...A.l.ph.Q.1e...Z....g..2e...smU&d;.J..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:GIF image data, version 89a, 113 x 175
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2981
                                                                                                                                                                                                            Entropy (8bit):7.758793907956808
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:AmEwM8ioQoHJQBTThKVI7G78NLL120GFBBFXJRxlu+BmO/5lNqm7Eq:B57QoHJQt4II8BZ+jxluZO/5lNqm7Eq
                                                                                                                                                                                                            MD5:DA5FB10F4215E9A1F4B162257972F9F3
                                                                                                                                                                                                            SHA1:8DB7FB453B79B8F2B4E67AC30A4BA5B5BDDEBD3B
                                                                                                                                                                                                            SHA-256:62866E95501C436B329A15432355743C6EFD64A37CFB65BCECE465AB63ECF240
                                                                                                                                                                                                            SHA-512:990CF306F04A536E4F92257A07DA2D120877C00573BD0F7B17466D74E797D827F6C127E2BEAADB734A529254595918C3A5F54FDBD859BC325A162C8CD8F6F5BE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:GIF89aq...............................f.................f...ff.f3.f..33.3............f..ff.f3.3f.33.3.f..ff.ff.ffff3ff333f.3f.33.33f.3................................................................!.. -dl-.!.......,....q......@.pH,...r.l:....A}H...v..R......D.VF..,%M....^.....fyzU.P..f...i.....t..Uqe..N..Z..i......~....g......u.....g......\...h.....P...h.....Q..g....Z..h......]......\...M...[..s...c2.+R.$. ......#.....)v..4....MO.b.....9......[.M.........h'..<-..=.....HQD....D?.~......W7. ..V.W0..l....*0p}..KP?c.\@KW.S(..M..B.....-q...S2...*.,..P.{....F..._MAn ....i.Y3............zh.y.j@...a876...ui.i..;K.........p...`.,}w....tv.m...Y..........;.;.e).e&.......-.NC.*4..(........*..F........[,w....f......E....h..a3.T.^.........)...C.N8.h\T...+&.z....g]H..B..#.t6..Z.....j.-..N......TI....A........M?..Q&V'...Mb.f.x...h.$r.U .9..Ci. ].4.Zb..@...X....%..<..b)V!........Y)x......T.....h.p.d..h..(........]@.**J.M.U.Jf...Y.:....F..g:..d..6q.-..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:GIF image data, version 89a, 130 x 200
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3491
                                                                                                                                                                                                            Entropy (8bit):7.790611381196208
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:ROGuxkQ9mcV7RXcECEtqCa+6GK8WseNXhewFIp9ZmL4u:ROGwpVOEbqCrWsUhtIk4u
                                                                                                                                                                                                            MD5:A5E4284D75C457F7A33587E7CE0D1D99
                                                                                                                                                                                                            SHA1:FA98A0FD8910DF2EFB14EDAEC038B4E391FEAB3C
                                                                                                                                                                                                            SHA-256:BAD9116386343F4A4C394BDB87146E49F674F687D52BB847BD9E8198FDA382CC
                                                                                                                                                                                                            SHA-512:4448664925D1C1D9269567905D044BBA48163745646344E08203FCEF5BA1524BA7E03A8903A53DAF7D73FE0D9D820CC9063D4DA2AA1E08EFBF58524B1D69D359
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:GIF89a................................f.................f...ff.f3.f..33.3............f..ff.3f.33.3.f..ff.ff.ffff3ff333f.3f.33.33f.3...................................................................!.. -dl-.!.......,...........@.pH,...r.l:..T..F$XIe..V$.x..V.Z.z..F.pxd~..........{....o....l..{.b...hi[}P.k...y.....y.f.._R.\...............m.....y.....x......^.Q...j.....\S.....^.......l......]...[.......).....{....7...`..<...`..">..i.?/..@............>..Z.z@....0B..r...j.V.I.@..;%R...*...J.p.A.t.*..$A*...>`.....@g5BP.A..p.x.............q..8...... ...(.Q..#..@...F..YSK..M..#o.....D.m..-.....k}...BT..V......'.....`.d..~;..9+..6...<b.eZ..y^0]0..I...=.6.....}.0<.Z...M...Y1*35.e.....b...U0F~.-.HT......l2.s.q`-....y...e....dPZ....~.zT.M.... "r.E/k. ...*..Lj@'........Pcd&.(..mxF_w.."K..x!..--Y`..A.....Be.jH.A..\..j.....du#.....]^...>......].i.FMO..].9n1",Y...F...EW.9.....0TY.T...Cv!i`%...Hz@.]..U.!Y...#Dv&pi.z(.mn.A....@Q.0.%...&.4.v.cw(.`cd'|..M9..."...,*.......
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:GIF image data, version 89a, 48 x 75
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1171
                                                                                                                                                                                                            Entropy (8bit):7.289201491091023
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:DOfHIzP8hqiF+oyPOmp3XHhPBlMVvG0ffWLpfc:DGoPM+o0OmZXHhOv5WRc
                                                                                                                                                                                                            MD5:7013CFC23ED23BFF3BDA4952266FA7F4
                                                                                                                                                                                                            SHA1:E5B1DED49095332236439538ECD9DD0B1FD4934B
                                                                                                                                                                                                            SHA-256:462A8FF8FD051A8100E8C6C086F497E4056ACE5B20B44791F4AAB964B010A448
                                                                                                                                                                                                            SHA-512:A887A5EC33B82E4DE412564E86632D9A984E8498F02D8FE081CC4AC091A68DF6CC1A82F4BF99906CFB6EA9D0EF47ADAC2D1B0778DCB997FB24E62FC7A6D77D41
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:GIF89a0.K.............................f.................f...ff.f3.f..33.3.........f..ff.f3.3f.33.3.f..ff.ff.f3ff333f.3f.33.33f.3......................................................................!.. -dl-.!.......,....0.K....@.pH,...GD.<:..%SR.Z......<.V.$l.....z......:.. .|v[D..f...z.W.G.Vr...NgsU.yl..qU..`.......`fe`.......Fg....(.&...g.Y.. .."..q.V.$.'.Ez.W....y...Y.U...(#Xrf.........Xux.U..........(U.4...X....G.B..t..1S...R..Y. ...l ..".>.h......,%K....A.....<s....#..8.iK.....a.y$h..DQh.PE)....6.....MyL.qzF..... ."..Y0..a......2..*t..Ma..b...M..R.....\..st..=....Q......,>s`....Qt.,..B.R.....!.$..%.....(...s...B.T...`,".h(. D....8..dC..\Q.p.......x.#A.....:..du..(D.XV......7....S.#n8a....2`...f.:G,...==(......`!..$...t....b..../N|...f..J.x... P&.|.d._!N...].1w.3D.0!....@o&H...N.B.J....pz8..w.i....=r.............@5.-!.......H."..[.j.AB<..p....h...V.D..6.h...ab1F.g...I !.V~.H..V.........:.G..|c...,.....TD5..c[.W.....LC.....FJ..71[..lH.M.....8.:$......
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:GIF image data, version 89a, 100 x 100
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):5473
                                                                                                                                                                                                            Entropy (8bit):7.754239979431754
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:+EqG96vSGfyJZ26G6U1LI7nTD2enhjc+2VBnOqcUERVIim:+46KcyJI6G6uU7/LhjlkhQR7m
                                                                                                                                                                                                            MD5:048AFE69735F6974D2CA7384B879820C
                                                                                                                                                                                                            SHA1:267A9520C4390221DCE50177E789A4EBD590F484
                                                                                                                                                                                                            SHA-256:E538F8F4934CA6E1CE29416D292171F28E67DA6C72ED9D236BA42F37445EA41E
                                                                                                                                                                                                            SHA-512:201DA67A52DADA3AE7C533DE49D3C08A9465F7AA12317A0AE90A8C9C04AA69A85EC00AF2D0069023CD255DDA8768977C03C73516E4848376250E8D0D53D232CB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:GIF89ad.d...................RJJ...B99.......RBB..B11ZBB!....R991!!...)....{{B!!R)).JJ.ss.ZZ.BB.kk.RR.JJ.BB9...JJR!!.ZZ.BB.11.99.{s.sk.kc.cZ.ZR.JB.ZR.JB.JB.RJ.B9.91.B9...{.JB.91.B9.B9.1){)!.)!.9)..ZR.JB{91.cR{1).ZJ.ZJ.RB.J9.B1.B1.9).1!....{B9.{k.scc1).kZZ)!c)!.9).B1.9).9).1!.1!.1!.B).9!.9!.1..).....{.sZ1)R)!.B1.B1.ZBR!..9).ZB.9).R9.R9.1!.J1.J1.B).B).9!.9!.1..1..).....sZ.J9.ZB.cJJ!.{1!.B).9!{)..9!.J).B!.B!.9..R1).kJ)!.B1{9).R9.cB.Z9.Z9.B).Z9.B).R1.9!.R1.J).J).B!.1..9....{.s.J9.{Z.ZB.sR.kJk1!.cB.cB.R1.R).1..B!.J!.B.....R91.J1).c.kJ.J).Z1.B!.B!..9!..{R.sJ.Z9.R1{9!..s.R9.Z...J91Z9){B)...............B91..1)!..............................RJR............B)1......R19........BJ.9B..{..s{......!.......,....d.d.@............0@PHa....*.p...7.8.y...C.s6Z.%Q.#s.`:B.N....4jd.K.0..|y....F@.......1~ ......'Y.B"C&R.V.R.4$k.3...D.......Ef*Y3..M........BDV._.....\..).]..>s..$H\%y0WL...d.......D..'..v..1Kz.Zp$;S
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2307
                                                                                                                                                                                                            Entropy (8bit):5.135743409565932
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:XU/zAcKT6yOCaDBfsHLk32s3J5w83KDyP1BXy3JQz7yuC:XNc+92sg3A8uyDXy3JQnDC
                                                                                                                                                                                                            MD5:F090D9B312C16489289FD39813412164
                                                                                                                                                                                                            SHA1:1BEC6668F6549771DADC67D153B89B8F77DCD4B9
                                                                                                                                                                                                            SHA-256:0D1E4405F6273F091732764ED89B57066BE63CE64869BE6C71EA337DC4F2F9B5
                                                                                                                                                                                                            SHA-512:57B323589C5A8D9CBB224416731D8CE65C4B94146DF15CE30885DF63B1D0B3F709093B65390A911F84F20B7C5DE3C0AF9B4D7D531742BE046EDA6E8C3432EF6E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:This software is copyrighted by the Regents of the University of..California, Sun Microsystems, Inc., Scriptics Corporation, ActiveState..Corporation, Apple Inc. and other parties. The following terms apply to..all files associated with the software unless explicitly disclaimed in..individual files.....The authors hereby grant permission to use, copy, modify, distribute,..and license this software and its documentation for any purpose, provided..that existing copyright notices are retained in all copies and that this..notice is included verbatim in any distributions. No written agreement,..license, or royalty fee is required for any of the authorized uses...Modifications to this software may be copyrighted by their authors..and need not follow the licensing terms described here, provided that..the new terms are clearly indicated on the first page of each file where..they apply.....IN NO EVENT SHALL THE AUTHORS OR DISTRIBUTORS BE LIABLE TO ANY PARTY..FOR DIRECT, INDIRECT, SPECIAL, INCI
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):15255
                                                                                                                                                                                                            Entropy (8bit):4.9510475386072095
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:apDYV5Yupn5OcckwBv3HCpg2J8JvJBfWeZhXkz+WkHGowv:aPPkevB2JuvJ9D3XmSc
                                                                                                                                                                                                            MD5:804E6DCE549B2E541986C0CE9E75E2D1
                                                                                                                                                                                                            SHA1:C44EE09421F127CF7F4070A9508F22709D06D043
                                                                                                                                                                                                            SHA-256:47C75F9F8348BF8F2C086C57B97B73741218100CA38D10B8ABDF2051C95B9801
                                                                                                                                                                                                            SHA-512:029426C4F659848772E6BB1D8182EB03D2B43ADF68FCFCC1EA1C2CC7C883685DEDA3FFFDA7E071912B9BDA616AD7AF2E1CB48CE359700C1A22E1E53E81CAE34B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# listbox.tcl --..#..# This file defines the default bindings for Tk listbox widgets..# and provides procedures that help in implementing those bindings...#..# Copyright (c) 1994 The Regents of the University of California...# Copyright (c) 1994-1995 Sun Microsystems, Inc...# Copyright (c) 1998 by Scriptics Corporation...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....#--------------------------------------------------------------------------..# tk::Priv elements used in this file:..#..# afterId -..Token returned by "after" for autoscanning...# listboxPrev -.The last element to be selected or deselected..#...during a selection operation...# listboxSelection -.All of the items that were selected before the..#...current selection operation (such as a mouse..#...drag) started; used to cancel an operation...#--------------------------------------------------------------------------....#--------------
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Tcl script, ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):9862
                                                                                                                                                                                                            Entropy (8bit):4.786615174847384
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:mvEEVwjVwqOpOLbkVAg/vyKEZ25YbKZbwrmQ:mvEEVwJwpALPgnyx25YGZkr3
                                                                                                                                                                                                            MD5:D83ED6AC2912900040530528A0237AB3
                                                                                                                                                                                                            SHA1:2D18E42A8B96C3D71C1C6701010FDF75C1E6D5D8
                                                                                                                                                                                                            SHA-256:848258B946C002E2696CA3815A1589C8120AF5CC41FBC11BBD9A3F5754CC21AF
                                                                                                                                                                                                            SHA-512:00B4CD0D58029FC37820C163A4AE1DEAD22FB5C767BDC118659EACE26D449C362189611DFB3FAB1AC129FABFEC2CE853EA2C10D418FAE5AEB91DDC9330FF782D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# megawidget.tcl..#..#.Basic megawidget support classes. Experimental for any use other than..#.the ::tk::IconList megawdget, which is itself only designed for use in..#.the Unix file dialogs...#..# Copyright (c) 2009-2010 Donal K. Fellows..#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES...#....package require Tk.....::oo::class create ::tk::Megawidget {.. superclass ::oo::class.. method unknown {w args} {...if {[string match .* $w]} {... [self] create $w {*}$args... return $w...}...next $w {*}$args.. }.. unexport new unknown.. self method create {name superclasses body} {...next $name [list \....superclass ::tk::MegawidgetClass {*}$superclasses]\;$body.. }..}....::oo::class create ::tk::MegawidgetClass {.. variable w hull options IdleCallbacks.. constructor args {...# Extract the "widget name" from the object name...set w [namespace tail [self]].....# Configure things...
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):39790
                                                                                                                                                                                                            Entropy (8bit):4.915612301723047
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:NKJsO8O4IzOQjJwxzire5pKVjriecYyq4CpKgnP:NKJsO8iOQizire54lriecYf40
                                                                                                                                                                                                            MD5:B7DAA21C1C192B8CB5B86CBD7B2CE068
                                                                                                                                                                                                            SHA1:AE8ABF9017F37CCDF5D0D15DE66BB124A7482BA0
                                                                                                                                                                                                            SHA-256:312AF944A276CDBF1EE00757EF141595670984F7F13E19922C25643A040F5339
                                                                                                                                                                                                            SHA-512:B619E3B8BE5EC4545E97B7A7A7F7FECC2AAFA58438F9CA3819F644720CF5FF5C44DA12AC25988570E595D97CAD799F87D93C24D5E67A7A953B9F5312952FBEB6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# menu.tcl --..#..# This file defines the default bindings for Tk menus and menubuttons...# It also implements keyboard traversal of menus and implements a few..# other utility procedures related to menus...#..# Copyright (c) 1992-1994 The Regents of the University of California...# Copyright (c) 1994-1997 Sun Microsystems, Inc...# Copyright (c) 1998-1999 Scriptics Corporation...# Copyright (c) 2007 Daniel A. Steffen <das@users.sourceforge.net>..#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# Elements of tk::Priv that are used in this file:..#..# cursor -..Saves the -cursor option for the posted menubutton...# focus -..Saves the focus during a menu selection operation...#...Focus gets restored here when the menu is unposted...# grabGlobal -..Used in conjunction with tk::Priv(oldGrab): if..#...tk::Priv(oldGrab) is non
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):30840
                                                                                                                                                                                                            Entropy (8bit):5.142909056222569
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:+c4g8rSnBGzHsGK83Ch0x/0kmSq6O4+rNfPCpM2sEmqKys3pCJxi5dEaY:+c4g8OnBGzBK83Ch0x/0FSq6OnrGM2h3
                                                                                                                                                                                                            MD5:983C7B78F1A0EBACAB8006D391A01FCD
                                                                                                                                                                                                            SHA1:7EA37474EA039ED7A37BFDD7D76EAE673E666283
                                                                                                                                                                                                            SHA-256:C5BDCA3ABA671F03DC4624AB5FD260490F5002491D6C619142CCF5A1A744528A
                                                                                                                                                                                                            SHA-512:A006EF9B7213E572F6FC540D1512A52C52FEC44E3A07846DE09662AE32B7191C5CF639798531847B39E4076BF9DD6314B6F5373065C04F4FEF221185B39C3117
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# mkpsenc.tcl --..#..# This file generates the postscript prolog used by Tk.....namespace eval ::tk {.. # Creates Postscript encoding vector for ISO-8859-1 (could theoretically.. # handle any 8-bit encoding, but Tk never generates characters outside.. # ASCII)... #.. proc CreatePostscriptEncoding {} {...variable psglyphs...# Now check for known. Even if it is known, it can be other than we...# need. GhostScript seems to be happy with such approach...set result "\[\n"...for {set i 0} {$i<256} {incr i 8} {... for {set j 0} {$j<8} {incr j} {....set enc [encoding convertfrom "iso8859-1" \.....[format %c [expr {$i+$j}]]]....catch {.... set hexcode {}.... set hexcode [format %04X [scan $enc %c]]....}....if {[info exists psglyphs($hexcode)]} {.... append result "/$psglyphs($hexcode)"....} else {.... append result "/space"....}... }... append result "\n"...}...append result "\]"...return $result.. }.... # List of adobe glyph names. Converted from glyph
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:xbm image (32x, ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):16786
                                                                                                                                                                                                            Entropy (8bit):4.717927930017041
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:+haZOxBpK8uxGe4V88/wxY3Fxqipz4zz4zxxFzxT4OcErDxqdRRZeuC/Vj2CoopC:+hRWRG3FFjvsfCoopwITHzLHFHHAABs
                                                                                                                                                                                                            MD5:217087AB6B2A8F9D7252E311D69C3769
                                                                                                                                                                                                            SHA1:09AEB2BC5B7C7F4AB3DE4211D786C519AE0970F6
                                                                                                                                                                                                            SHA-256:A07E3A3809CED3C6C9C1E171DCA5AD1F28357734CD41B2B9DD9F58085B3D2842
                                                                                                                                                                                                            SHA-512:6E57633C924BFC16D380C014C20DD24D5727E70D4843FCEC4D7995B4DB21941EA8F2A5FD6E5386DF3364B6905D4D66B2B9595DC8FC70CFF40A2D49A92A1B6FBA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# msgbox.tcl --..#..#.Implements messageboxes for platforms that do not have native..#.messagebox support...#..# Copyright (c) 1994-1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# Ensure existence of ::tk::dialog namespace..#..namespace eval ::tk::dialog {}....image create bitmap ::tk::dialog::b1 -foreground black \..-data "#define b1_width 32\n#define b1_height 32..static unsigned char q1_bits[] = {.. 0x00, 0xf8, 0x1f, 0x00, 0x00, 0x07, 0xe0, 0x00, 0xc0, 0x00, 0x00, 0x03,.. 0x20, 0x00, 0x00, 0x04, 0x10, 0x00, 0x00, 0x08, 0x08, 0x00, 0x00, 0x10,.. 0x04, 0x00, 0x00, 0x20, 0x02, 0x00, 0x00, 0x40, 0x02, 0x00, 0x00, 0x40,.. 0x01, 0x00, 0x00, 0x80, 0x01, 0x00, 0x00, 0x80, 0x01, 0x00, 0x00, 0x80,.. 0x01, 0x00, 0x00, 0x80, 0x01, 0x00, 0x00, 0x80, 0x01, 0x00, 0x00, 0x80,.. 0x01, 0x00, 0x00, 0x80, 0x02, 0x00, 0x00, 0x40, 0x02, 0x00, 0x00, 0x40,.. 0x04, 0x00,
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4235
                                                                                                                                                                                                            Entropy (8bit):4.789130604359491
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:nlw9Twd+j3gLhokqwX+hTnJgNanPNcgRhgP+5QPwJJENL:nlw9TjjwI3hTnJgNaRhgP75L
                                                                                                                                                                                                            MD5:5A8B46B85DCCBF74E2B5B820E1A7B9D1
                                                                                                                                                                                                            SHA1:980F4FC5BABA82BA0FE02F9BD03A23DF6D565BB1
                                                                                                                                                                                                            SHA-256:4DFFBEEDBF0D66D84B13088016D1A782CEAAD4DED27BE1E38842F8969C0E533F
                                                                                                                                                                                                            SHA-512:2D81FC06CF3C20E4F6314BD13AF81FDE38A9B06510584C84C6A0C8C36314F980F77D02BD8056E7EE5DE599A0620E0C0349124147334B9C141145270046B19D90
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:namespace eval ::tk {.. ::msgcat::mcset cs "&Abort" "&P\u0159eru\u0161it".. ::msgcat::mcset cs "&About..." "&O programu...".. ::msgcat::mcset cs "All Files" "V\u0161echny soubory".. ::msgcat::mcset cs "Application Error" "Chyba programu".. ::msgcat::mcset cs "Bold Italic".. ::msgcat::mcset cs "&Blue" "&Modr\341".. ::msgcat::mcset cs "Cancel" "Zru\u0161it".. ::msgcat::mcset cs "&Cancel" "&Zru\u0161it".. ::msgcat::mcset cs "Cannot change to the directory \"%1\$s\".\nPermission denied." "Nemohu zm\u011bnit atku\341ln\355 adres\341\u0159 na \"%1\$s\".\nP\u0159\355stup odm\355tnut.".. ::msgcat::mcset cs "Choose Directory" "V\375b\u011br adres\341\u0159e".. ::msgcat::mcset cs "Cl&ear" "Sma&zat".. ::msgcat::mcset cs "&Clear Console" "&Smazat konzolu".. ::msgcat::mcset cs "Color" "Barva".. ::msgcat::mcset cs "Console" "Konzole".. ::msgcat::mcset cs "&Copy" "&Kop\355rovat".. ::msgcat::mcset cs "Cu&t" "V&y\u0159\355znout".. ::msgcat::mcset cs "&
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3987
                                                                                                                                                                                                            Entropy (8bit):4.651948695787255
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:nRZ2uDMr05sIEzs2KkrT+XuTKN0FjDDP9:nRZzDy4kBKkrT+QpP9
                                                                                                                                                                                                            MD5:227B0F255F854460E8E5146ED7A17B85
                                                                                                                                                                                                            SHA1:99A080CAD631F21963C51A5B254BDAD3724DC866
                                                                                                                                                                                                            SHA-256:FEEF8F8AD33BB3362C845A25D6ED273C398051047D899B31790474614C7AFD2D
                                                                                                                                                                                                            SHA-512:36A4B48831316CC29686CC76DA00110EB078EC56F55A960D11AE427AA3D913C340C1E3805BF2AD40C1A8A92FC6587DA5D2C245E7501289FC3E228BE14FE49598
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:namespace eval ::tk {.. ::msgcat::mcset da "&Abort" "&Afbryd".. ::msgcat::mcset da "&About..." "&Om...".. ::msgcat::mcset da "All Files" "Alle filer".. ::msgcat::mcset da "Application Error" "Programfejl".. ::msgcat::mcset da "&Blue" "&Bl\u00E5".. ::msgcat::mcset da "Cancel" "Annuller".. ::msgcat::mcset da "&Cancel" "&Annuller".. ::msgcat::mcset da "Cannot change to the directory \"%1\$s\".\nPermission denied." "Kan ikke skifte til katalog \"%1\$s\".\nIngen rettigheder.".. ::msgcat::mcset da "Choose Directory" "V\u00E6lg katalog".. ::msgcat::mcset da "Cl&ear" "&Ryd".. ::msgcat::mcset da "&Clear Console" "&Ryd konsolen".. ::msgcat::mcset da "Color" "Farve".. ::msgcat::mcset da "Console" "Konsol".. ::msgcat::mcset da "&Copy" "&Kopier".. ::msgcat::mcset da "Cu&t" "Kli&p".. ::msgcat::mcset da "&Delete" "&Slet".. ::msgcat::mcset da "Details >>" "Detailer".. ::msgcat::mcset da "Directory \"%1\$s\" does not exist." "Katalog \"%1\$s\" finde
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4914
                                                                                                                                                                                                            Entropy (8bit):4.6221938909259475
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:nxLEpatioUqGBLbz4ME/XKKVN9R7S/0oYr9:epY3MkXKKxRu2r9
                                                                                                                                                                                                            MD5:2203F65BCDA61BC15AEAC4F868C6D94A
                                                                                                                                                                                                            SHA1:C4CC3975679D23892406E4E8971359A0775B1B86
                                                                                                                                                                                                            SHA-256:C0F574B14068A049E93421C73873D750C98DE28B7B77AA42FE72CBE0270A4186
                                                                                                                                                                                                            SHA-512:79F134FDAD3B12524D43BF9F59D3C04CAE30A95F591A51B82C8DF7CC8563BEA5D464AEECC457D9F60C04365E30459C447ED537AFC832BA25E1815DE06C2B81E5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:namespace eval ::tk {.. ::msgcat::mcset de "&Abort" "&Abbruch".. ::msgcat::mcset de "&About..." "&\u00dcber...".. ::msgcat::mcset de "All Files" "Alle Dateien".. ::msgcat::mcset de "Application Error" "Applikationsfehler".. ::msgcat::mcset de "&Apply" "&Anwenden".. ::msgcat::mcset de "Bold" "Fett".. ::msgcat::mcset de "Bold Italic" "Fett kursiv".. ::msgcat::mcset de "&Blue" "&Blau".. ::msgcat::mcset de "Cancel" "Abbruch".. ::msgcat::mcset de "&Cancel" "&Abbruch".. ::msgcat::mcset de "Cannot change to the directory \"%1\$s\".\nPermission denied." "Kann nicht in das Verzeichnis \"%1\$s\" wechseln.\nKeine Rechte vorhanden.".. ::msgcat::mcset de "Choose Directory" "W\u00e4hle Verzeichnis".. ::msgcat::mcset de "Cl&ear" "&R\u00fccksetzen".. ::msgcat::mcset de "&Clear Console" "&Konsole l\u00f6schen".. ::msgcat::mcset de "Color" "Farbe".. ::msgcat::mcset de "Console" "Konsole".. ::msgcat::mcset de "&Copy" "&Kopieren".. ::msgcat::mcset de "
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with very long lines (355), with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8784
                                                                                                                                                                                                            Entropy (8bit):4.334043617395095
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:tVj/F+oxBHbkI8+xTqFt2zPJ0k63fRGIUvPXrfBNnzc+zIF7meUOT7GC8MO07S0g:fj9+AHlLoozHn7fBFrMVmehCAGb
                                                                                                                                                                                                            MD5:780F863903BBDAA6C371EC0D3C7E6D59
                                                                                                                                                                                                            SHA1:DF5D435E132BEE4C076A7FC577C8C275A8B68CD5
                                                                                                                                                                                                            SHA-256:3F6F155864FE59A341BFD869735E54DD21CEE21BBD038433D9B271AD77BA3F7E
                                                                                                                                                                                                            SHA-512:091965EE912513AE1943BE840A2E757188FBA6F760F7C47BE80D06313D59B051F183E3A29D4B1CEDE1F9E54CA3CA23D75FF2C3A3672A4E71FB56F0FA76F7FA0D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:## Messages for the Greek (Hellenic - "el") language...## Please report any changes/suggestions to:..## petasis@iit.demokritos.gr....namespace eval ::tk {.. ::msgcat::mcset el "&Abort" "\u03a4\u03b5\u03c1\u03bc\u03b1\u03c4\u03b9\u03c3\u03bc\u03cc\u03c2".. ::msgcat::mcset el "About..." "\u03a3\u03c7\u03b5\u03c4\u03b9\u03ba\u03ac...".. ::msgcat::mcset el "All Files" "\u038c\u03bb\u03b1 \u03c4\u03b1 \u0391\u03c1\u03c7\u03b5\u03af\u03b1".. ::msgcat::mcset el "Application Error" "\u039b\u03ac\u03b8\u03bf\u03c2 \u0395\u03c6\u03b1\u03c1\u03bc\u03bf\u03b3\u03ae\u03c2".. ::msgcat::mcset el "&Blue" "\u039c\u03c0\u03bb\u03b5".. ::msgcat::mcset el "&Cancel" "\u0391\u03ba\u03cd\u03c1\u03c9\u03c3\u03b7".. ::msgcat::mcset el \.."Cannot change to the directory \"%1\$s\".\nPermission denied." \.."\u0394\u03b5\u03bd \u03b5\u03af\u03bd\u03b1\u03b9 \u03b4\u03c5\u03bd\u03b1\u03c4\u03ae \u03b7 \u03b1\u03bb\u03bb\u03b1\u03b3\u
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3377
                                                                                                                                                                                                            Entropy (8bit):4.279601088621442
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:sQ7dw5bO0V3gqmCNyoKJ6iwp/uvENv4SKEcET2hsHFjr:n7dwNOc3RmOKJQcvEl4SK1ET2hYFjr
                                                                                                                                                                                                            MD5:D48CFC9EC779085E8F6AAA7B1C40C89A
                                                                                                                                                                                                            SHA1:0CF6253BFF39F40CA0991F9B06D3394BFEA21ED2
                                                                                                                                                                                                            SHA-256:4A33B44B2E220E28EAAE7FAC407CAFE43D97C270DA58FA5F3B699A1760BFB2A4
                                                                                                                                                                                                            SHA-512:C00EC0CFB48ABE621EF625C51952BCF177CE3BC7F0DEC5276EF84C9A97C7E014806B106EA8DEE202C43F8DD54ED7261A8D899E3EE12E3F37A90C387D864463AE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:namespace eval ::tk {.. ::msgcat::mcset en "&Abort".. ::msgcat::mcset en "&About...".. ::msgcat::mcset en "All Files".. ::msgcat::mcset en "Application Error".. ::msgcat::mcset en "&Apply".. ::msgcat::mcset en "Bold".. ::msgcat::mcset en "Bold Italic".. ::msgcat::mcset en "&Blue".. ::msgcat::mcset en "Cancel".. ::msgcat::mcset en "&Cancel".. ::msgcat::mcset en "Cannot change to the directory \"%1\$s\".\nPermission denied.".. ::msgcat::mcset en "Choose Directory".. ::msgcat::mcset en "Cl&ear".. ::msgcat::mcset en "&Clear Console".. ::msgcat::mcset en "Color".. ::msgcat::mcset en "Console".. ::msgcat::mcset en "&Copy".. ::msgcat::mcset en "Cu&t".. ::msgcat::mcset en "&Delete".. ::msgcat::mcset en "Details >>".. ::msgcat::mcset en "Directory \"%1\$s\" does not exist.".. ::msgcat::mcset en "&Directory:".. ::msgcat::mcset en "&Edit".. ::msgcat::mcset en "Effects".. ::msgcat::mcset en "Error: %1\$s".. ::msgcat::mcs
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):66
                                                                                                                                                                                                            Entropy (8bit):4.262228832346611
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:fEGp6fRyv//mGoW8vMKEQXyVn:sooyv//xoQOOn
                                                                                                                                                                                                            MD5:3D41FC47CD9936F817EF9645D73A77ED
                                                                                                                                                                                                            SHA1:E62BBE094B71CAF4A389DE3ECD84D2EEFBA33827
                                                                                                                                                                                                            SHA-256:01238293356E82F1D298896491F8B299BB7DC9C34F299C9E756254C736DA612B
                                                                                                                                                                                                            SHA-512:B92582C32C4D7CD9DE6571CBB6B93DD693A8B5A80645468E2D02B80C339BE2B95D5B4878A0DA9AFFE9E2F98A6C38AAE9CC1FF2440146D0ED128FE8C9A92EECDB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:namespace eval ::tk {.. ::msgcat::mcset en_gb Color Colour..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4035
                                                                                                                                                                                                            Entropy (8bit):4.614759526381991
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:n6oXunu4/LQmI+nl0WemQ+uISIKk/2nibN5My/uXcFSZHBohy:n6oXuu4jJtlPemVuISIKkuniJS1Gy
                                                                                                                                                                                                            MD5:3704A08985B0AA3C521FDF9C2DA59D97
                                                                                                                                                                                                            SHA1:3F1E42C5697504B4DEE1EE314CD361B4203BF686
                                                                                                                                                                                                            SHA-256:84B117857674A2426290946053A61316C5C8C6808F2C6EDF0ECC5C4A9C5C72AC
                                                                                                                                                                                                            SHA-512:99FE97B10B1CA59DDA0385161E7C05F7D22424B6B1FB844138921EF94B2E9809D73EBC0062897D0DDE040CF92C96A6E4916CC9F3F02442AE2C4162858434B6BA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:namespace eval ::tk {.. ::msgcat::mcset eo "&Abort" "&\u0108esigu".. ::msgcat::mcset eo "&About..." "Pri...".. ::msgcat::mcset eo "All Files" "\u0108iuj dosieroj".. ::msgcat::mcset eo "Application Error" "Aplikoeraro".. ::msgcat::mcset eo "&Blue" "&Blua".. ::msgcat::mcset eo "Cancel" "Rezignu".. ::msgcat::mcset eo "&Cancel" "&Rezignu".. ::msgcat::mcset eo "Cannot change to the directory \"%1\$s\".\nPermission denied." "Neeble \u015dan\u011di al dosierujo \"%1\$s\".\nVi ne rajtas tion.".. ::msgcat::mcset eo "Choose Directory" "Elektu Dosierujon".. ::msgcat::mcset eo "Cl&ear" "&Vakigu".. ::msgcat::mcset eo "&Clear Console" "&Vakigu konzolon".. ::msgcat::mcset eo "Color" "Koloro".. ::msgcat::mcset eo "Console" "Konzolo".. ::msgcat::mcset eo "&Copy" "&Kopiu".. ::msgcat::mcset eo "Cu&t" "&Eltondu".. ::msgcat::mcset eo "&Delete" "&Forigu".. ::msgcat::mcset eo "Details >>" "Detaloj >>".. ::msgcat::mcset eo "Directory \"%1\$s\" does not exi
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4024
                                                                                                                                                                                                            Entropy (8bit):4.536517819515934
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:nN0T1Lt8ZYSih/aiik148aFscyTzoixccUTqjcg60Dx/H5:nN0BLSQUXy/o8re055
                                                                                                                                                                                                            MD5:4765F3C055742530E4644771EBC6C69F
                                                                                                                                                                                                            SHA1:8BEA722AC00522DEAA5B380AEEF4CA57D7A271BD
                                                                                                                                                                                                            SHA-256:D2842B80F1B521EFF2D2656A69274B5F2A8F4F5831AF2E8EE73E3C37389F981F
                                                                                                                                                                                                            SHA-512:9CA247F22797A1A1FCA42B5CDABF58262ED95EECDDD321CEB1440A60A4375923E0F511238F360D159EB5EED6F82CBBE0B8907A07CC77DB831BF97082932CD0FD
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:namespace eval ::tk {.. ::msgcat::mcset es "&Abort" "&Abortar".. ::msgcat::mcset es "&About..." "&Acerca de ...".. ::msgcat::mcset es "All Files" "Todos los archivos".. ::msgcat::mcset es "Application Error" "Error de la aplicaci\u00f3n".. ::msgcat::mcset es "&Blue" "&Azul".. ::msgcat::mcset es "Cancel" "Cancelar".. ::msgcat::mcset es "&Cancel" "&Cancelar".. ::msgcat::mcset es "Cannot change to the directory \"%1\$s\".\nPermission denied." "No es posible acceder al directorio \"%1\$s\".\nPermiso denegado.".. ::msgcat::mcset es "Choose Directory" "Elegir directorio".. ::msgcat::mcset es "Cl&ear" "&Borrar".. ::msgcat::mcset es "&Clear Console" "&Borrar consola".. ::msgcat::mcset es "Color".. ::msgcat::mcset es "Console" "Consola".. ::msgcat::mcset es "&Copy" "&Copiar".. ::msgcat::mcset es "Cu&t" "Cor&tar".. ::msgcat::mcset es "&Delete" "&Borrar".. ::msgcat::mcset es "Details >>" "Detalles >>".. ::msgcat::mcset es "Directory \"%1\$s\"
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4693
                                                                                                                                                                                                            Entropy (8bit):4.640083757706223
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:najdLGoC0TXwqTwPRNQXfdHzAIX169ZZv6CpvgIPJupuupw6kWVVxn6/9Yv:nWdLGo2WiMn4t5pvbxuPtx6F6
                                                                                                                                                                                                            MD5:BD795A1D95446BEE7AEB16FB6E346271
                                                                                                                                                                                                            SHA1:38469DBD386C35B90EBE0A0FE2CE9F1AB5A5444A
                                                                                                                                                                                                            SHA-256:893BEDCDAED4602898D988E6248B8BB0857DD66C06194B45F31340CA03D82369
                                                                                                                                                                                                            SHA-512:B9BDDECB1DE2025C6C4027BF6228A14D5F573F5859ED3444298809266F06E6203F72004D589314C6529A2E198039355B4FD6160F87DA8F97B55E9F841B6C3F5A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:namespace eval ::tk {.. ::msgcat::mcset fi "&Abort" "&Keskeyt\u00e4".. ::msgcat::mcset fi "&About..." "&Tietoja...".. ::msgcat::mcset fi "All Files" "Kaikki tiedostot".. ::msgcat::mcset fi "Application Error" "Ohjelmavirhe".. ::msgcat::mcset fi "&Apply" "K\u00e4&yt\u00e4".. ::msgcat::mcset fi "Bold" "Lihavoitu".. ::msgcat::mcset fi "Bold Italic" "Lihavoitu, kursivoitu".. ::msgcat::mcset fi "&Blue" "&Sininen".. ::msgcat::mcset fi "Cancel" "Peruuta".. ::msgcat::mcset fi "&Cancel" "&Peruuta".. ::msgcat::mcset fi "Cannot change to the directory \"%1\$s\".\nPermission denied." "Ei voitu vaihtaa hakemistoon \"%1\$s\".\nLupa ev\u00e4tty.".. ::msgcat::mcset fi "Choose Directory" "Valitse hakemisto".. ::msgcat::mcset fi "Cl&ear" "&Tyhjenn\u00e4".. ::msgcat::mcset fi "&Clear Console" "&Tyhjenn\u00e4 konsoli".. ::msgcat::mcset fi "Color" "V\u00e4ri".. ::msgcat::mcset fi "Console" "Konsoli".. ::msgcat::mcset fi "&Copy" "K&opioi".. ::msgcat::mcs
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3877
                                                                                                                                                                                                            Entropy (8bit):4.630737553723335
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:nByEWs/3lHFB9FamsIfSAzZ2eaISAxh0BRc3jC:nByEWaRNzsSSWonMAv
                                                                                                                                                                                                            MD5:E279E5FFF03E1B8E9063ABC8A499A6BD
                                                                                                                                                                                                            SHA1:80910911F6B4830BA4DCBA9A9EAD12C9F802DDC9
                                                                                                                                                                                                            SHA-256:3F2CEB4A33695AB6B56E27F61A4C60C029935BB026497D99CB2C246BCB4A63C4
                                                                                                                                                                                                            SHA-512:8333388E421AC3F342317BEBE352809B0B190EF8B044A0BAE2FE4051974D86008BAFDCB7098E9DC39A8D9E1E08FB87F54B9D3388AF2D0185FF913DB6788C5AB5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:namespace eval ::tk {.. ::msgcat::mcset fr "&Abort" "&Annuler".. ::msgcat::mcset fr "About..." "\u00c0 propos...".. ::msgcat::mcset fr "All Files" "Tous les fichiers".. ::msgcat::mcset fr "Application Error" "Erreur d'application".. ::msgcat::mcset fr "&Blue" "&Bleu".. ::msgcat::mcset fr "Cancel" "Annuler".. ::msgcat::mcset fr "&Cancel" "&Annuler".. ::msgcat::mcset fr "Cannot change to the directory \"%1\$s\".\nPermission denied." "Impossible d'acc\u00e9der au r\u00e9pertoire \"%1\$s\".\nPermission refus\u00e9e.".. ::msgcat::mcset fr "Choose Directory" "Choisir r\u00e9pertoire".. ::msgcat::mcset fr "Cl&ear" "Effacer".. ::msgcat::mcset fr "Color" "Couleur".. ::msgcat::mcset fr "Console".. ::msgcat::mcset fr "Copy" "Copier".. ::msgcat::mcset fr "Cu&t" "Couper".. ::msgcat::mcset fr "Delete" "Effacer".. ::msgcat::mcset fr "Details >>" "D\u00e9tails >>".. ::msgcat::mcset fr "Directory \"%1\$s\" does not exist." "Le r\u00e9pertoire \"%1\$s\"
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4678
                                                                                                                                                                                                            Entropy (8bit):4.7955991577265245
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:nkCEz2TTrKmA17fzq/Hj+pUva+fQR/a5a/Thn5kU:kTqM17u/8NiMrhb
                                                                                                                                                                                                            MD5:4F1610E0C73DAE668E3F9D9235631152
                                                                                                                                                                                                            SHA1:63EE54A6C1A69B798C65C999D5F80A7AB252B6D8
                                                                                                                                                                                                            SHA-256:E063AD7CA93F37728A65E4CD7C0433950F22607D307949F6CB056446AFEAA4FE
                                                                                                                                                                                                            SHA-512:37F4B8A9CD020A77591C09AF40FBC2FA82107B2596D31B5F30CE6ECAA225417CF7A5C62FB7A93539B0D7E930D0A44F9BF2EE6BE113F831B0A72B229444672AFD
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:namespace eval ::tk {.. ::msgcat::mcset hu "&Abort" "&Megszak\u00edt\u00e1s".. ::msgcat::mcset hu "&About..." "N\u00e9vjegy...".. ::msgcat::mcset hu "All Files" "Minden f\u00e1jl".. ::msgcat::mcset hu "Application Error" "Alkalmaz\u00e1s hiba".. ::msgcat::mcset hu "&Blue" "&K\u00e9k".. ::msgcat::mcset hu "Cancel" "M\u00e9gsem".. ::msgcat::mcset hu "&Cancel" "M\u00e9g&sem".. ::msgcat::mcset hu "Cannot change to the directory \"%1\$s\".\nPermission denied." "A k\u00f6nyvt\u00e1rv\u00e1lt\u00e1s nem siker\u00fclt: \"%1\$s\".\nHozz\u00e1f\u00e9r\u00e9s megtagadva.".. ::msgcat::mcset hu "Choose Directory" "K\u00f6nyvt\u00e1r kiv\u00e1laszt\u00e1sa".. ::msgcat::mcset hu "Cl&ear" "T\u00f6rl\u00e9s".. ::msgcat::mcset hu "&Clear Console" "&T\u00f6rl\u00e9s Konzol".. ::msgcat::mcset hu "Color" "Sz\u00edn".. ::msgcat::mcset hu "Console" "Konzol".. ::msgcat::mcset hu "&Copy" "&M\u00e1sol\u00e1s".. ::msgcat::mcset hu "Cu&t" "&Kiv\u00e1g\u00e1s".. ::ms
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3765
                                                                                                                                                                                                            Entropy (8bit):4.49679862548805
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:nmU4xnonTjwUE5Xs6ZrT8BpXAg+Wr+u92C8t7mU9nUSs:nZ4FonFE58HBpXjr+fBJs
                                                                                                                                                                                                            MD5:B74C54666A5A431A782DB691B4CA3315
                                                                                                                                                                                                            SHA1:2BC63982C14BBA8A4C451CE31540181F40CE2216
                                                                                                                                                                                                            SHA-256:806930F283FD097195C7850E3486B3815D1564529B4F8E5FA6D26F3175183BC1
                                                                                                                                                                                                            SHA-512:8120E2FFD14E0A992E254796ADDC0DC995C921BE31688C0995D7A36FE82609D78791FEF73EAF5B14E2F0D40AD256AB8DAAA07C18E6950362B28E40B71E47C0B6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:namespace eval ::tk {.. ::msgcat::mcset it "&Abort" "&Interrompi".. ::msgcat::mcset it "&About..." "Informazioni...".. ::msgcat::mcset it "All Files" "Tutti i file".. ::msgcat::mcset it "Application Error" "Errore dell' applicazione".. ::msgcat::mcset it "&Blue" "&Blu".. ::msgcat::mcset it "Cancel" "Annulla".. ::msgcat::mcset it "&Cancel" "&Annulla".. ::msgcat::mcset it "Cannot change to the directory \"%1\$s\".\nPermission denied." "Impossibile accedere alla directory \"%1\$s\".\nPermesso negato.".. ::msgcat::mcset it "Choose Directory" "Scegli una directory".. ::msgcat::mcset it "Cl&ear" "Azzera".. ::msgcat::mcset it "&Clear Console" "Azzera Console".. ::msgcat::mcset it "Color" "Colore".. ::msgcat::mcset it "Console".. ::msgcat::mcset it "&Copy" "Copia".. ::msgcat::mcset it "Cu&t" "Taglia".. ::msgcat::mcset it "Delete" "Cancella".. ::msgcat::mcset it "Details >>" "Dettagli >>".. ::msgcat::mcset it "Directory \"%1\$s\" does not ex
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4557
                                                                                                                                                                                                            Entropy (8bit):4.524344068436489
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:nucQswBju0x0M4U2z9KSSOzZL5KhWTqGGIrlxXvhYbL/ZO5NT+T4kiLzzdDf1SDM:nLGa0x0Mp2KSHKSv2bL/ZO5u6nRfAXU9
                                                                                                                                                                                                            MD5:E56229BAC5A8ABB90C4DD8EE3F9FF9F8
                                                                                                                                                                                                            SHA1:7527D6C3C6C84BFF0E683FFA86A21C58458EB55D
                                                                                                                                                                                                            SHA-256:0914FBA42361227D14FA281E8A9CBF57C16200B4DA1E61CC3402EF0113A512C7
                                                                                                                                                                                                            SHA-512:13649DDB06DB4BA9E39BEAF828211086A519444DA9AB5CBDD1B88B29208388189A5141F75AD94B56A348EDDE534FFADE8B19B557CB988EA4ECC9A84B135D36C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:namespace eval ::tk {.. ::msgcat::mcset nl "&Abort" "&Afbreken".. ::msgcat::mcset nl "&About..." "Over...".. ::msgcat::mcset nl "All Files" "Alle Bestanden".. ::msgcat::mcset nl "Application Error" "Toepassingsfout".. ::msgcat::mcset nl "&Apply" "Toepassen".. ::msgcat::mcset nl "Bold" "Vet".. ::msgcat::mcset nl "Bold Italic" "Vet Cursief".. ::msgcat::mcset nl "&Blue" "&Blauw".. ::msgcat::mcset nl "Cancel" "Annuleren".. ::msgcat::mcset nl "&Cancel" "&Annuleren".. ::msgcat::mcset nl "Cannot change to the directory \"%1\$s\".\nPermission denied." "Kan niet naar map \"%1\$s\" gaan.\nU heeft hiervoor geen toestemming.".. ::msgcat::mcset nl "Choose Directory" "Kies map".. ::msgcat::mcset nl "Cl&ear" "Wissen".. ::msgcat::mcset nl "&Clear Console" "&Wis Console".. ::msgcat::mcset nl "Color" "Kleur".. ::msgcat::mcset nl "Console".. ::msgcat::mcset nl "&Copy" "Kopi\u00ebren".. ::msgcat::mcset nl "Cu&t" "Knippen".. ::msgcat::mcset nl "&Dele
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4932
                                                                                                                                                                                                            Entropy (8bit):4.799369674927008
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:nXra9E310fwNCeVsvSmy6MZv8lWBTDGdZ3tojTyrEQmAUCIx4wBxZ:n7a9Q0fyw5MQWgP3uoZChB3
                                                                                                                                                                                                            MD5:8CFA2E38822303FDCB55AE3277F0B81B
                                                                                                                                                                                                            SHA1:447F28A5064FCEA019C60B3F9B6D50CD43C2D0E3
                                                                                                                                                                                                            SHA-256:EACEB1F08DE0863CCF726881E07FE5B135EA09646C5253E0CBF7DDB987EB0D92
                                                                                                                                                                                                            SHA-512:E38BA9059AFF55C2B22A4AE24D6A76149C76DBA8BF8646AE81D6E07D7ED490D0605034B29D9AC848E6685C8EC26A3DBE5B2EAF462B14D96376E80076FBE7082A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:namespace eval ::tk {.. ::msgcat::mcset pl "&Abort" "&Przerwij".. ::msgcat::mcset pl "&About..." "O programie...".. ::msgcat::mcset pl "All Files" "Wszystkie pliki".. ::msgcat::mcset pl "Application Error" "B\u0142\u0105d w programie".. ::msgcat::mcset pl "&Apply" "Zastosuj".. ::msgcat::mcset pl "Bold" "Pogrubienie".. ::msgcat::mcset pl "Bold Italic" "Pogrubiona kursywa".. ::msgcat::mcset pl "&Blue" "&Niebieski".. ::msgcat::mcset pl "Cancel" "Anuluj".. ::msgcat::mcset pl "&Cancel" "&Anuluj".. ::msgcat::mcset pl "Cannot change to the directory \"%1\$s\".\nPermission denied." "Nie mo\u017cna otworzy\u0107 katalogu \"%1\$s\".\nOdmowa dost\u0119pu.".. ::msgcat::mcset pl "Choose Directory" "Wybierz katalog".. ::msgcat::mcset pl "Cl&ear" "&Wyczy\u015b\u0107".. ::msgcat::mcset pl "&Clear Console" "&Wyczy\u015b\u0107 konsol\u0119".. ::msgcat::mcset pl "Color" "Kolor".. ::msgcat::mcset pl "Console" "Konsola".. ::msgcat::mcset pl "&Copy" "&Kopiu
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3987
                                                                                                                                                                                                            Entropy (8bit):4.63232183429232
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:nHOT1mM5qHHxiBHb3joTjtcp2UqMxweo6VvilCMKKXx9vjM:nHOT1mMQnwB/otcUUpGX6VPVoLjM
                                                                                                                                                                                                            MD5:4018686F2A8E299D86BDB1478BC97896
                                                                                                                                                                                                            SHA1:0EECE3D57F2EA5EECE8157B06F3AFB97E1F2551A
                                                                                                                                                                                                            SHA-256:D687F71F0432BB0D02EFDF576E526D2C19D4136F76C41A3224A2F034168F3F34
                                                                                                                                                                                                            SHA-512:4D730068B2A21E1D6004205B10A9D0D5EE9683FEB03B6FB673E8B9B94ED6BE468086A52DFE97C4DBF35A07CBB2C5E276DF0952A06C78E029D53D796CB6FCC8DF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:namespace eval ::tk {.. ::msgcat::mcset pt "&Abort" "&Abortar".. ::msgcat::mcset pt "About..." "Sobre ...".. ::msgcat::mcset pt "All Files" "Todos os arquivos".. ::msgcat::mcset pt "Application Error" "Erro de aplica\u00e7\u00e3o".. ::msgcat::mcset pt "&Blue" "&Azul".. ::msgcat::mcset pt "Cancel" "Cancelar".. ::msgcat::mcset pt "&Cancel" "&Cancelar".. ::msgcat::mcset pt "Cannot change to the directory \"%1\$s\".\nPermission denied." "N\u00e3o foi poss\u00edvel mudar para o diret\u00f3rio \"%1\$s\".\nPermiss\u00e3o negada.".. ::msgcat::mcset pt "Choose Directory" "Escolha um diret\u00f3rio".. ::msgcat::mcset pt "Cl&ear" "Apagar".. ::msgcat::mcset pt "&Clear Console" "Apagar Console".. ::msgcat::mcset pt "Color" "Cor".. ::msgcat::mcset pt "Console".. ::msgcat::mcset pt "&Copy" "Copiar".. ::msgcat::mcset pt "Cu&t" "Recortar".. ::msgcat::mcset pt "&Delete" "Excluir".. ::msgcat::mcset pt "Details >>" "Detalhes >>".. ::msgcat::mcset pt "D
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8620
                                                                                                                                                                                                            Entropy (8bit):4.477728981060218
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:n9MEBGkFKT4YHCDhxqEMk0yOC2xXLtSRoxwKl9zFAWx2yuV9cDcwRjnWNQuNFNfO:T0rm8IONoRkN1w+jRQ/FoxrRHRJP
                                                                                                                                                                                                            MD5:C69A904A57FDC95520086E9DDFED362C
                                                                                                                                                                                                            SHA1:F0220602ABE91FE563E5AA6A4EA4AB43818C0CFC
                                                                                                                                                                                                            SHA-256:F0D310A2EE9C0AF928D822CBB39BCBE54FB2C1C95EE8167DFFD55EDC1B2FE040
                                                                                                                                                                                                            SHA-512:808B82F29B7BA06AF5AE44C6C23EC8DD743E93B391F060C7586D6D3FF26C97294BD11AD215848EBA422491BD50C4509330DD24C83134C7A384E81304133CAADB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:namespace eval ::tk {.. ::msgcat::mcset ru "&Abort" "&\u041e\u0442\u043c\u0435\u043d\u0438\u0442\u044c".. ::msgcat::mcset ru "&About..." "\u041f\u0440\u043e...".. ::msgcat::mcset ru "All Files" "\u0412\u0441\u0435 \u0444\u0430\u0439\u043b\u044b".. ::msgcat::mcset ru "Application Error" "\u041e\u0448\u0438\u0431\u043a\u0430 \u0432 \u043f\u0440\u043e\u0433\u0440\u0430\u043c\u043c\u0435".. ::msgcat::mcset ru "&Apply" "&\u041f\u0440\u0438\u043c\u0435\u043d\u0438\u0442\u044c".. ::msgcat::mcset ru "Bold" "Bold".. ::msgcat::mcset ru "Bold Italic" "Bold Italic".. ::msgcat::mcset ru "&Blue" " &\u0413\u043e\u043b\u0443\u0431\u043e\u0439".. ::msgcat::mcset ru "Cancel" "\u041e\u0442\u043c\u0435\u043d\u0430".. ::msgcat::mcset ru "&Cancel" "\u041e\u0442&\u043c\u0435\u043d\u0430".. ::msgcat::mcset ru "Cannot change to the directory \"%1\$s\".\nPermission denied." \....."\u041d\u0435 \u043c\u043e\u0433\u0443 \u043f\u0435\u0440\u0435\u0439\u0442\u0438 \u0432 \u043a\u043
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3908
                                                                                                                                                                                                            Entropy (8bit):4.658068191079967
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:nT8A5cbwKmtI1sE9xt6BDyepTr2iiK/yGqXZlBp9:nD5cb2extDepTCnVpJ9
                                                                                                                                                                                                            MD5:1D085A672A6FCDECEF5D7D876E4C74A3
                                                                                                                                                                                                            SHA1:1A40C03F15A6926359CA3E5C0A809485CAD28AEE
                                                                                                                                                                                                            SHA-256:A6821A13D34FB31F1827294B82C4BF9586BB255CA14F78C3ACE11181F42EF211
                                                                                                                                                                                                            SHA-512:981EDEEF5E4C915BB8F10044096B412D1855CAD08F98A448C6C0A49A54222945EBD102DDCB9525535E0FB19313C319155FA59384605B2C36CC8B4A58693D57E7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:namespace eval ::tk {.. ::msgcat::mcset sv "&Abort" "&Avsluta".. ::msgcat::mcset sv "&About..." "&Om...".. ::msgcat::mcset sv "All Files" "Samtliga filer".. ::msgcat::mcset sv "Application Error" "Programfel".. ::msgcat::mcset sv "&Blue" "&Bl\u00e5".. ::msgcat::mcset sv "Cancel" "Avbryt".. ::msgcat::mcset sv "&Cancel" "&Avbryt".. ::msgcat::mcset sv "Cannot change to the directory \"%1\$s\".\nPermission denied." "Kan ej n\u00e5 mappen \"%1\$s\".\nSaknar r\u00e4ttigheter.".. ::msgcat::mcset sv "Choose Directory" "V\u00e4lj mapp".. ::msgcat::mcset sv "Cl&ear" "&Radera".. ::msgcat::mcset sv "&Clear Console" "&Radera konsollen".. ::msgcat::mcset sv "Color" "F\u00e4rg".. ::msgcat::mcset sv "Console" "Konsoll".. ::msgcat::mcset sv "&Copy" "&Kopiera".. ::msgcat::mcset sv "Cu&t" "Klipp u&t".. ::msgcat::mcset sv "&Delete" "&Radera".. ::msgcat::mcset sv "Details >>" "Detaljer >>".. ::msgcat::mcset sv "Directory \"%1\$s\" does not exist." "Mapp
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4951
                                                                                                                                                                                                            Entropy (8bit):5.319678095131993
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:nnIoT3wHqLHQslojYhOvZSVGNUpi6Zz0qBAE9A+uiTrBsyqCgnPLz:nnIoT3wHU/osIAwNILt0HE2oV6CgPLz
                                                                                                                                                                                                            MD5:1435107EB17A09E4AD7277FFA1C76913
                                                                                                                                                                                                            SHA1:9990C26829275F16C6FC494D32C4298EC541E7D3
                                                                                                                                                                                                            SHA-256:B6802B7B080A2D8BC3D81614EC55A609CB5EF673C7A81E93E07925D6710F90DD
                                                                                                                                                                                                            SHA-512:4B2CAE4FA135411761D5B7CBFFABCE87D745A9B6496C7FD7C4AF10E76EE36E51CA62A1417CF6C27070EFF9539A305BE45C010AE4F8532C8C2D915FA101F5157E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:namespace eval ::tk {.. ::msgcat::mcset zh_cn "&Abort" "&..".. ::msgcat::mcset zh_cn "&About..." "&....".. ::msgcat::mcset zh_cn "All Files" "....".. ::msgcat::mcset zh_cn "Application Error" "......".. ::msgcat::mcset zh_cn "&Apply" "&..".. ::msgcat::mcset zh_cn "Bold" "..".. ::msgcat::mcset zh_cn "Bold Italic" "....".. ::msgcat::mcset zh_cn "&Blue" "&..".. ::msgcat::mcset zh_cn "Cancel" "..".. ::msgcat::mcset zh_cn "&Cancel" "&..".. ::msgcat::mcset zh_cn "Cannot change to the directory \"%1\$s\".\nPermission denied." "...... \"%1\$s\".\n......".. ::msgcat::mcset zh_cn "Choose Directory" ".....".. ::msgcat::mcset zh_cn "Cl&ear" ".&.".. ::msgcat::mcset zh_cn "&Clear Console" "&....".. ::msgcat::mcset zh_cn "Color" "..".. ::msgcat::mcset zh_cn "Console" "..".. ::msgcat::mcset zh_cn "&Copy" "&..".. ::msgcat::mcset zh
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):5772
                                                                                                                                                                                                            Entropy (8bit):5.038729016734604
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:onzxtm7EMgdMjwPqeuAmz9LD1kFIQETZqoIK/RLf7w:ozxtm7qUwi79l0sZqoBJLDw
                                                                                                                                                                                                            MD5:FC9E03823BEB08DAF7681C09D106DF7D
                                                                                                                                                                                                            SHA1:7D06FC8F98140E0FFAA2571BD522FC772E58DE54
                                                                                                                                                                                                            SHA-256:540EEECBA17207A56290BAFFDAE882BBD4F88364791204AD5D14C7BEDD022CCC
                                                                                                                                                                                                            SHA-512:2B5BAD311A703A0FE2ED67ACE311BAD4C767BCD23DFC3D9ABDF5C3604146A6A15D6BD13A14BDEFCDB2B602C708AACFAB404E96FCBA7C546AD0DAECD4BE2EB34A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# obsolete.tcl --..#..# This file contains obsolete procedures that people really shouldn't..# be using anymore, but which are kept around for backward compatibility...#..# Copyright (c) 1994 The Regents of the University of California...# Copyright (c) 1994 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# The procedures below are here strictly for backward compatibility with..# Tk version 3.6 and earlier. The procedures are no longer needed, so..# they are no-ops. You should not use these procedures anymore, since..# they may be removed in some future release.....proc tk_menuBar args {}..proc tk_bindForTraversal args {}....# ::tk::classic::restore --..#..# Restore the pre-8.5 (Tk classic) look as the widget defaults for classic..# Tk widgets...#..# The value following an 'option add' call is the new 8.5 value...#..namespace eval ::tk::classic {.. # This may need t
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1629
                                                                                                                                                                                                            Entropy (8bit):4.784780799273752
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:g2hBuOrlkBytcqYXRE5fvvXq1EhJPqOj6Wf0cVlN:gQ6q4E5HCqhBqOhcaD
                                                                                                                                                                                                            MD5:9B7A8FD2C6B538FF31BDC380452C6DE3
                                                                                                                                                                                                            SHA1:3F915BFE85CED9F6C7E9A352718770E9F14F098E
                                                                                                                                                                                                            SHA-256:40CA505C9784B0767D4854485C5C311829594A4FCBDFD7251E60E6BB7EA74FD1
                                                                                                                                                                                                            SHA-512:43937152B844BE1E597E99DA1270E54AB1D572AE89CB759E6D41C18C9C8044CCC15A6925F9C5AF617AE9EC1404E78C2733231F4D5C6CFE4D23C546387B1FC328
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# optMenu.tcl --..#..# This file defines the procedure tk_optionMenu, which creates..# an option button and its associated menu...#..# Copyright (c) 1994 The Regents of the University of California...# Copyright (c) 1994 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# ::tk_optionMenu --..# This procedure creates an option button named $w and an associated..# menu. Together they provide the functionality of Motif option menus:..# they can be used to select one of many values, and the current value..# appears in the global variable varName, as well as in the text of..# the option menubutton. The name of the menu is returned as the..# procedure's result, so that the caller can use it to change configuration..# options on the menu or otherwise manipulate it...#..# Arguments:..# w -...The name to use for the menubutton...# varName -..Global variable to hold the currently
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8418
                                                                                                                                                                                                            Entropy (8bit):4.964814946573677
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:HWh/x+hFMyTA/CTzxFoUuliRLDm8pQrQlENPyF3o48M6C:HWL+MyTA/CTzvAiRqyEw3ok
                                                                                                                                                                                                            MD5:4CE08A10CD9AE941654B8C679DF669F3
                                                                                                                                                                                                            SHA1:F1288BABCA698FD18C3BD221E6AE6C02F2975AAE
                                                                                                                                                                                                            SHA-256:849B4C57E4644E51BEAEAEB3AE59B7FF067E582ECD10F1B2CAF6B6E72F11F506
                                                                                                                                                                                                            SHA-512:0F37539DA3540E9B1DA7B0377E3BBB359B71DB4271D63BC9501E95931B4E609E8CB91DC2F7B08A6452598D4A0D58C6A2034049A215000EEF0F93A9963D003632
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# palette.tcl --..#..# This file contains procedures that change the color palette used..# by Tk...#..# Copyright (c) 1995-1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# ::tk_setPalette --..# Changes the default color scheme for a Tk application by setting..# default colors in the option database and by modifying all of the..# color options for existing widgets that have the default value...#..# Arguments:..# The arguments consist of either a single color name, which..# will be used as the new background color (all other colors will..# be computed from this) or an even number of values consisting of..# option names and values. The name for an option is the one used..# for the option database, such as activeForeground, not -activeforeground.....proc ::tk_setPalette {args} {.. if {[winfo depth .] == 1} {...# Just return on monochrome displays, otherwise errors
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):5370
                                                                                                                                                                                                            Entropy (8bit):4.979530133775421
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:ssAXzkTQ9w5fLQYkJLZkRXKUXfwyZTq2sz8j2Em3YKhrYK:jAXgE0DQpJLGR6UXfpqnzG3m3YKhrYK
                                                                                                                                                                                                            MD5:286C01A1B12261BC47F5659FD1627ABD
                                                                                                                                                                                                            SHA1:4CA36795CAB6DFE0BBBA30BB88A2AB71A0896642
                                                                                                                                                                                                            SHA-256:AA4F87E41AC8297F51150F2A9F787607690D01793456B93F0939C54D394731F9
                                                                                                                                                                                                            SHA-512:D54D5A89B7408A9724A1CA1387F6473BDAD33885194B2EC5A524C7853A297FD65CE2A57F571C51DB718F6A00DCE845DE8CF5F51698F926E54ED72CDC81BCFE54
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# panedwindow.tcl --..#..# This file defines the default bindings for Tk panedwindow widgets and..# provides procedures that help in implementing those bindings.....bind Panedwindow <Button-1> { ::tk::panedwindow::MarkSash %W %x %y 1 }..bind Panedwindow <Button-2> { ::tk::panedwindow::MarkSash %W %x %y 0 }....bind Panedwindow <B1-Motion> { ::tk::panedwindow::DragSash %W %x %y 1 }..bind Panedwindow <B2-Motion> { ::tk::panedwindow::DragSash %W %x %y 0 }....bind Panedwindow <ButtonRelease-1> {::tk::panedwindow::ReleaseSash %W 1}..bind Panedwindow <ButtonRelease-2> {::tk::panedwindow::ReleaseSash %W 0}....bind Panedwindow <Motion> { ::tk::panedwindow::Motion %W %x %y }....bind Panedwindow <Leave> { ::tk::panedwindow::Leave %W }....# Initialize namespace..namespace eval ::tk::panedwindow {}....# ::tk::panedwindow::MarkSash --..#..# Handle marking the correct sash for possible dragging..#..# Arguments:..# w..the widget..# x..widget local x coord..# y..widget local y coord..# proxy.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):376
                                                                                                                                                                                                            Entropy (8bit):5.040809246948068
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:CsUgabAOgjDnzJNBc6ynID/cL4RpncleXN17MQ9PCSIBIQ08hof7MQ9PCSIBIQei:lGbyntNO6LYZliCNBIUhkCNBIFi
                                                                                                                                                                                                            MD5:8A0517A7A4C70111080ED934329E2BC5
                                                                                                                                                                                                            SHA1:5B465E0D3500A8F04EE1C705662032F44E2ED0D2
                                                                                                                                                                                                            SHA-256:A5D208887A94832328C3A33928A80F3B46AA205C20DB4F050A47D940E94071B4
                                                                                                                                                                                                            SHA-512:D9F502A006A5E0514FD61426818AD1F4168E449588F9D383D6B0BF87A18BE82C420863A9A28E1BEB441284A0B1BC2A0B3D3276A0FE3196341AEC15A27920DE5D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:if {![package vsatisfies [package provide Tcl] 8.6.0]} return..if {($::tcl_platform(platform) eq "unix") && ([info exists ::env(DISPLAY)]...|| ([info exists ::argv] && ("-display" in $::argv)))} {.. package ifneeded Tk 8.6.13 [list load [file join $dir .. .. bin libtk8.6.dll]]..} else {.. package ifneeded Tk 8.6.13 [list load [file join $dir .. .. bin tk86t.dll]]..}..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Tcl script, ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7632
                                                                                                                                                                                                            Entropy (8bit):4.891666209090638
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:Eet0t8bm9Z+Yjo+j/YKOtOUOtk8XKUal320:EetG8biZZs+bIAUoxX0d
                                                                                                                                                                                                            MD5:21A3AC11146EC26784C0E729D8D644D0
                                                                                                                                                                                                            SHA1:C7E0918E8692C42C1D1DD1BBCBFFF22A85979B69
                                                                                                                                                                                                            SHA-256:579701605669AADFFBCDB7E3545C68442495428EE6E93C2D3A3133583BCD3D33
                                                                                                                                                                                                            SHA-512:724ED83B989AD9033BEC4211EE50E4C9E85B51054C518CDF7E02D0ED0416F636B9F38C0B0D29F8F4F7F465B77C7D2E01D0918D2C2C3FEC4C7739EA982302FA2E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# safetk.tcl --..#..# Support procs to use Tk in safe interpreters...#..# Copyright (c) 1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....# see safetk.n for documentation....#..#..# Note: It is now ok to let untrusted code being executed..# between the creation of the interp and the actual loading..# of Tk in that interp because the C side Tk_Init will..# now look up the parent interp and ask its safe::TkInit..# for the actual parameters to use for it's initialization (if allowed),..# not relying on the child state...#....# We use opt (optional arguments parsing)..package require opt 0.4.1;....namespace eval ::safe {.... # counter for safe toplevels.. variable tkSafeId 0..}....#..# tkInterpInit : prepare the child interpreter for tk loading..# most of the real job is done by loadTk..# returns the child name (tkInterpInit
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8693
                                                                                                                                                                                                            Entropy (8bit):4.968450834020619
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:GSusE8YOdpO4aDtao+QYa6t2jooB6ajpaqa5xQGmLGKOC9dLrVx:KsbYQO48t+QYa+NkFjpagGmKKX9dLrVx
                                                                                                                                                                                                            MD5:D45202D3D2D052D4C6BFE8D1322AAB39
                                                                                                                                                                                                            SHA1:8CDF184AC2E9299B2B2A107A64E9D1803AA298DE
                                                                                                                                                                                                            SHA-256:0747A387FDD1B2C7135ECEAE7B392ED52E1D1EBF3FFA90FEBE886DBC0981EB74
                                                                                                                                                                                                            SHA-512:27B005F955BAE00D15C4492E7BD3EBDC5EE3BF9C164C418198B4BD185709C8810AA6CF76CBCC07EEB4C1D20F8C76EF8DF8B219563C18B88C94954C910BFF575D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# scale.tcl --..#..# This file defines the default bindings for Tk scale widgets and provides..# procedures that help in implementing the bindings...#..# Copyright (c) 1994 The Regents of the University of California...# Copyright (c) 1994-1995 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# The code below creates the default class bindings for entries...#-------------------------------------------------------------------------....# Standard Motif bindings:....bind Scale <Enter> {.. if {$tk_strictMotif} {...set tk::Priv(activeBg) [%W cget -activebackground]...%W configure -activebackground [%W cget -background].. }.. tk::ScaleActivate %W %x %y..}..bind Scale <Motion> {.. tk::ScaleActivate %W %x %y..}..bind Scale <Leave> {.. if {$tk_strictMotif} {...%W configure -activebackground
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):13188
                                                                                                                                                                                                            Entropy (8bit):5.063842571848725
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:Gf7RV8ei32PHKT8H2wwucyRlXn+kl1nBKp4nu5FCyK:2mei3qHKT8WPurnXn+I1nBg4nu5MyK
                                                                                                                                                                                                            MD5:5249CD1E97E48E3D6DEC15E70B9D7792
                                                                                                                                                                                                            SHA1:612E021BA25B5E512A0DFD48B6E77FC72894A6B9
                                                                                                                                                                                                            SHA-256:EEC90404F702D3CFBFAEC0F13BF5ED1EBEB736BEE12D7E69770181A25401C61F
                                                                                                                                                                                                            SHA-512:E4E0AB15EB9B3118C30CD2FF8E5AF87C549EAA9B640FFD809A928D96B4ADDEFB9D25EFDD1090FBD0019129CDF355BB2F277BC7194001BA1D2ED4A581110CEAFC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# scrlbar.tcl --..#..# This file defines the default bindings for Tk scrollbar widgets...# It also provides procedures that help in implementing the bindings...#..# Copyright (c) 1994 The Regents of the University of California...# Copyright (c) 1994-1996 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# The code below creates the default class bindings for scrollbars...#-------------------------------------------------------------------------....# Standard Motif bindings:..if {[tk windowingsystem] eq "x11" || [tk windowingsystem] eq "aqua"} {....bind Scrollbar <Enter> {.. if {$tk_strictMotif} {...set tk::Priv(activeBg) [%W cget -activebackground]...%W configure -activebackground [%W cget -background].. }.. %W activate [%W identify %x %y]..}..bind Scrollbar <Motion> {.. %W activate [%
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):16543
                                                                                                                                                                                                            Entropy (8bit):5.034958189335699
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:IMpfyeKu9TzD0E8+9T1wqBaQKpiqQr7E32fnzXfWJU:IMpfyeKu9Tx8WODTp2zPP
                                                                                                                                                                                                            MD5:EAA36F0AA69AE19DDBDD0448FBAD9D4D
                                                                                                                                                                                                            SHA1:EB0ADB4F4D937BAC2F17480ADAF6F948262E754D
                                                                                                                                                                                                            SHA-256:747889C3086C917A34554A9DC495BC0C08A03FD3A5828353ED2A64B97F376835
                                                                                                                                                                                                            SHA-512:C8368F19EC6842ED67073B9FC9C9274107E643324CB23B28C54DF63FB720F63B043281B30DBEA053D08481B0442A87465F715A8AA0711B01CE83FF7B9F8A4F4C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# spinbox.tcl --..#..# This file defines the default bindings for Tk spinbox widgets and provides..# procedures that help in implementing those bindings. The spinbox builds..# off the entry widget, so it can reuse Entry bindings and procedures...#..# Copyright (c) 1992-1994 The Regents of the University of California...# Copyright (c) 1994-1997 Sun Microsystems, Inc...# Copyright (c) 1999-2000 Jeffrey Hobbs..# Copyright (c) 2000 Ajuba Solutions..#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# Elements of tk::Priv that are used in this file:..#..# afterId -..If non-null, it means that auto-scanning is underway..#...and it gives the "after" id for the next auto-scan..#...command to be executed...# mouseMoved -..Non-zero means the mouse has moved a significant..#...amount since the button went down (so, for example,..#.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):20523
                                                                                                                                                                                                            Entropy (8bit):4.786929402401609
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:eeVL0UI9Ms++J7VT/hc+ISyNsATbOan/uW/UFQ1gs1gxtKZufe2SvdJcmq/YbhEB:eeF0UI9Ms++J7VT/hc+ISyCATbOan2W+
                                                                                                                                                                                                            MD5:9378397DD3DCA9DFB181F6F512B15631
                                                                                                                                                                                                            SHA1:4F95DD6B658B6A912725DC7D6226F8414020D6C7
                                                                                                                                                                                                            SHA-256:B04B1A675572E6FCD12C5FE82C4FD0930395548436FF93D848BF340AE202E7E3
                                                                                                                                                                                                            SHA-512:D28CC3C8F3D0B1B2371CBD9EE29AC6881BABD8A07C762FF8F3284449998EE44FA44752CC8AB0DE47A3492776CE1D13BC8EA18CFDBDF710639D2D62D02CB917A9
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# Tcl autoload index file, version 2.0..# This file is generated by the "auto_mkindex" command..# and sourced to set up indexing information for one or..# more commands. Typically each line is a command that..# sets an element in the auto_index array, where the..# element name is the name of a command and the value is..# a script that loads the command.....set auto_index(::tk::dialog::error::Return) [list source [file join $dir bgerror.tcl]]..set auto_index(::tk::dialog::error::Details) [list source [file join $dir bgerror.tcl]]..set auto_index(::tk::dialog::error::SaveToLog) [list source [file join $dir bgerror.tcl]]..set auto_index(::tk::dialog::error::Destroy) [list source [file join $dir bgerror.tcl]]..set auto_index(::tk::dialog::error::bgerror) [list source [file join $dir bgerror.tcl]]..set auto_index(bgerror) [list source [file join $dir bgerror.tcl]]..set auto_index(::tk::ButtonInvoke) [list source [file join $dir button.tcl]]..set auto_index(::tk::ButtonAutoInvoke) [list sou
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):5309
                                                                                                                                                                                                            Entropy (8bit):4.74935501162253
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:wfQXIqAv6iEwYtKVlPBnXWASbvMsDjXKpQQkK2tTsSZQ7Fowqm2K5r:wf+IqI6iU43PJYbvMsDjXKpsK2tISyZV
                                                                                                                                                                                                            MD5:5F042DE8AD8941C7B9EF6D7BE06C86E4
                                                                                                                                                                                                            SHA1:A4DFCEA2ACCAC2E85EAAA186DC765086D1E3AA3C
                                                                                                                                                                                                            SHA-256:A4A8568633F827B54326640E6D1C3FDE4978EDC9E9FA1FB1D7B58F189DF1B1DC
                                                                                                                                                                                                            SHA-512:E92A00028696A1557666CAB1C25AE6B63F25D75A9811BFAC56DFC069ECC769CC751B71CC81FA85C9CDE8F7FB6D7121EB64B58548CEE8AFE3F6C4A5C243507216
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# tearoff.tcl --..#..# This file contains procedures that implement tear-off menus...#..# Copyright (c) 1994 The Regents of the University of California...# Copyright (c) 1994-1997 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....# ::tk::TearoffMenu --..# Given the name of a menu, this procedure creates a torn-off menu..# that is identical to the given menu (including nested submenus)...# The new torn-off menu exists as a toplevel window managed by the..# window manager. The return value is the name of the new menu...# The window is created at the point specified by x and y..#..# Arguments:..# w -...The menu to be torn-off (duplicated)...# x -...x coordinate where window is created..# y -...y coordinate where window is created....proc ::tk::TearOffMenu {w {x 0} {y 0}} {.. # Find a unique name to use for the torn-off menu. Find the first.. # ancestor of w that is a
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):34969
                                                                                                                                                                                                            Entropy (8bit):4.95825801435303
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:Rp4LaQDlOrqquMwIMyv4Et8avJLgmTGXs1bYMeNnnZl8n6KRD:RYK8aymTGs1b0xncn6KR
                                                                                                                                                                                                            MD5:9CA5094ED6FE46620ABF090BF8E2AE63
                                                                                                                                                                                                            SHA1:60DC3C2E3F69CE5B6DB4F2B3A1F3C109D766BC63
                                                                                                                                                                                                            SHA-256:AB88556E349F03BACA2D8DC2121071A4F299DB86F484CAB2D9249FF4C7007564
                                                                                                                                                                                                            SHA-512:0B0C20A754BE744A7FA214BA06AB0744A9BC466D51F96310D97EA1E61119A8ACFEF24E6DC5C4EBDD2C126BF84ACE74FFE622E9641C87E5A240DD13D1F7B5E6AF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# text.tcl --..#..# This file defines the default bindings for Tk text widgets and provides..# procedures that help in implementing the bindings...#..# Copyright (c) 1992-1994 The Regents of the University of California...# Copyright (c) 1994-1997 Sun Microsystems, Inc...# Copyright (c) 1998 by Scriptics Corporation...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....#-------------------------------------------------------------------------..# Elements of ::tk::Priv that are used in this file:..#..# afterId -..If non-null, it means that auto-scanning is underway..#...and it gives the "after" id for the next auto-scan..#...command to be executed...# char -..Character position on the line; kept in order..#...to allow moving up or down past short lines while..#...still remembering the desired position...# mouseMoved -..Non-zero means the mouse has moved a significant..#...amount since the button we
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Tcl script, ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):24102
                                                                                                                                                                                                            Entropy (8bit):5.137459715823081
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:NJyxt+WaB9USY15gSgC3DbTbXLXKr3cIXyDAbK2LMGgtewT+3oFQRyH5bAy59HmD:NJItNe9USZblXysm7GgteoFQRYMESL
                                                                                                                                                                                                            MD5:184D05201893B2042D3FA6140FCF277C
                                                                                                                                                                                                            SHA1:AAD67797864456749ADF0C4A1C0BE52F563C8FB8
                                                                                                                                                                                                            SHA-256:1D5E7518AFC1382E36BF13FC5196C8A7CD93A4E9D24ACF445522564245A489B0
                                                                                                                                                                                                            SHA-512:291BDF793CABC5EC27E8265A8A313FE0F4ACAB4DB6CE507A46488A83EEF72CD43CF5815762B22D1C8D64A9EEDEA927E109F937E6573058E5493B1354DD449CB3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# tk.tcl --..#..# Initialization script normally executed in the interpreter for each Tk-based..# application. Arranges class bindings for widgets...#..# Copyright (c) 1992-1994 The Regents of the University of California...# Copyright (c) 1994-1996 Sun Microsystems, Inc...# Copyright (c) 1998-2000 Ajuba Solutions...#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES.....# Verify that we have Tk binary and script components from the same release..package require -exact Tk 8.6.13.....# Create a ::tk namespace..namespace eval ::tk {.. # Set up the msgcat commands.. namespace eval msgcat {...namespace export mc mcmax.. if {[interp issafe] || [catch {package require msgcat}]} {.. # The msgcat package is not available. Supply our own.. # minimal replacement... proc mc {src args} {.. return [format $src {*}$args].. }.. proc mc
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):39557
                                                                                                                                                                                                            Entropy (8bit):5.186073482848965
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:+oj+AqE9cn9tJNgDt0/vsKulXgo65Eh6pQb:+6+Zv/ggEdio65Ehdb
                                                                                                                                                                                                            MD5:670837EBC804E7B6E2F65F840BC508D6
                                                                                                                                                                                                            SHA1:2DD316487F87DDE5D05F65F564CAE4E1306CE662
                                                                                                                                                                                                            SHA-256:3AAA66AE8E74B94481C3F6642634E78BB5D7892771E7C27B54DFA56DED0B2F3C
                                                                                                                                                                                                            SHA-512:BB8350ADDF1A25C037DFD60A4AFCBF401CACAD2A370B60BD0BA0981D938C46394BD8D40D1E9A66F4E3C46FCC2A41CF688E78C4F1FE918B45E70D3E92D8B3D116
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# tkfbox.tcl --..#..#.Implements the "TK" standard file selection dialog box. This dialog..#.box is used on the Unix platforms whenever the tk_strictMotif flag is..#.not set...#..#.The "TK" standard file selection dialog box is similar to the file..#.selection dialog box on Win95(TM). The user can navigate the..#.directories by clicking on the folder icons or by selecting the..#."Directory" option menu. The user can select files by clicking on the..#.file icons or by entering a filename in the "Filename:" entry...#..# Copyright (c) 1994-1998 Sun Microsystems, Inc...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....namespace eval ::tk::dialog {}..namespace eval ::tk::dialog::file {.. namespace import -force ::tk::msgcat::*.. variable showHiddenBtn 0.. variable showHiddenVar 1.... # Create the images if they did not already exist... if {![info exists ::tk::Priv(updirImage)]} {...s
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3713
                                                                                                                                                                                                            Entropy (8bit):4.915055696129498
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:InrWdo3L7Fe5qusQGdrMNnQbfIxEOxE0kFgG0FgGouox9FrGVuwg3kNcT+z5UlEr:UWdsOBn/1i+pqxwNjKs
                                                                                                                                                                                                            MD5:01F28512E10ACBDDF93AE2BB29E343BC
                                                                                                                                                                                                            SHA1:C9CF23D6315218B464061F011E4A9DC8516C8F1F
                                                                                                                                                                                                            SHA-256:AE0437FB4E0EBD31322E4EACA626C12ABDE602DA483BB39D0C5EE1BC00AB0AF4
                                                                                                                                                                                                            SHA-512:FE3BAE36DDB67F6D7A90B7A91B6EC1A009CF26C0167C46635E5A9CEAEC9083E59DDF74447BF6F60399657EE9604A2314B170F78A921CF948B2985DDF02A89DA6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# Ttk widget set: Alternate theme..#....namespace eval ttk::theme::alt {.... variable colors.. array set colors {...-frame .."#d9d9d9"...-window.."#ffffff"...-darker ."#c3c3c3"...-border.."#414141"...-activebg ."#ececec"...-disabledfg."#a3a3a3"...-selectbg."#4a6984"...-selectfg."#ffffff"...-altindicator."#aaaaaa".. }.... ttk::style theme settings alt {.....ttk::style configure "." \... -background .$colors(-frame) \... -foreground .black \... -troughcolor.$colors(-darker) \... -bordercolor.$colors(-border) \... -selectbackground .$colors(-selectbg) \... -selectforeground .$colors(-selectfg) \... -font ..TkDefaultFont \... ;.....ttk::style map "." -background \... [list disabled $colors(-frame) active $colors(-activebg)] ;...ttk::style map "." -foreground [list disabled $colors(-disabledfg)] ;.. ttk::style map "." -embossed [list disabled 1] ;.....ttk::style configure TButton \... -anchor center -width -11 -padding "1 1" \... -reli
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3838
                                                                                                                                                                                                            Entropy (8bit):4.940737732832436
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:WdbclJFvlyLi+8OWXgQahpvAdNutdHrFBlCFBK2tdHkFBlhKgY1geAWUWeFVvtdp:C8EQPNeWgFeqdXj
                                                                                                                                                                                                            MD5:F07A3A86362E9E253BE91F59714FE134
                                                                                                                                                                                                            SHA1:84DE1AB2EAE62E4B114F0E613BD94955AFA9E6C7
                                                                                                                                                                                                            SHA-256:E199CC9C429B35A09721D0A22543C3729E2B8462E68DFA158C0CEC9C70A0D79D
                                                                                                                                                                                                            SHA-512:324EAF9F857076CA4FECB26D8DF76F8BB1D3F15EAE55D6B6C9689BF1682B306AC7A3592B6A518D23F9FE4DC21EFB6ACF1ECA948F889FA1ADFFA0E12C0BEAB57F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# Aqua theme (OSX native look and feel)..#....namespace eval ttk::theme::aqua {.. ttk::style theme settings aqua {.....ttk::style configure . \... -font TkDefaultFont \... -background systemWindowBackgroundColor \... -foreground systemLabelColor \... -selectbackground systemSelectedTextBackgroundColor \... -selectforeground systemSelectedTextColor \... -selectborderwidth 0 \... -insertwidth 1.....ttk::style map . \... -foreground {....disabled systemDisabledControlTextColor....background systemLabelColor} \... -selectbackground {....background systemSelectedTextBackgroundColor....!focus systemSelectedTextBackgroundColor} \... -selectforeground {....background systemSelectedTextColor....!focus systemSelectedTextColor}.....# Button...ttk::style configure TButton -anchor center -width -6 \... -foreground systemControlTextColor...ttk::style map TButton \... -foreground {....pressed white... {alternate !pressed !background} white}...ttk::styl
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3014
                                                                                                                                                                                                            Entropy (8bit):4.917794267131833
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:A5N+EqJWR1eTC01cG61ELLgrDgk1JgQ6TQGvhV5giT6TUP+3JWMHTeJ:kN+RQfccG61ooDgQ6dNT6TUP+PHO
                                                                                                                                                                                                            MD5:D4BF1AF5DCDD85E3BD11DBF52EB2C146
                                                                                                                                                                                                            SHA1:B1691578041319E671D31473A1DD404855D2038B
                                                                                                                                                                                                            SHA-256:E38A9D1F437981AA6BF0BDD074D57B769A4140C0F7D9AFF51743FE4ECC6DFDDF
                                                                                                                                                                                                            SHA-512:25834B4B231F4FF1A88EEF67E1A102D1D0546EC3B0D46856258A6BE6BBC4B381389C28E2EB60A01FF895DF24D6450CD16CA449C71F82BA53BA438A4867A47DCD
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# Bindings for Buttons, Checkbuttons, and Radiobuttons...#..# Notes: <Button1-Leave>, <Button1-Enter> only control the "pressed"..# state; widgets remain "active" if the pointer is dragged out...# This doesn't seem to be conventional, but it's a nice way..# to provide extra feedback while the grab is active...# (If the button is released off the widget, the grab deactivates and..# we get a <Leave> event then, which turns off the "active" state)..#..# Normally, <ButtonRelease> and <ButtonN-Enter/Leave> events are..# delivered to the widget which received the initial <Button>..# event. However, Tk [grab]s (#1223103) and menu interactions..# (#1222605) can interfere with this. To guard against spurious..# <Button1-Enter> events, the <Button1-Enter> binding only sets..# the pressed state if the button is currently active...#....namespace eval ttk::button {}....bind TButton <Enter> ..{ %W instate !disabled {%W state active} }..bind TButton <Leave>..{ %W state !active }..bind TButton <s
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4809
                                                                                                                                                                                                            Entropy (8bit):4.905115353394083
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:KrS4se/XhW03cC7TxPp/uo1ZUb0WZvSoetCgV+tMWG3xT3xgNB4x76FAuoxVYuIJ:oS4sSjWwFAGkhiP3xT3xL6B2bbe
                                                                                                                                                                                                            MD5:2B20E7B2E6BDDBEB14F5F63BF38DBF24
                                                                                                                                                                                                            SHA1:43DB48094C4BD7DE3B76AFBC051D887FEFE9887E
                                                                                                                                                                                                            SHA-256:CFFC59931FDD1683AD23895E92522CF49B099128753FCDFF34374024E42CF995
                                                                                                                                                                                                            SHA-512:1EB5EA78D26D18EAD6563AFBF1798F71723001DCC945E7DB3E4368564D0563029BE3565876AD8CB97331CFE34B2A0A313FA1BF252B87049160FE5DCD65434775
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# "Clam" theme...#..# Inspired by the XFCE family of Gnome themes...#....namespace eval ttk::theme::clam {.. variable colors.. array set colors {...-disabledfg.."#999999"...-frame .."#dcdad5"...-window .."#ffffff"...-dark..."#cfcdc8"...-darker .."#bab5ab"...-darkest.."#9e9a91"...-lighter.."#eeebe7"...-lightest .."#ffffff"...-selectbg.."#4a6984"...-selectfg.."#ffffff"...-altindicator.."#5895bc"...-disabledaltindicator."#a0a0a0".. }.... ttk::style theme settings clam {.....ttk::style configure "." \... -background $colors(-frame) \... -foreground black \... -bordercolor $colors(-darkest) \... -darkcolor $colors(-dark) \... -lightcolor $colors(-lighter) \... -troughcolor $colors(-darker) \... -selectbackground $colors(-selectbg) \... -selectforeground $colors(-selectfg) \... -selectborderwidth 0 \... -font TkDefaultFont \... ;.....ttk::style map "." \... -background [list disabled $colors(-frame) \..... active $colors(-lighter)] \..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3864
                                                                                                                                                                                                            Entropy (8bit):4.935603001745302
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:zcJZjdWs+WVB4ULsMF7tnvnuSuqo5DKxiFgG0FgGHx9FrGTtu/3Kt+iW2PbuAk38:zcJZEstB4UoituSm+VtYErY
                                                                                                                                                                                                            MD5:0205663142775F4EF2EB104661D30979
                                                                                                                                                                                                            SHA1:452A0D613288A1CC8A1181C3CC1167E02AA69A73
                                                                                                                                                                                                            SHA-256:424BBA4FB6836FEEBE34F6C176ED666DCE51D2FBA9A8D7AA756ABCBBAD3FC1E3
                                                                                                                                                                                                            SHA-512:FB4D212A73A6F5A8D2774F43D310328B029B52B35BEE133584D8326363B385AB7AA4AE25E98126324CC716962888321E0006E5F6EF8563919A1D719019B2D117
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# "classic" Tk theme...#..# Implements Tk's traditional Motif-like look and feel...#....namespace eval ttk::theme::classic {.... variable colors; array set colors {...-frame.."#d9d9d9"...-window.."#ffffff"...-activebg."#ececec"...-troughbg."#c3c3c3"...-selectbg."#c3c3c3"...-selectfg."#000000"...-disabledfg."#a3a3a3"...-indicator."#b03060"...-altindicator."#b05e5e".. }.... ttk::style theme settings classic {...ttk::style configure "." \... -font..TkDefaultFont \... -background..$colors(-frame) \... -foreground..black \... -selectbackground.$colors(-selectbg) \... -selectforeground.$colors(-selectfg) \... -troughcolor.$colors(-troughbg) \... -indicatorcolor.$colors(-frame) \... -highlightcolor.$colors(-frame) \... -highlightthickness.1 \... -selectborderwidth.1 \... -insertwidth.2 \... ;.....# To match pre-Xft X11 appearance, use:...#.ttk::style configure . -font {Helvetica 12 bold}.....ttk::style map "." -background \... [list disabled
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):12718
                                                                                                                                                                                                            Entropy (8bit):5.063548300335668
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:otLzBJ9SfinaXUBLPYXlk7fKiLH+AzIoJdJwGknmyLsxoVEQGITse8g5sarkT32e:wB5aXmLPYXmrKxLL7A
                                                                                                                                                                                                            MD5:F7065D345A4BFB3127C3689BF1947C30
                                                                                                                                                                                                            SHA1:9631C05365B0F5A36E4CA5CBA83628CCD7FCBDE1
                                                                                                                                                                                                            SHA-256:68EED4AF6D2EC5B3EA24B1122A704B040366CBE2F458103137479352FFA1475A
                                                                                                                                                                                                            SHA-512:74B99B9E326680150DD5EC7263192691BCD8A71B2A4EE7F3177DEDDD43E924A7925085C6D372731A70570F96B3924450255B2F54CA3B9C44D1160CA37E715B00
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# Combobox bindings...#..# <<NOTE-WM-TRANSIENT>>:..#..#.Need to set [wm transient] just before mapping the popdown..#.instead of when it's created, in case a containing frame..#.has been reparented [#1818441]...#..#.On Windows: setting [wm transient] prevents the parent..#.toplevel from becoming inactive when the popdown is posted..#.(Tk 8.4.8+)..#..#.On X11: WM_TRANSIENT_FOR on override-redirect windows..#.may be used by compositing managers and by EWMH-aware..#.window managers (even though the older ICCCM spec says..#.it's meaningless)...#..#.On OSX: [wm transient] does utterly the wrong thing...#.Instead, we use [MacWindowStyle "help" "noActivates hideOnSuspend"]...#.The "noActivates" attribute prevents the parent toplevel..#.from deactivating when the popdown is posted, and is also..#.necessary for "help" windows to receive mouse events...#."hideOnSuspend" makes the popdown disappear (resp. reappear)..#.when the parent toplevel is deactivated (resp. reactivated)...#.(see [#18147
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4674
                                                                                                                                                                                                            Entropy (8bit):4.836935825704301
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:DRYEqfLDxGmxGUetobPT6t6brv0q3O4Uxz0:DWEqTDbxdKobPqe5PUxw
                                                                                                                                                                                                            MD5:1A799FE3754307A5AADE98C367E2F5D7
                                                                                                                                                                                                            SHA1:C64BE4B77F0D298610F4EE20FCEBBAEE3C8B5F22
                                                                                                                                                                                                            SHA-256:5B33F32B0139663347D6CF70A5A838F8E4554E0E881E97C8478B77733162EA73
                                                                                                                                                                                                            SHA-512:89F367F9A59730BCDFC5ABDE0E35A10B72A1F19C68A768BA4524C938EF5C5CAF094C1BFA8FC74173F65201F6617544223C2143252A9F691EE9AAA7543315179F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# Map symbolic cursor names to platform-appropriate cursors...#..# The following cursors are defined:..#..#.standard.-- default cursor for most controls..#.""..-- inherit cursor from parent window..#.none..-- no cursor..#..#.text..-- editable widgets (entry, text)..#.link..-- hyperlinks within text..#.crosshair.-- graphic selection, fine control..#.busy..-- operation in progress..#.forbidden.-- action not allowed..#..#.hresize..-- horizontal resizing..#.vresize..-- vertical resizing..#..# Also resize cursors for each of the compass points,..# {nw,n,ne,w,e,sw,s,se}resize...#..# Platform notes:..#..# Windows doesn't distinguish resizing at the 8 compass points,..# only horizontal, vertical, and the two diagonals...#..# OSX doesn't have resize cursors for nw, ne, sw, or se corners...# We use the Tk-defined X11 fallbacks for these...#..# X11 doesn't have a "forbidden" cursor (usually a slashed circle);..# "pirate" seems to be the conventional cursor for this purpose...#..# Windows has a
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4553
                                                                                                                                                                                                            Entropy (8bit):4.933885986949396
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:lNl3u3lCFUeuMGN3xbVJU+N3xbVJh3IwxkxlBqatUrtY:zl3ZUe9GN3NVC+N3NVjqntUZY
                                                                                                                                                                                                            MD5:FC79F42761D63172163C08F0F5C94436
                                                                                                                                                                                                            SHA1:AABAB4061597D0D6DC371F46D14AAA1A859096DF
                                                                                                                                                                                                            SHA-256:49AE8FAF169165BDDAF01D50B52943EBAB3656E9468292B7890BE143D0FCBC91
                                                                                                                                                                                                            SHA-512:F619834A95C9DEB93F8184BCC437D701A961C77E24A831ADBD5C145556D26986BFDA2A6ACB9E8784F8B2380E122D12AC893EB1B6ACF03098922889497E1FF9EA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# Settings for default theme...#....namespace eval ttk::theme::default {.. variable colors.. array set colors {...-frame..."#d9d9d9"...-foreground.."#000000"...-window..."#ffffff"...-text .."#000000"...-activebg.."#ececec"...-selectbg.."#4a6984"...-selectfg.."#ffffff"...-darker .."#c3c3c3"...-disabledfg.."#a3a3a3"...-indicator.."#4a6984"...-disabledindicator."#a3a3a3"...-altindicator.."#9fbdd8"...-disabledaltindicator."#c0c0c0".. }.... ttk::style theme settings default {.....ttk::style configure "." \... -borderwidth .1 \... -background .$colors(-frame) \... -foreground .$colors(-foreground) \... -troughcolor .$colors(-darker) \... -font ..TkDefaultFont \... -selectborderwidth.1 \... -selectbackground.$colors(-selectbg) \... -selectforeground.$colors(-selectfg) \... -insertwidth .1 \... -indicatordiameter.10 \... ;.....ttk::style map "." -background \... [list disabled $colors(-frame) active $colors(-activebg)]...ttk::style map "."
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):17658
                                                                                                                                                                                                            Entropy (8bit):5.026830367336785
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:sca9Jzcyzf6yzwO+v+iPT3vKof8q3YIuR13a:sT9Jzcy76wiV3YNa
                                                                                                                                                                                                            MD5:7FFD7A32C7F8E234763E99E3357DB624
                                                                                                                                                                                                            SHA1:67C67557F3A6DC8B240E85D46F6B733FEE45A013
                                                                                                                                                                                                            SHA-256:266553EB9EED333DD836BA96204AE008F10686F4F12C404187F1E01CAB65D246
                                                                                                                                                                                                            SHA-512:D18B73E44F37ED92B9FD7C1F6510285D1280EB5BC665B46996E538924E9D1CAD63337279BF92587132C3AEA497325A17CCE671EA59537B350F6D921C25346F39
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# DERIVED FROM: tk/library/entry.tcl r1.22..#..# Copyright (c) 1992-1994 The Regents of the University of California...# Copyright (c) 1994-1997 Sun Microsystems, Inc...# Copyright (c) 2004, Joe English..#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES...#....namespace eval ttk {.. namespace eval entry {...variable State.....set State(x) 0...set State(selectMode) none...set State(anchor) 0...set State(scanX) 0...set State(scanIndex) 0...set State(scanMoved) 0.....# Button-2 scan speed is (scanNum/scanDen) characters...# per pixel of mouse movement....# The standard Tk entry widget uses the equivalent of...# scanNum = 10, scanDen = average character width....# I don't know why that was chosen....#...set State(scanNum) 1...set State(scanDen) 1...set State(deadband) 3.;# #pixels for mouse-moved deadband... }..}....### Option database settings...#..option add *TEntry.cursor [ttk::cursor text] widg
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):5732
                                                                                                                                                                                                            Entropy (8bit):5.001928619185109
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:NzEh94ntnVU8Z/1LkAKgW22SeLMQR8hzcksejmOF4ytZm:Sh9ahV3ZWAKgWDfktm
                                                                                                                                                                                                            MD5:80331FCBE4C049FF1A0D0B879CB208DE
                                                                                                                                                                                                            SHA1:4EB3EFDFE3731BD1AE9FD52CE32B1359241F13CF
                                                                                                                                                                                                            SHA-256:B94C319E5A557A5665B1676D602B6495C0887C5BACF7FA5B776200112978BB7B
                                                                                                                                                                                                            SHA-512:A4BD2D91801C121A880225F1F3D0C4E30BF127190CF375F6F7A49EB4239A35C49C44F453D6D3610DF0D6A7B3CB15F4E79BD9C129025CC496CEB856FCC4B6DE87
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# Font specifications...#..# This file, [source]d at initialization time, sets up the following..# symbolic fonts based on the current platform:..#..# TkDefaultFont.-- default for GUI items not otherwise specified..# TkTextFont.-- font for user text (entry, listbox, others)..# TkFixedFont.-- standard fixed width font..# TkHeadingFont.-- headings (column headings, etc)..# TkCaptionFont -- dialog captions (primary text in alert dialogs, etc.)..# TkTooltipFont.-- font to use for tooltip windows..# TkIconFont.-- font to use for icon captions..# TkMenuFont.-- used to use for menu items..#..# In Tk 8.5, some of these fonts may be provided by the TIP#145 implementation..# (On Windows and Mac OS X as of Oct 2007)...#..# +++ Platform notes:..#..# Windows:..#.The default system font changed from "MS Sans Serif" to "Tahoma"..# .in Windows XP/Windows 2000...#..#.MS documentation says to use "Tahoma 8" in Windows 2000/XP,..#.although many MS programs still use "MS Sans Serif 8"..#..#.Should use
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):6443
                                                                                                                                                                                                            Entropy (8bit):4.9213750923402735
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:toMcJQkmcE6fNuLyiCzSLSRwgppdT3kXdpK3dpKkSH2tOTjvAG:tRc6kFbcH2pyXz+zO2y
                                                                                                                                                                                                            MD5:F11A76FBABF35E446A1200A5A7A6730A
                                                                                                                                                                                                            SHA1:4CBAB3507C1EF275691C98620D2B5CEEB9043B3E
                                                                                                                                                                                                            SHA-256:54663FBF524CAD9D74AB1EC44B7FDDE0B87F06E5347191962C97F51F714E29BB
                                                                                                                                                                                                            SHA-512:95471D1519AE663EC7EB4639D847019E0C9F70DEA2B0680D81FB8BBE7CD1FF643A3DF5E06CA2CC54385BE094BDCC64AB0F1AA1652F91D16C4EF7B68CB670371E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# Bindings for Menubuttons...#..# Menubuttons have three interaction modes:..#..# Pulldown: Press menubutton, drag over menu, release to activate menu entry..# Popdown: Click menubutton to post menu..# Keyboard: <space> or accelerator key to post menu..#..# (In addition, when menu system is active, "dropdown" -- menu posts..# on mouse-over. Ttk menubuttons don't implement this)...#..# For keyboard and popdown mode, we hand off to tk_popup and let..# the built-in Tk bindings handle the rest of the interaction...#..# ON X11:..#..# Standard Tk menubuttons use a global grab on the menubutton...# This won't work for Ttk menubuttons in pulldown mode,..# since we need to process the final <ButtonRelease> event,..# and this might be delivered to the menu. So instead we..# rely on the passive grab that occurs on <Button> events,..# and transition to popdown mode when the mouse is released..# or dragged outside the menubutton...#..# ON WINDOWS:..#..# I'm not sure what the hell is going on h
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):5825
                                                                                                                                                                                                            Entropy (8bit):4.96378772387536
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:RErUhyi5JeUQBWdz6eP8ClR6/u6AsBmPNNiREUkheLY1EVL23sN2JJjQdD:6uyiyDQBP8q6/u6AUREUsNEVq3y2jkdD
                                                                                                                                                                                                            MD5:F811F3E46A4EFA73292F40D1CDDD265D
                                                                                                                                                                                                            SHA1:7FC70A1984555672653A0840499954B854F27920
                                                                                                                                                                                                            SHA-256:22264D8D138E2C0E9A950305B4F08557C5A73F054F8215C0D8CE03854042BE76
                                                                                                                                                                                                            SHA-512:4424B7C687EB9B1804ED3B1C685F19D4D349753B374D9046240F937785C9713E8A760ADA46CB628C15F9C7983CE4A7987691C968330478C9C1A9B74E953E40AC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# Bindings for TNotebook widget..#....namespace eval ttk::notebook {.. variable TLNotebooks ;# See enableTraversal..}....bind TNotebook <Button-1>..{ ttk::notebook::Press %W %x %y }..bind TNotebook <Right>...{ ttk::notebook::CycleTab %W 1; break }..bind TNotebook <Left>...{ ttk::notebook::CycleTab %W -1; break }..bind TNotebook <Control-Tab>..{ ttk::notebook::CycleTab %W 1; break }..bind TNotebook <Control-Shift-Tab>.{ ttk::notebook::CycleTab %W -1; break }..catch {..bind TNotebook <Control-ISO_Left_Tab>.{ ttk::notebook::CycleTab %W -1; break }..}..bind TNotebook <Destroy>..{ ttk::notebook::Cleanup %W }....# ActivateTab $nb $tab --..#.Select the specified tab and set focus...#..# Desired behavior:..#.+ take focus when reselecting the currently-selected tab;..#.+ keep focus if the notebook already has it;..#.+ otherwise set focus to the first traversable widget..#. in the newly-selected tab;..#.+ do not leave the focus in a deselected tab...#..proc ttk::notebook::ActivateTab {
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2274
                                                                                                                                                                                                            Entropy (8bit):4.951790637542993
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:zVAqE3ZF8b4rXzsqAOAXsmCLFeNqkFeNXez:zLeU4bzSs1M
                                                                                                                                                                                                            MD5:848A62BCF6ED3C16A8CFD26C43E1BC4E
                                                                                                                                                                                                            SHA1:6F5E3EDF62716B511CF575BE2C6C997AFA2FA1E7
                                                                                                                                                                                                            SHA-256:20EE6AD9D701709724292A926AF93C93784B254B48A656ECC140EF3A0FE10A11
                                                                                                                                                                                                            SHA-512:AE78028EAF96E5B77DEFF0CD655360DB3A8058AC98B6753D9B77D629EDFFC582999A22A7075B9F5BA83EE65DA093E2CCB0EEAA4049898910D7AF517FDE60B28E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# Bindings for ttk::panedwindow widget...#....namespace eval ttk::panedwindow {.. variable State.. array set State {...pressed 0.. .pressX.-...pressY.-...sash .-...sashPos -.. }..}....## Bindings:..#..bind TPanedwindow <Button-1> ..{ ttk::panedwindow::Press %W %x %y }..bind TPanedwindow <B1-Motion>..{ ttk::panedwindow::Drag %W %x %y }..bind TPanedwindow <ButtonRelease-1> .{ ttk::panedwindow::Release %W %x %y }....bind TPanedwindow <Motion> ..{ ttk::panedwindow::SetCursor %W %x %y }..bind TPanedwindow <Enter> ..{ ttk::panedwindow::SetCursor %W %x %y }..bind TPanedwindow <Leave> ..{ ttk::panedwindow::ResetCursor %W }..# See <<NOTE-PW-LEAVE-NOTIFYINFERIOR>>..bind TPanedwindow <<EnteredChild>>.{ ttk::panedwindow::ResetCursor %W }....## Sash movement:..#..proc ttk::panedwindow::Press {w x y} {.. variable State.... set sash [$w identify $x $y].. if {$sash eq ""} {.. .set State(pressed) 0...return.. }.. set State(pressed) .1.. set State(pressX) .$x.. set
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1138
                                                                                                                                                                                                            Entropy (8bit):4.763501917862434
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:nJ8v3O0NSiio0pNFVkIks0ImxlnINgDImSgGINSyWghT:JFqS/o03fkxs0Rn+gD4v+S2F
                                                                                                                                                                                                            MD5:DBF3BF0E8F04E9435E9561F740DFC700
                                                                                                                                                                                                            SHA1:C7619A05A834EFB901C57DCFEC2C9E625F42428F
                                                                                                                                                                                                            SHA-256:697CC0A75AE31FE9C2D85FB25DCA0AFA5D0DF9C523A2DFAD2E4A36893BE75FBA
                                                                                                                                                                                                            SHA-512:D3B323DFB3EAC4A78DA2381405925C131A99C6806AF6FD8041102162A44E48BF166982A4AE4AA142A14601736716F1A628D9587E292FA8E4842BE984374CC192
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# Ttk widget set: progress bar utilities...#....namespace eval ttk::progressbar {.. variable Timers.;# Map: widget name -> after ID..}....# Autoincrement --..#.Periodic callback procedure for autoincrement mode..#..proc ttk::progressbar::Autoincrement {pb steptime stepsize} {.. variable Timers.... if {![winfo exists $pb]} {.. .# widget has been destroyed -- cancel timer...unset -nocomplain Timers($pb)...return.. }.... set Timers($pb) [after $steptime \.. .[list ttk::progressbar::Autoincrement $pb $steptime $stepsize] ].... $pb step $stepsize..}....# ttk::progressbar::start --..#.Start autoincrement mode. Invoked by [$pb start] widget code...#..proc ttk::progressbar::start {pb {steptime 50} {stepsize 1}} {.. variable Timers.. if {![info exists Timers($pb)]} {...Autoincrement $pb $steptime $stepsize.. }..}....# ttk::progressbar::stop --..#.Cancel autoincrement mode. Invoked by [$pb stop] widget code...#..proc ttk::progressbar::stop {pb} {.. variabl
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2787
                                                                                                                                                                                                            Entropy (8bit):4.795451191784129
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:IKADAzizZIcAlRqucObmn4AzyVN2AJyhAzukPNP:IHIBRqupmLSZkklP
                                                                                                                                                                                                            MD5:F1C33CC2D47115BBECD2E7C2FCB631A7
                                                                                                                                                                                                            SHA1:0123A961242ED8049B37C77C726DB8DBD94C1023
                                                                                                                                                                                                            SHA-256:B909ADD0B87FA8EE08FD731041907212A8A0939D37D2FF9B2F600CD67DABD4BB
                                                                                                                                                                                                            SHA-512:96587A8C3555DA1D810010C10C516CE5CCAB071557A3C8D9BD65C647C7D4AD0E35CBED0788F1D72BAFAC8C84C7E2703FC747F70D9C95F720745A1FC4A701C544
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# scale.tcl - Copyright (C) 2004 Pat Thoyts <patthoyts@users.sourceforge.net>..#..# Bindings for the TScale widget....namespace eval ttk::scale {.. variable State.. array set State {...dragging 0.. }..}....bind TScale <Button-1> { ttk::scale::Press %W %x %y }..bind TScale <B1-Motion> { ttk::scale::Drag %W %x %y }..bind TScale <ButtonRelease-1> { ttk::scale::Release %W %x %y }....bind TScale <Button-2> { ttk::scale::Jump %W %x %y }..bind TScale <B2-Motion> { ttk::scale::Drag %W %x %y }..bind TScale <ButtonRelease-2> { ttk::scale::Release %W %x %y }....bind TScale <Button-3> { ttk::scale::Jump %W %x %y }..bind TScale <B3-Motion> { ttk::scale::Drag %W %x %y }..bind TScale <ButtonRelease-3> { ttk::scale::Release %W %x %y }....## Keyboard navigation bindings:..#..bind TScale <<LineStart>> { %W set [%W cget -from] }..bind TScale <<LineEnd>> { %W set [%W cget -to] }....bind TScale <<PrevChar>> { ttk::scale::Increment %W -1 }..bin
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3285
                                                                                                                                                                                                            Entropy (8bit):4.979174619784594
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:tyASEji8RYQ8FGD7BDos9Q1TBfvq/HKTh9lkHv8T/mAezeLEAAFULxZh4x:eIi8qFu2d11XlhfkPcczeLS4Zm
                                                                                                                                                                                                            MD5:3FB31A225CEC64B720B8E579582F2749
                                                                                                                                                                                                            SHA1:9C0151D9E2543C217CF8699FF5D4299A72E8F13C
                                                                                                                                                                                                            SHA-256:6EAA336B13815A7FC18BCD6B9ADF722E794DA2888D053C229044784C8C8E9DE8
                                                                                                                                                                                                            SHA-512:E6865655585E3D2D6839B56811F3FD86B454E8CD44E258BB1AC576AD245FF8A4D49FBB7F43458BA8A6C9DAAC8DFA923A176F0DD8A9976A11BEA09E6E2D17BF45
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# Bindings for TScrollbar widget..#....namespace eval ttk::scrollbar {.. variable State.. # State(xPress).--.. # State(yPress).-- initial position of mouse at start of drag... # State(first).-- value of -first at start of drag...}....bind TScrollbar <Button-1> ..{ ttk::scrollbar::Press %W %x %y }..bind TScrollbar <B1-Motion>..{ ttk::scrollbar::Drag %W %x %y }..bind TScrollbar <ButtonRelease-1>.{ ttk::scrollbar::Release %W %x %y }....bind TScrollbar <Button-2> ..{ ttk::scrollbar::Jump %W %x %y }..bind TScrollbar <B2-Motion>..{ ttk::scrollbar::Drag %W %x %y }..bind TScrollbar <ButtonRelease-2>.{ ttk::scrollbar::Release %W %x %y }....# Redirect scrollwheel bindings to the scrollbar widget..#..# The shift-bindings scroll left/right (not up/down)..# if a widget has both possibilities..set eventList [list <MouseWheel> <Shift-MouseWheel>]..switch [tk windowingsystem] {.. aqua {.. lappend eventList <Option-MouseWheel> <Shift-Option-MouseWheel>.. }.. x11 {..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2503
                                                                                                                                                                                                            Entropy (8bit):4.830288003879418
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:naLvMnAqeYQWYh7FvBrrbnMCfY/aVAbAigWAuFM0PfWAX20:nWQapprPnJY/8A8iRFdPtj
                                                                                                                                                                                                            MD5:DD6A1737B14D3F7B2A0B4F8BE99C30AF
                                                                                                                                                                                                            SHA1:E6B06895317E73CD3DC78234DD74C74F3DB8C105
                                                                                                                                                                                                            SHA-256:E92D77B5CDCA2206376DB2129E87E3D744B3D5E31FDE6C0BBD44A494A6845CE1
                                                                                                                                                                                                            SHA-512:B74AE92EDD53652F8A3DB0D84C18F9CE9069805BCAB0D3C2DBB537D7C241AA2681DA69B699D88A10029798D7B5BC015682F64699BA475AE6A379EEF23B48DAAF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# Sizegrip widget bindings...#..# Dragging a sizegrip widget resizes the containing toplevel...#..# NOTE: the sizegrip widget must be in the lower right hand corner...#....switch -- [tk windowingsystem] {.. x11 -.. win32 {...option add *TSizegrip.cursor [ttk::cursor seresize] widgetDefault.. }.. aqua {.. .# Aqua sizegrips use default Arrow cursor... }..}....namespace eval ttk::sizegrip {.. variable State.. array set State {...pressed .0...pressX ..0...pressY ..0...width ..0...height ..0...widthInc.1...heightInc.1.. resizeX 1.. resizeY 1...toplevel .{}.. }..}....bind TSizegrip <Button-1> ..{ ttk::sizegrip::Press.%W %X %Y }..bind TSizegrip <B1-Motion> ..{ ttk::sizegrip::Drag .%W %X %Y }..bind TSizegrip <ButtonRelease-1> .{ ttk::sizegrip::Release %W %X %Y }....proc ttk::sizegrip::Press {W X Y} {.. variable State.... if {[$W instate disabled]} { return }.... set top [winfo toplevel $W].... # If the toplevel is not resi
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):5003
                                                                                                                                                                                                            Entropy (8bit):5.055050310142795
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:1qg/+yrjqA/K5ytxm1J1Ve6J1yQLUAzz/S76hrwxGGe2F:N/+yr2Gk1J1Ve6fxUAzDS76hrwxs2F
                                                                                                                                                                                                            MD5:9C2833FAA9248F09BC2E6AB1BA326D59
                                                                                                                                                                                                            SHA1:F13CF048FD706BBB1581DC80E33D1AAD910D93E8
                                                                                                                                                                                                            SHA-256:DF286BB59F471AA1E19DF39AF0EF7AA84DF9F04DC4A439A747DD8BA43C300150
                                                                                                                                                                                                            SHA-512:5FF3BE1E3D651C145950C3FC5B8C2E842211C937D1042173964383D4D59ECF5DD0EC39FF7771D029716F2D895F0B1A72591EF3BF7947FE64D4D6DB5F0B8ABFFB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# ttk::spinbox bindings..#....namespace eval ttk::spinbox { }....### Spinbox bindings...#..# Duplicate the Entry bindings, override if needed:..#....ttk::copyBindings TEntry TSpinbox....bind TSpinbox <Motion>...{ ttk::spinbox::Motion %W %x %y }..bind TSpinbox <Button-1> ..{ ttk::spinbox::Press %W %x %y }..bind TSpinbox <ButtonRelease-1> .{ ttk::spinbox::Release %W }..bind TSpinbox <Double-Button-1> .{ ttk::spinbox::DoubleClick %W %x %y }..bind TSpinbox <Triple-Button-1> .{} ;# disable TEntry triple-click....bind TSpinbox <Up>...{ event generate %W <<Increment>> }..bind TSpinbox <Down> ...{ event generate %W <<Decrement>> }....bind TSpinbox <<Increment>>..{ ttk::spinbox::Spin %W +1 }..bind TSpinbox <<Decrement>> ..{ ttk::spinbox::Spin %W -1 }....ttk::bindMouseWheel TSpinbox ..[list ttk::spinbox::MouseWheel %W]....## Motion --..#.Sets cursor...#..proc ttk::spinbox::Motion {w x y} {.. variable State.. ttk::saveCursor $w State(userConfCursor) [ttk::cursor text].. if { [$w ide
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):10180
                                                                                                                                                                                                            Entropy (8bit):4.886259798213254
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:FoTvMxHZZ1u2xj7+ZBHxjiXJv9IfwW+vr3UxjXEJDTF/MyLF3JcMzlsra2tYGa5P:mImAkRKYXMH59o4UbS30LWb
                                                                                                                                                                                                            MD5:F705B3A292D02061DA0ABB4A8DD24077
                                                                                                                                                                                                            SHA1:FD75C2250F6F66435444F7DEEF383C6397ED2368
                                                                                                                                                                                                            SHA-256:C88B60FFB0F72E095F6FC9786930ADD7F9ED049EABC713F889F9A7DA516E188C
                                                                                                                                                                                                            SHA-512:09817638DD3D3D5C57FA630C7EDF2F19C3956C9BD264DBF07627FA14A03AECD22D5A5319806E49EF1030204FADEF17C57CE8EAE4378A319AD2093321D9151C8F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# ttk::treeview widget bindings and utilities...#....namespace eval ttk::treeview {.. variable State.... # Enter/Leave/Motion.. #.. set State(activeWidget) .{}.. set State(activeHeading) .{}.... # Press/drag/release:.. #.. set State(pressMode) .none.. set State(pressX)..0.... # For pressMode == "resize".. set State(resizeColumn).#0.... # For pressmode == "heading".. set State(heading) .{}..}....### Widget bindings...#....bind Treeview.<Motion> ..{ ttk::treeview::Motion %W %x %y }..bind Treeview.<B1-Leave>..{ #nothing }..bind Treeview.<Leave>...{ ttk::treeview::ActivateHeading {} {}}..bind Treeview.<Button-1> ..{ ttk::treeview::Press %W %x %y }..bind Treeview.<Double-Button-1> .{ ttk::treeview::DoubleClick %W %x %y }..bind Treeview.<ButtonRelease-1> .{ ttk::treeview::Release %W %x %y }..bind Treeview.<B1-Motion> ..{ ttk::treeview::Drag %W %x %y }..bind Treeview .<Up> ..{ ttk::treeview::Keynav %W up }..bind Treeview .<Down> ..{ ttk::treeview
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4993
                                                                                                                                                                                                            Entropy (8bit):4.954034141173847
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:lfxukTy5jPTq8LIgF2diyNTNR6nkrn4ijSSvNigyJ5612HtZG835MSvWOTRsHWU:BM+y5jrq8G/2nkEijSSvNigyJ5612Htw
                                                                                                                                                                                                            MD5:AF45B2C8B43596D1BDECA5233126BD14
                                                                                                                                                                                                            SHA1:A99E75D299C4579E10FCDD59389B98C662281A26
                                                                                                                                                                                                            SHA-256:2C48343B1A47F472D1A6B9EE8D670CE7FB428DB0DB7244DC323FF4C7A8B4F64B
                                                                                                                                                                                                            SHA-512:C8A8D01C61774321778AB149F6CA8DDA68DB69133CB5BA7C91938E4FD564160ECDCEC473222AFFB241304A9ACC73A36B134B3A602FD3587C711F2ADBB64AFA80
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# Ttk widget set initialization script...#....### Source library scripts...#....namespace eval ::ttk {.. variable library.. if {![info exists library]} {...set library [file dirname [info script]].. }..}....source -encoding utf-8 [file join $::ttk::library fonts.tcl]..source -encoding utf-8 [file join $::ttk::library cursors.tcl]..source -encoding utf-8 [file join $::ttk::library utils.tcl]....## ttk::deprecated $old $new --..#.Define $old command as a deprecated alias for $new command..#.$old and $new must be fully namespace-qualified...#..proc ttk::deprecated {old new} {.. interp alias {} $old {} ttk::do'deprecate $old $new..}..## do'deprecate --..#.Implementation procedure for deprecated commands --..#.issue a warning (once), then re-alias old to new...#..proc ttk::do'deprecate {old new args} {.. deprecated'warning $old $new.. interp alias {} $old {} $new.. uplevel 1 [linsert $args 0 $new]..}....## deprecated'warning --..#.Gripe about use of deprecated comman
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8624
                                                                                                                                                                                                            Entropy (8bit):5.001791071900077
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:e0ebpSp+IZwnmTmpx8xzaHfw8K7LlJWQl8p7M+R5:rw0+WmpWxa/w9nlJHu
                                                                                                                                                                                                            MD5:51086BC3315A4AE4A8591A654CFC3CEA
                                                                                                                                                                                                            SHA1:2AC08309C63575B7A01FA62D3C262643CD8C823A
                                                                                                                                                                                                            SHA-256:4AA041C050758B3331DC395381F7FBCE81E387908FC7A3C6107C4E7140F56F2E
                                                                                                                                                                                                            SHA-512:6D69F7EAC9D5AF3B3EA85AE3E74BDFA6278789502D5E35EFE94349BFC543503BE7540D783D2632E349DD53F21074C702AC1FC487EE70C74234A08397F7238723
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# Utilities for widget implementations...#....### Focus management...#..# See also: #1516479..#....## ttk::takefocus --..#.This is the default value of the "-takefocus" option..#.for ttk::* widgets that participate in keyboard navigation...#..# NOTES:..#.tk::FocusOK (called by tk_focusNext) tests [winfo viewable]..#.if -takefocus is 1, empty, or missing; but not if it's a..#.script prefix, so we have to check that here as well...#..#..proc ttk::takefocus {w} {.. expr {[$w instate !disabled] && [winfo viewable $w]}..}....## ttk::GuessTakeFocus --..#.This routine is called as a fallback for widgets..#.with a missing or empty -takefocus option...#..#.It implements the same heuristics as tk::FocusOK...#..proc ttk::GuessTakeFocus {w} {.. # Don't traverse to widgets with '-state disabled':.. #.. if {![catch {$w cget -state} state] && $state eq "disabled"} {...return 0.. }.... # Allow traversal to widgets with explicit key or focus bindings:.. #.. if {[regexp {Key|F
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):9710
                                                                                                                                                                                                            Entropy (8bit):4.6639701588183895
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:BktY1F+qXd95WSZaHFHRE3GRKFh2oaoT/ezKpqvYMHab:V1F+cd95WSZuhRE34KbPmKmY2ab
                                                                                                                                                                                                            MD5:0AA7F8B43C3E07F3A4DA07FC6DF9A1B0
                                                                                                                                                                                                            SHA1:153AFB735B10BBA16CFBE161777232F983845D90
                                                                                                                                                                                                            SHA-256:EC5F203C69DF390E9B99944CF3526D6E77DC6F68E9B1A029F326A41AFED1EF81
                                                                                                                                                                                                            SHA-512:5406553211CD6714C98EF7765ABD46424CCB013343EFF693FDD3AE6E0AAE9B5983446E0E1CC706D6B2C285084BF83D397306D3D52028CBBCFB8F369857C5B69C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# Settings for Microsoft Windows Vista and Server 2008..#....# The Vista theme can only be defined on Windows Vista and above. The theme..# is created in C due to the need to assign a theme-enabled function for..# detecting when themeing is disabled. On systems that cannot support the..# Vista theme, there will be no such theme created and we must not..# evaluate this script.....if {"vista" ni [ttk::style theme names]} {.. return..}....namespace eval ttk::theme::vista {.... ttk::style theme settings vista {.... .ttk::style configure . \... -background SystemButtonFace \... -foreground SystemWindowText \... -selectforeground SystemHighlightText \... -selectbackground SystemHighlight \... -insertcolor SystemWindowText \... -font TkDefaultFont \... ;.....ttk::style map "." \... -foreground [list disabled SystemGrayText] \... ;.....ttk::style configure TButton -anchor center -padding {1 1} -width -11...ttk::style configure TRadiobutton -padding 2...ttk::
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2865
                                                                                                                                                                                                            Entropy (8bit):4.917847108902527
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:b69VhW2gL5FPVWRzQsVqrEuF3yYrf7rfJF8xUqBgLt6g3ktO5jo4+iZ6O2htYtCW:bbXl+CEqZNNSxU0Ht2MR7W
                                                                                                                                                                                                            MD5:769C0719A4044F91E7D132A25291E473
                                                                                                                                                                                                            SHA1:6FB07B0C887D443A43FB15D5728920B578171219
                                                                                                                                                                                                            SHA-256:AE82BCCCE708FF9C303CBCB3D4CC3FF5577A60D5B23822EA79E3E07CCE3CBBD1
                                                                                                                                                                                                            SHA-512:47FED061DDC6B4EB63EF77901D0094FF2EBB1BAFACB3F44FBF13FB59DEA1EC83985B2862086ECF1A7957819A88A0FAA144B35F16BEA9356BBD9775070D42E636
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# Settings for 'winnative' theme...#....namespace eval ttk::theme::winnative {.. ttk::style theme settings winnative {.....ttk::style configure "." \... -background SystemButtonFace \... -foreground SystemWindowText \... -selectforeground SystemHighlightText \... -selectbackground SystemHighlight \... -fieldbackground SystemWindow \... -insertcolor SystemWindowText \... -troughcolor SystemScrollbar \... -font TkDefaultFont \... ;.....ttk::style map "." -foreground [list disabled SystemGrayText] ;.. ttk::style map "." -embossed [list disabled 1] ;.....ttk::style configure TButton \... -anchor center -width -11 -relief raised -shiftrelief 1...ttk::style configure TCheckbutton -padding "2 4"...ttk::style configure TRadiobutton -padding "2 4"...ttk::style configure TMenubutton \... -padding "8 4" -arrowsize 3 -relief raised.....ttk::style map TButton -relief {{!disabled pressed} sunken}.....ttk::style configure TEntry \... -padding 2 -select
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2103
                                                                                                                                                                                                            Entropy (8bit):4.9805308941424355
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:aaiIu89VhW2gLRWJyO514rf+rfzxTrf/MW+iZ6O2htYtCp:XoXAk21nxQ7p
                                                                                                                                                                                                            MD5:162F30D2716438C75EA16B57E6F63088
                                                                                                                                                                                                            SHA1:3F626FF0496BB16B27106BED7E38D1C72D1E3E27
                                                                                                                                                                                                            SHA-256:AEDB21C6B2909A4BB4686837D2126E521A8CC2B38414A4540387B801EBD75466
                                                                                                                                                                                                            SHA-512:6EBF9648F1381D04F351BB469B6E3A38F3D002189C92EAF80A18D65632037FF37D34EC8814BBF7FAE34553645BFC13985212F24684EE8C4E205729B975C88C97
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:#..# Settings for 'xpnative' theme..#....namespace eval ttk::theme::xpnative {.... ttk::style theme settings xpnative {.....ttk::style configure . \... -background SystemButtonFace \... -foreground SystemWindowText \... -selectforeground SystemHighlightText \... -selectbackground SystemHighlight \... -insertcolor SystemWindowText \... -font TkDefaultFont \... ;.....ttk::style map "." \... -foreground [list disabled SystemGrayText] \... ;.....ttk::style configure TButton -anchor center -padding {1 1} -width -11...ttk::style configure TRadiobutton -padding 2...ttk::style configure TCheckbutton -padding 2...ttk::style configure TMenubutton -padding {8 4}.....ttk::style configure TNotebook -tabmargins {2 2 2 0}...ttk::style map TNotebook.Tab \... -expand [list selected {2 2 2 2}].....ttk::style configure TLabelframe.Label -foreground "#0046d5".....# OR: -padding {3 3 3 6}, which some apps seem to use....ttk::style configure TEntry -padding {2 2 2 4}...ttk::
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):10521
                                                                                                                                                                                                            Entropy (8bit):5.0647027375963996
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:1Y3uWEXm/swEePmJhRAXd1hTHsHG2ML/9Lm2daM0Hu:8hodMiM0Hu
                                                                                                                                                                                                            MD5:508F7E258C04970FAE526990168CB773
                                                                                                                                                                                                            SHA1:33785204B18C0E0F5CDCB5B49399B5907351FDB8
                                                                                                                                                                                                            SHA-256:B463B366F139DDF7FED31F34C6D2341F9F27845A1A358011DFC801E1333B1828
                                                                                                                                                                                                            SHA-512:A12985B58DD1D46297119CED47B7F44EF4139CED6C36FD028E66DD657E5ED0663B744C679A5BF7A39B39D17A32E1280D2945F6B9AD59AEF20436F68040F6070C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# unsupported.tcl --..#..# Commands provided by Tk without official support. Use them at your..# own risk. They may change or go away without notice...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....# ----------------------------------------------------------------------..# Unsupported compatibility interface for folks accessing Tk's private..# commands and variable against recommended usage...# ----------------------------------------------------------------------....namespace eval ::tk::unsupported {.... # Map from the old global names of Tk private commands to their.. # new namespace-encapsulated names..... variable PrivateCommands.. array set PrivateCommands {...tkButtonAutoInvoke..::tk::ButtonAutoInvoke...tkButtonDown...::tk::ButtonDown...tkButtonEnter...::tk::ButtonEnter...tkButtonInvoke...::tk::ButtonInvoke...tkButtonLeave...::tk::ButtonLeave...tkButtonUp...::tk::ButtonUp...tk
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):26991
                                                                                                                                                                                                            Entropy (8bit):4.974180990171971
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:0BLzjXhss64XKNFXm39QJ63nwFiHLgRIdNPCRE5phLtffsNP4XWdxWk+I5oP9jNR:0BvjXoFCB3flLCRE5phLCP3xWq8vWTod
                                                                                                                                                                                                            MD5:FA99EF44FAA88A6BA1967A1257DEB97B
                                                                                                                                                                                                            SHA1:CC99DBF678F4169A90ACC5A89C6F8DAB48052EC6
                                                                                                                                                                                                            SHA-256:C4722EADEDE763FA52E7937D40067B0F8EB86B7A4B707F90212ED3E5289690D0
                                                                                                                                                                                                            SHA-512:3AF16095784908A444CD61EEF178A30B9FED9C20AA91D94044A3AECB6047267FB80BCE790FC1F28FB19AEF664A6618FD832612F541FDADCC34B6C01E92E5EA40
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# xmfbox.tcl --..#..#.Implements the "Motif" style file selection dialog for the..#.Unix platform. This implementation is used only if the..#."::tk_strictMotif" flag is set...#..# Copyright (c) 1996 Sun Microsystems, Inc...# Copyright (c) 1998-2000 Scriptics Corporation..#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....namespace eval ::tk::dialog {}..namespace eval ::tk::dialog::file {}......# ::tk::MotifFDialog --..#..#.Implements a file dialog similar to the standard Motif file..#.selection box...#..# Arguments:..#.type.."open" or "save"..#.args..Options parsed by the procedure...#..# Results:..#.When -multiple is set to 0, this returns the absolute pathname..#.of the selected file. (NOTE: This is not the same as a single..#.element list.)..#..#.When -multiple is set to > 0, this returns a Tcl list of absolute..# pathnames. The argument for -multiple is ignored, but for consistency..#
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):66328
                                                                                                                                                                                                            Entropy (8bit):6.292278022777317
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:1536:uRvfc/1Zb3YuY7S81CG6O6mdIvOSz7SysxLR:Qvuz3hKSpG6O6mdIvOSzs
                                                                                                                                                                                                            MD5:ED2305190284E384A31337094C9F5239
                                                                                                                                                                                                            SHA1:EB8FAEBF9FE9438541CA65B9892BADC2233A405D
                                                                                                                                                                                                            SHA-256:2CAD195BA200CD94702403559323C7ABF3772A20203A11BEAE03770A04437DE2
                                                                                                                                                                                                            SHA-512:139C83EBF748720E64C7A6A8F00F45755D17CD8F754CADC0804ECE5753C02E5C95210A8B96A92FFF89148BA34568F8B1BD6C33D1D3BA7A75F881446956876893
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......bu..&..&..&../l_. ..6..$..6..%..6.....6..+..n..$..ml.$...o.#..&.....n...$..n..'..n.3.'..n..'..Rich&..................PE..d....g.f.........." ...).n...j.......................................................h....`.............................................P.............................../......0......T...............................@............................................text....l.......n.................. ..`.rdata...B.......D...r..............@..@.data... ...........................@....pdata..............................@..@.rsrc...............................@..@.reloc..0...........................@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):38168
                                                                                                                                                                                                            Entropy (8bit):6.338968434676258
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:kEkKWSx+lZb+7iNEpPlFIvCiS5YiSyvxPAMxkERJ:kE9W5XyiNEvFIvCiQ7SyJPxj
                                                                                                                                                                                                            MD5:FDA7D7AADA1D15CAB2ADD2F4BD2E59A1
                                                                                                                                                                                                            SHA1:7E61473F2AD5E061EF59105BF4255DBE7DB5117A
                                                                                                                                                                                                            SHA-256:B0ED1C62B73B291A1B57E3D8882CC269B2FCBB1253F2947DA18D9036E0C985D9
                                                                                                                                                                                                            SHA-512:95C2934A75507EA2D8C817DA7E76EE7567EC29A52018AEF195FAC779B7FFB440C27722D162F8E416B6EF5D3FD0936C71A55776233293B3DD0124D51118A2B628
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........H2.&a.&a.&a..a.&a..'`.&a..%`.&a.."`.&a..'`.&a..#`.&a..'`.&a.'a..&a.."`.&a../`.&a..&`.&a...a.&a..$`.&aRich.&a................PE..d....g.f.........." ...).,...<.......)..............................................Y.....`.........................................0V..H...xV.......................f.../......t...tG..T............................C..@............@.......T..@....................text....*.......,.................. ..`.rdata..d ...@..."...0..............@..@.data........p.......R..............@....pdata...............V..............@..@.rsrc................Z..............@..@.reloc..t............d..............@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Zip archive data, at least v2.0 to extract, compression method=store
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1332793
                                                                                                                                                                                                            Entropy (8bit):5.5865879348515195
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12288:f8lJGUqc4rmn9OPNsxuy4htMHc1b4oDAs/SquRROzBMdmyP/H/V949/Rr2/Hg:f8lJGUU697ls30yMdmyPvP4t2/Hg
                                                                                                                                                                                                            MD5:BED03063E08A571088685625544CE144
                                                                                                                                                                                                            SHA1:56519A1B60314EC43F3AF0C5268ECC4647239BA3
                                                                                                                                                                                                            SHA-256:0D960743DBF746817B61FF7DD1C8C99B4F8C915DE26946BE56118CD6BEDAEBDC
                                                                                                                                                                                                            SHA-512:C136E16DB86F94B007DB42A9BF485A7C255DCC2843B40337E8F22A67028117F5BD5D48F7C1034D7446BB45EA16E530F1216D22740DDB7FAB5B39CC33D4C6D995
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:PK..........!....uS...S......._collections_abc.pyc......................................Z.....d.Z.d.d.l.m.Z.m.Z...d.d.l.Z...e.e.e.............Z...e.d.........Z.d...Z...e.e.........Z.[.g.d...Z.d.Z...e...e.d.................Z...e...e...e.........................Z...e...e.i.j%..........................................Z...e...e.i.j)..........................................Z...e...e.i.j-..........................................Z...e...e.g.................Z...e...e...e.g.........................Z...e...e...e.d.........................Z...e...e...e.d.d.z...........................Z...e...e...e.........................Z...e...e.d.................Z ..e...e.d.................Z!..e...e...e"........................Z#..e.i.j%..................................Z$..e.i.j)..................................Z%..e.i.j-..................................Z&..e.e.jN..........................Z(..e...d...................Z)d...Z*..e*........Z*..e.e*........Z+e*jY............................[*d...Z-..e-........
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):299427
                                                                                                                                                                                                            Entropy (8bit):6.047872935262006
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6144:QW1x/M8fRR1jplkXURrVADwYCuCigT/QRSRqNb7d8iu5Nahx:QWb/TRJLWURrI5RWavdF08/
                                                                                                                                                                                                            MD5:50EA156B773E8803F6C1FE712F746CBA
                                                                                                                                                                                                            SHA1:2C68212E96605210EDDF740291862BDF59398AEF
                                                                                                                                                                                                            SHA-256:94EDEB66E91774FCAE93A05650914E29096259A5C7E871A1F65D461AB5201B47
                                                                                                                                                                                                            SHA-512:01ED2E7177A99E6CB3FBEF815321B6FA036AD14A3F93499F2CB5B0DAE5B713FD2E6955AA05F6BDA11D80E9E0275040005E5B7D616959B28EFC62ABB43A3238F0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:.# Issuer: CN=GlobalSign Root CA O=GlobalSign nv-sa OU=Root CA.# Subject: CN=GlobalSign Root CA O=GlobalSign nv-sa OU=Root CA.# Label: "GlobalSign Root CA".# Serial: 4835703278459707669005204.# MD5 Fingerprint: 3e:45:52:15:09:51:92:e1:b7:5d:37:9f:b1:87:29:8a.# SHA1 Fingerprint: b1:bc:96:8b:d4:f4:9d:62:2a:a8:9a:81:f2:15:01:52:a4:1d:82:9c.# SHA256 Fingerprint: eb:d4:10:40:e4:bb:3e:c7:42:c9:e3:81:d3:1e:f2:a4:1a:48:b6:68:5c:96:e7:ce:f3:c1:df:6c:d4:33:1c:99.-----BEGIN CERTIFICATE-----.MIIDdTCCAl2gAwIBAgILBAAAAAABFUtaw5QwDQYJKoZIhvcNAQEFBQAwVzELMAkG.A1UEBhMCQkUxGTAXBgNVBAoTEEdsb2JhbFNpZ24gbnYtc2ExEDAOBgNVBAsTB1Jv.b3QgQ0ExGzAZBgNVBAMTEkdsb2JhbFNpZ24gUm9vdCBDQTAeFw05ODA5MDExMjAw.MDBaFw0yODAxMjgxMjAwMDBaMFcxCzAJBgNVBAYTAkJFMRkwFwYDVQQKExBHbG9i.YWxTaWduIG52LXNhMRAwDgYDVQQLEwdSb290IENBMRswGQYDVQQDExJHbG9iYWxT.aWduIFJvb3QgQ0EwggEiMA0GCSqGSIb3DQEBAQUAA4IBDwAwggEKAoIBAQDaDuaZ.jc6j40+Kfvvxi4Mla+pIH/EqsLmVEQS98GPR4mdmzxzdzxtIK+6NiY6arymAZavp.xy0Sy6scTHAHoT0KMM0VjU/43dSMUBUc71DuxC73/OlS8pF94G3VNTCOXkNz
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):10752
                                                                                                                                                                                                            Entropy (8bit):4.674392865869017
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:KGUmje72HzA5iJGhU2Y0hQMsQJCUCLsZEA4elh3XQMtCFXiHBpv9cX6gTim1qeSC:rjQ2HzzU2bRYoe1HH9cqgTimoe
                                                                                                                                                                                                            MD5:D9E0217A89D9B9D1D778F7E197E0C191
                                                                                                                                                                                                            SHA1:EC692661FCC0B89E0C3BDE1773A6168D285B4F0D
                                                                                                                                                                                                            SHA-256:ECF12E2C0A00C0ED4E2343EA956D78EED55E5A36BA49773633B2DFE7B04335C0
                                                                                                                                                                                                            SHA-512:3B788AC88C1F2D682C1721C61D223A529697C7E43280686B914467B3B39E7D6DEBAFF4C0E2F42E9DDDB28B522F37CB5A3011E91C66D911609C63509F9228133D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......B..............................M....................................... ...?.......?.......?.a.....?.......Rich............................PE..d....jAe.........." ...%.....................................................p............`..........................................'..p...`(..d....P.......@...............`..,...`#.............................. "..@............ ...............................text............................... ..`.rdata....... ......................@..@.data...8....0......."..............@....pdata.......@.......$..............@..@.rsrc........P.......&..............@..@.reloc..,....`.......(..............@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):122880
                                                                                                                                                                                                            Entropy (8bit):5.917175475547778
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3072:bA3W6Fck6/g5DzNa4cMy/dzpd1dhdMdJGFEr6/vD:MW6NzcMy/d13FErgvD
                                                                                                                                                                                                            MD5:BF9A9DA1CF3C98346002648C3EAE6DCF
                                                                                                                                                                                                            SHA1:DB16C09FDC1722631A7A9C465BFE173D94EB5D8B
                                                                                                                                                                                                            SHA-256:4107B1D6F11D842074A9F21323290BBE97E8EED4AA778FBC348EE09CC4FA4637
                                                                                                                                                                                                            SHA-512:7371407D12E632FC8FB031393838D36E6A1FE1E978CED36FF750D84E183CDE6DD20F75074F4597742C9F8D6F87AF12794C589D596A81B920C6C62EE2BA2E5654
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........C..r...r...r......r...s...r...s...r...w...r...v..r...q...r.#.s...r...s...r..8z...r..8r...r..8....r..8p...r.Rich..r.........................PE..d....jAe.........." ...%.:...........<.......................................0............`.........................................@...d.......................(............ ......P...................................@............P...............................text....8.......:.................. ..`.rdata...W...P...X...>..............@..@.data...8=.......0..................@....pdata..(...........................@..@.rsrc...............................@..@.reloc....... ......................@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):5440
                                                                                                                                                                                                            Entropy (8bit):5.074342830021076
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:DlaQIUQIhQIKQILbQIRIaMPktjaVxsxA2TtLDmplH7dwnqTIvrUmA0JQTQCQx5KN:LcPuP1srTtLDmplH7JTIvYX0JQTQ9x54
                                                                                                                                                                                                            MD5:554DC6138FDBF98B7F1EDFE207AF3D67
                                                                                                                                                                                                            SHA1:B6C806E2AFF9A0F560916A90F793348DBF0514BA
                                                                                                                                                                                                            SHA-256:0064A9B5FD2AC18605E512EF7127318AD9CF259E9445488C169F237A590602E1
                                                                                                                                                                                                            SHA-512:3A71B533874F4D0F94F15192791D2FA4DF9E8EBF184C711F1D4FA97230C04764C1C9A93258355B08107E5B72053C6901E883E3DB577E8A204D5B9EB3F8BC7BFC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Metadata-Version: 2.3.Name: cryptography.Version: 43.0.1.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: Apache Software License.Classifier: License :: OSI Approved :: BSD License.Classifier: Natural Language :: English.Classifier: Operating System :: MacOS :: MacOS X.Classifier: Operating System :: POSIX.Classifier: Operating System :: POSIX :: BSD.Classifier: Operating System :: POSIX :: Linux.Classifier: Operating System :: Microsoft :: Windows.Classifier: Programming Language :: Python.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3 :: Only.Classifier: Programming Language :: Python :: 3.7.Classifier: Programming Language :: Python :: 3.8.Classifier: Programming Language :: Python :: 3.9.Classifier: Programming Language :: Python :: 3.10.Classifier: Programming Language :: Python :: 3.11.Classifier: Programming Language :: Python :: 3.12.Classif
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):15579
                                                                                                                                                                                                            Entropy (8bit):5.567434003079107
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:bX1ToLbz5jF4E9VqhXJZ4WPB6s7B0Ppz+NX6in5Lqw/I+B:bXeLbhCEsJrPB6s7B0Ppz+96innVB
                                                                                                                                                                                                            MD5:E8478B758300439BF58613F2A3A2676C
                                                                                                                                                                                                            SHA1:39ED064E67212A54E4B8D1C909E6AD2ACF48025D
                                                                                                                                                                                                            SHA-256:5ADEAA62D3045659DDF79324823AA3BCB1CA78F264442D6F6F6B9C8A8470A634
                                                                                                                                                                                                            SHA-512:D7029823DC5585FBE885DDB52EED2D02D1584EB945EF23916391201FCBD17DF0B14F338BDFC6E81318297F831CA99796423206F781373857317E068F0C0B321C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:cryptography-43.0.1.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..cryptography-43.0.1.dist-info/METADATA,sha256=AGSptf0qwYYF5RLvcScxitnPJZ6URUiMFp8jelkGAuE,5440..cryptography-43.0.1.dist-info/RECORD,,..cryptography-43.0.1.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..cryptography-43.0.1.dist-info/WHEEL,sha256=8_4EnrLvbhzH224YH8WypoB7HFn-vpbwr_zHlr3XUBI,94..cryptography-43.0.1.dist-info/license_files/LICENSE,sha256=Pgx8CRqUi4JTO6mP18u0BDLW8amsv4X1ki0vmak65rs,197..cryptography-43.0.1.dist-info/license_files/LICENSE.APACHE,sha256=qsc7MUj20dcRHbyjIJn2jSbGRMaBOuHk8F9leaomY_4,11360..cryptography-43.0.1.dist-info/license_files/LICENSE.BSD,sha256=YCxMdILeZHndLpeTzaJ15eY9dz2s0eymiSMqtwCPtPs,1532..cryptography/__about__.py,sha256=pY_pmYXjJTK-LjfCu7ot0NMj0QC2dkD1dCPyV8QjISM,445..cryptography/__init__.py,sha256=mthuUrTd4FROCpUYrTIqhjz6s6T9djAZrV7nZ1oMm2o,364..cryptography/__pycache__/__about__.cpython-312.pyc,,..cryptography/__pycache__/__ini
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):94
                                                                                                                                                                                                            Entropy (8bit):5.016084900984752
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeX5pGogP+tkKciH/KQb:RtvoTWKTQb
                                                                                                                                                                                                            MD5:C869D30012A100ADEB75860F3810C8C9
                                                                                                                                                                                                            SHA1:42FD5CFA75566E8A9525E087A2018E8666ED22CB
                                                                                                                                                                                                            SHA-256:F3FE049EB2EF6E1CC7DB6E181FC5B2A6807B1C59FEBE96F0AFFCC796BDD75012
                                                                                                                                                                                                            SHA-512:B29FEAF6587601BBE0EDAD3DF9A87BFC82BB2C13E91103699BABD7E039F05558C0AC1EF7D904BCFAF85D791B96BC26FA9E39988DD83A1CE8ECCA85029C5109F0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: maturin (1.7.0).Root-Is-Purelib: false.Tag: cp39-abi3-win_amd64.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):197
                                                                                                                                                                                                            Entropy (8bit):4.61968998873571
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:hWDncJhByZmJgXPForADu1QjygQuaAJygT2d5GeWreLRuOFEXAYeBKmJozlMHuO:h9Co8FyQjkDYc5tWreLBF/pn2mH1
                                                                                                                                                                                                            MD5:8C3617DB4FB6FAE01F1D253AB91511E4
                                                                                                                                                                                                            SHA1:E442040C26CD76D1B946822CAF29011A51F75D6D
                                                                                                                                                                                                            SHA-256:3E0C7C091A948B82533BA98FD7CBB40432D6F1A9ACBF85F5922D2F99A93AE6BB
                                                                                                                                                                                                            SHA-512:77A1919E380730BCCE5B55D76FBFFBA2F95874254FAD955BD2FE1DE7FC0E4E25B5FDAAB0FEFFD6F230FA5DC895F593CF8BFEDF8FDC113EFBD8E22FADAB0B8998
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:This software is made available under the terms of *either* of the licenses.found in LICENSE.APACHE or LICENSE.BSD. Contributions to cryptography are made.under the terms of *both* these licenses..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):11360
                                                                                                                                                                                                            Entropy (8bit):4.426756947907149
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:nUDG5KXSD9VYUKhu1JVF9hFGvV/QiGkS594drFjuHYx5dvTrLh3kTSEnQHbHR:UIvlKM1zJlFvmNz5VrlkTS0QHt
                                                                                                                                                                                                            MD5:4E168CCE331E5C827D4C2B68A6200E1B
                                                                                                                                                                                                            SHA1:DE33EAD2BEE64352544CE0AA9E410C0C44FDF7D9
                                                                                                                                                                                                            SHA-256:AAC73B3148F6D1D7111DBCA32099F68D26C644C6813AE1E4F05F6579AA2663FE
                                                                                                                                                                                                            SHA-512:F451048E81A49FBFA11B49DE16FF46C52A8E3042D1BCC3A50AAF7712B097BED9AE9AED9149C21476C2A1E12F1583D4810A6D36569E993FE1AD3879942E5B0D52
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:. Apache License. Version 2.0, January 2004. https://www.apache.org/licenses/.. TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION.. 1. Definitions... "License" shall mean the terms and conditions for use, reproduction,. and distribution as defined by Sections 1 through 9 of this document... "Licensor" shall mean the copyright owner or entity authorized by. the copyright owner that is granting the License... "Legal Entity" shall mean the union of the acting entity and all. other entities that control, are controlled by, or are under common. control with that entity. For the purposes of this definition,. "control" means (i) the power, direct or indirect, to cause the. direction or management of such entity, whether by contract or. otherwise, or (ii) ownership of fifty percent (50%) or more of the. outstanding shares, or (iii) beneficial ow
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1532
                                                                                                                                                                                                            Entropy (8bit):5.058591167088024
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:MjUnoorbOFFTJJyRrYFTjzMbmqEvBTP4m96432s4EOkUTKQROJ32s3yxsITf+3tY:MkOFJSrYJsaN5P406432svv32s3EsIqm
                                                                                                                                                                                                            MD5:5AE30BA4123BC4F2FA49AA0B0DCE887B
                                                                                                                                                                                                            SHA1:EA5B412C09F3B29BA1D81A61B878C5C16FFE69D8
                                                                                                                                                                                                            SHA-256:602C4C7482DE6479DD2E9793CDA275E5E63D773DACD1ECA689232AB7008FB4FB
                                                                                                                                                                                                            SHA-512:DDBB20C80ADBC8F4118C10D3E116A5CD6536F72077C5916D87258E155BE561B89EB45C6341A1E856EC308B49A4CB4DBA1408EABD6A781FBE18D6C71C32B72C41
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Copyright (c) Individual contributors..All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions are met:.. 1. Redistributions of source code must retain the above copyright notice,. this list of conditions and the following disclaimer... 2. Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution... 3. Neither the name of PyCA Cryptography nor the names of its contributors. may be used to endorse or promote products derived from this software. without specific prior written permission...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND.ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED.WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOS
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7900672
                                                                                                                                                                                                            Entropy (8bit):6.519460416205842
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:49152:Hvisa2OcIo0UYN1YA2sBCT7I0XIU6iOGtlqNVwASO0AIjoI+b0vjemXSKSDhxlT3:Pi/2PTYDBCT7NY+gTNxY7GbdJ295x
                                                                                                                                                                                                            MD5:81AD4F91BB10900E3E2E8EAF917F42C9
                                                                                                                                                                                                            SHA1:840F7AEF02CDA6672F0E3FC7A8D57F213DDD1DC6
                                                                                                                                                                                                            SHA-256:5F20D6CEC04685075781996A9F54A78DC44AB8E39EB5A2BCF3234E36BEF4B190
                                                                                                                                                                                                            SHA-512:11CD299D6812CDF6F0A74BA86EB44E9904CE4106167EBD6E0B81F60A5FCD04236CEF5CFF81E51ED391F5156430663056393DC07353C4A70A88024194768FFE9D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......l..(...(...(...!...:...8...*...8...,...8... ...8...9...c..&...G...*...(...+...`...V...(.....`...)...`...)...Rich(...........................PE..d....j.f.........." ...).`Z..V........X.......................................x...........`.........................................p.r.......r...............t...............x......Cj.T....................Cj.(....Aj.@............pZ..............................text...._Z......`Z................. ..`.rdata..ZR...pZ..T...dZ.............@..@.data....+....r.......r.............@....pdata........t.......s.............@..@.reloc........x.......w.............@..B........................................................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Apple Desktop Services Store
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):6148
                                                                                                                                                                                                            Entropy (8bit):0.6888931042627182
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:Q2ggpaOJTZ4OJTajdO3oz6ifn9mmNIlwO89EEX/HnXw6XUEK/XDXw6X:3fpFTZDToE3oz6ifnImm+fnV2V
                                                                                                                                                                                                            MD5:A2FE3C1CC8F70B63D7B51111A5E45EAD
                                                                                                                                                                                                            SHA1:450C18DF31657412B794688CB1CACE5DBF5E8EFA
                                                                                                                                                                                                            SHA-256:57ADA387AF15BFF448242A05E4E35D2B757798B0802CB894C81B4DC4E473002F
                                                                                                                                                                                                            SHA-512:90D6A5D667A4386DB834EDDFFB526218F1C10B9F56F020B52AAB3E31B5B7E0E51E86867760C7BAFC18DF9F3C52A76C63774A6EE915127C39296209C39A2A77B5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:....Bud1.................................................................................sIlocblob...............................................................................................................................................................................................................................................................................................................................................................................................................................................f.o.n.t.sIlocblob.......A.................i.c.o.n.sIlocblob.........................i.c.o.n.sbwspblob....bplist00.............]ShowStatusBar[ShowToolbar[ShowTabView_..ContainerShowSidebar\WindowBounds[ShowSidebar...._..{{380, 96}, {1099, 800}}...#/;R_klmno......................................i.c.o.n.svSrnlong.........t.h.e.m.e.sIlocblob....................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:OpenType font data
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3528
                                                                                                                                                                                                            Entropy (8bit):5.5463381859994065
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:AhHW6DYnFFJFRFO7XPfWB8O8E09Li3kX6QpyotT6c43W:AhH/D2FrbQXPuCE09HScSW
                                                                                                                                                                                                            MD5:5F1BFE2E716608D1394D7A444CBD0354
                                                                                                                                                                                                            SHA1:20D061B3B742CFA31E5FBC862D34F557534EFDBF
                                                                                                                                                                                                            SHA-256:FAD67E2B060C318B6C8646D087FBD3ADD938B6676243F14B0C52623179641274
                                                                                                                                                                                                            SHA-512:57E4C2743FDB6D54B7736F88E267ADC1953508075E211A95539A31BF62AEF0DF67367EA9326D43118D69827D3376606705047BFF8092D1D6278D002594B68ABF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:OTTO........CFF ..&.........OS/2i.d........`cmap.J.I........head../........6hhea...........$hmtxYf.....d...dmaxp..P.........name.P.....`...Qpost........... .........a.._.<..........v......v...........................................................P................................1..............................XXXX.@. .Z.........,.........^... . .....".............y.......................K.........#.J.........!.`...........#......... .............y...........y...........y...........y...........y...........y...........y...........y.......................K.....................2.............R.........F.m.........B.............0.........@...........................................................................................................2.............RCustomTkinter_shapes_font.C.u.s.t.o.m.T.k.i.n.t.e.r._.s.h.a.p.e.s._.f.o.n.tRegular.R.e.g.u.l.a.rCustomTkinter_shapes_font Regular.C.u.s.t.o.m.T.k.i.n.t.e.r._.s.h.a.p.e.s._.f.o.n.t. .R.e.g.u.l.a.rCustomTkinter_shapes_fontRegular.C.u.s.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:TrueType Font data, 18 tables, 1st "GDEF", 15 names, Microsoft, language 0x409, Copyright 2011 Google Inc. All Rights Reserved.Roboto MediumRegularVersion 2.137; 2017Roboto-Med
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):168644
                                                                                                                                                                                                            Entropy (8bit):6.500433229170635
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3072:Fqmtn5wkex8r6Qym7KCkygAKuXylCC9ptSUXl8j/6afWZCyhASD/JwXI:425wklN7T3QtSUXz/2STyXI
                                                                                                                                                                                                            MD5:B2D307DF606F23CB14E6483039E2B7FA
                                                                                                                                                                                                            SHA1:FDDC8B1C688EF3BAED0D5A46ABF5F01F0EDAF02B
                                                                                                                                                                                                            SHA-256:4AC8E03606FFA4C37F61A6510A2080F1F37A7054F4726C214887D3B23F72E369
                                                                                                                                                                                                            SHA-512:2623C2A235720F389E0D8668DA01891B7A0D23A0FC3DB82865D8CB9BB730804EE84FCD863F33D28AAA236C1261714FF7C325FA677A4599356C29682D3571ACEE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:........... GDEF.B.........bGPOS.nK.......e.GSUB..Y..}4....OS/2.....<...`cmap..Qm........cvt 1..K...H...\fpgm..$....8....gasp............glyf/......,...<hdmxd.t.........head...r......6hhea...........$hmtx..M........8loca..n........maxp.>.....h... name>.mR........post.m.d...t... prep...).......S...d...(.............o......9........................EX../... >Y..EX../....>Y......9......9......9......9........9......9......01!!.!.......!.5.!.(.<..6......................}.w...x.^.^..^...............<......9.........EX../... >Y..EX../....>Y.....+X!...Y..../01.#.!.462...."&.~......J.JH.H......9KK97JJ....e...@.......%...EX../...">Y..../..../......./01..#.3..#.3..#...-#...w.}....}.....`...............EX../... >Y..EX../... >Y..EX../....>Y..EX../....>Y......9../.....+X!...Y............../.....+X!...Y...............................01.#.#.#5!.#5!.3.3.3.3.#.3.#.#.3.#...L.L...:...N.N.N.N..:..L.v.:....f....9....`...`....f.8.9...d.-.&...,...*-...9...EX../... >Y..EX../... >Y..EX.#/.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:TrueType Font data, 18 tables, 1st "GDEF", 13 names, Microsoft, language 0x409, Copyright 2011 Google Inc. All Rights Reserved.RobotoRegularVersion 2.137; 2017Roboto-RegularRob
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):168260
                                                                                                                                                                                                            Entropy (8bit):6.486835016949693
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3072:Jy2goL/sAQRuzzlPrvRwhRFUzMWlYfxJVBxV+aYT3qPXI0eH4OuNOIOU7og2FnI:BOmCeu+bqPaHkWUMxFnI
                                                                                                                                                                                                            MD5:F36638C2135B71E5A623DCA52B611173
                                                                                                                                                                                                            SHA1:84D102488738B0EBBC7A5087973EFFBD54C95BD5
                                                                                                                                                                                                            SHA-256:319CFF6E7A31F0F2A41C475DCA42890AA5D19FE16017E2290F8C1D4E14F76481
                                                                                                                                                                                                            SHA-512:E9D55580EDDDE182CD9AB96057E129039154F54EFB0384613AA9513ED0D2D16EACCB5F6D77A299DE601ADDF0150DCDDE1FE98E31D047BBF85A66AC319C3280B5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:........... GDEF.B.........bGPOS..........].GSUB..Y..{.....OS/2.......l...`cmap..Qm........cvt +......p...Tfpgmw.`....h....gasp.......x....glyf&......,...lhdmxUz`z........head.j.z.......6hhea.......H...$hmtx.r.........8loca.w.........maxp.>........ name6!a.........post.m.d...X... prep.f.....$...I...d...(.............q......9........................EX../....>Y..EX../....>Y......9......9......9......9..........9......9.......01!!.!.......!.5.!.(.<..6......................}.w...x.^.^..^.......{.......0...EX../....>Y..EX../....>Y.....+X!...Y......901.#.3.462..."&.[....7l88l7......-==Z;;........#.........../......9../........01..#.3..#.3...o.....o...x...........w...............EX../....>Y..EX../....>Y..EX../....>Y..EX../....>Y......9|../......+X!...Y............../.....+X!...Y...............................01.!.#.#5!.!5!.3.!.3.3.#.3.#.#.!.!....P.P...E....R.R..R.R..E..P....E.....f....b....`...`.....f.#.b....n.0.....+.i...EX../....>Y..EX."/..".>Y.."...9..................+X!.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Apple Desktop Services Store
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):6148
                                                                                                                                                                                                            Entropy (8bit):0.3190422957527575
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:6:VWilXPQIIW7e4WNW3dDh+Sk1dfl/CuX86XkEslX/9ldlXSPnrtHP8//ktLERulXC:Qi/fHIBdNaO89EEX/HnXw6XAERqXw6X
                                                                                                                                                                                                            MD5:0B5F6FF2993F88FB78902D1CCDD8BEB1
                                                                                                                                                                                                            SHA1:B26C174A98E6564B0E60E2E99BC78E6490B5F42A
                                                                                                                                                                                                            SHA-256:E53EFB2CA4FDE2219A3DC5DED422EC46EECC7A0547B6663B9AC9E16196AC6D25
                                                                                                                                                                                                            SHA-512:D30900D33A2D7387BD115BC2C403C1A70F792579E320C0EE175BF64F68EA2F1C2872D65A8E803653151C94559D2D2CBAD5A0E683347F7D7A926015A6C0F94A06
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:....Bud1.................................................................................o.m.T.k.i.n.............................................C.u.s.t.o.m.T.k.i.n.t.e.r._.i.c.o.n._.W.i.n.d.o.w.s...i.c.oIlocblob.......A............................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:MS Windows icon resource - 1 icon, 256x256 with PNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced, 32 bits/pixel
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):13238
                                                                                                                                                                                                            Entropy (8bit):7.73062615393382
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:BZXOm6Hm+o9UHgbqweqnjwzVBwNb3bezsRnsE4k7GdfH+jCQoGl8xf+4wznvYvQP:Ph6HmvHeqj4ViPosRnsE94fo0hWPQ+
                                                                                                                                                                                                            MD5:F6E65C6257AFECA83D565264A490029A
                                                                                                                                                                                                            SHA1:B3613164E587D09C052C34CCDC4D44DAC4FF44E2
                                                                                                                                                                                                            SHA-256:1234C017C871EB2E20D36F668F93E066CDCB93DB464D5CEF9D7A5BF83506D28C
                                                                                                                                                                                                            SHA-512:4F9EBE74582F8DB18287292FD5350F20D52E0118F7AAF6848BF6EEC37C4A16069939F0F5716E934FE3D7AAB0E0A0B2BE34BF2AEE359426FF2AAE681B992D75C6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:............ ..3.......PNG........IHDR.............\r.f....orNT..w...3ZIDATx....T...{..e.../~..q.....1N.3..|A#a..vh...%.q..(....@.[u..]...B...F.K..hDQ\YE....z..{...[.V.Zz.....?U.M.[.......s...8._A....@Z...7.T...3.H..7X.=.u...rQ.x.l...+..o...D..:...rEW..2...+.R...;.)..xJ....3.OaS@.;..W...>.......9 .% ..@zI..y.0*;..^.....0.....)7.ct.q.....V5.@W;..5...x..0.p'...`BQ../..5...u>.......K.&..~..k.....#.FO..g.T....A.>.RI'H....*.L*<3F*i_(.v..e].....@..[.T.].&?..JQ...bo..JZE..VzF..4(.............."M.V`b...W...B.?...56_..k\.A>...*....].L].3h..h.P.Q...............8......<H.MtHK>..^.R.!.J.....W.>_*h.!..-.J;.Ke....@.\.&.e4.U.^.i..W..t .X...`.;.x.......H3..h....X...._(0......Q.F.....gPs..p.7...:.@9O..s8.h.0F...j4..w1.7...|...0|>.M.. x...)..`x.<......$..5..a0.V{,oU.VaJ..."e.i...L>.4..v./..~RY..7......k.s..*..r.....QY.o.Y...h.%....n[.r..O.y..~M7.j|..=FUZ..UA.w.....P.T..........JO)...S.[..Q_M.../..._.R.....Q/....w.&.Y..+........1....S.*..l)..p..Kp...W.....@
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:JSON data
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4520
                                                                                                                                                                                                            Entropy (8bit):4.888457499634604
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:KupscLUBH2cEyzmGvtu/XaNgdacgWu/Bwg+Y51hlk2cEdVJFvLpwZdIunacEkGgC:KupNUtMiPQ/XXIRp/v+Y51hT/vlggf+4
                                                                                                                                                                                                            MD5:05EB3947CE9A8C3BEF66C14D0F938671
                                                                                                                                                                                                            SHA1:06FFC811EE51609809D88894022E222B339AEFEE
                                                                                                                                                                                                            SHA-256:C9417470C16CED7A43D6C4A8E027AFA6EDC62C24D5AEE7C4C2DCD11385964D3B
                                                                                                                                                                                                            SHA-512:4DB7C14FBA78185EDF6459016608CB8FA0A250DFB48432C552BB4E0466CF49622B34D847E17C254BB1C8D15BF365E91BCE3EDE552BA8733FDE9D21779F7F1C13
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:{. "CTk": {. "fg_color": ["gray92", "gray14"]. },. "CTkToplevel": {. "fg_color": ["gray92", "gray14"]. },. "CTkFrame": {. "corner_radius": 6,. "border_width": 0,. "fg_color": ["gray86", "gray17"],. "top_fg_color": ["gray81", "gray20"],. "border_color": ["gray65", "gray28"]. },. "CTkButton": {. "corner_radius": 6,. "border_width": 0,. "fg_color": ["#3B8ED0", "#1F6AA5"],. "hover_color": ["#36719F", "#144870"],. "border_color": ["#3E454A", "#949A9F"],. "text_color": ["#DCE4EE", "#DCE4EE"],. "text_color_disabled": ["gray74", "gray60"]. },. "CTkLabel": {. "corner_radius": 0,. "fg_color": "transparent",. "text_color": ["gray10", "#DCE4EE"]. },. "CTkEntry": {. "corner_radius": 6,. "border_width": 2,. "fg_color": ["#F9F9FA", "#343638"],. "border_color": ["#979DA2", "#565B5E"],. "text_color":["gray10", "#DCE4EE"],. "placeholder_text_color": ["gray52", "gray62"]. },. "CTkCheckBox": {. "corner_radius": 6,. "bo
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:JSON data
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4514
                                                                                                                                                                                                            Entropy (8bit):4.857879128214415
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:Kg6L6Xv7Lo2cE0mUtFRCdVWFiaVdXcEdVfvLpwiunacELTaUb4:K5uXoM0VTon2iaVd9Xvlp604
                                                                                                                                                                                                            MD5:37B54F5CD74CD965B783B62F13743F4F
                                                                                                                                                                                                            SHA1:F9EBE07E79E146F79DC88A7FF8942C0E43049F0D
                                                                                                                                                                                                            SHA-256:6A57FA6F8FB8961A30CE6429522B180D76E3AF9B8E0DAAC259059841386A6BD3
                                                                                                                                                                                                            SHA-512:07C93B7312CB1185BAC0555B380B82857BF1F41C93974E5DBAF4DD875822D589AAF80B979272E56E1C2AE3EC7EA34FE81781CC48F2305CE1828CE32984EB43A3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:{. "CTk": {. "fg_color": ["gray95", "gray10"]. },. "CTkToplevel": {. "fg_color": ["gray95", "gray10"]. },. "CTkFrame": {. "corner_radius": 6,. "border_width": 0,. "fg_color": ["gray90", "gray13"],. "top_fg_color": ["gray85", "gray16"],. "border_color": ["gray65", "gray28"]. },. "CTkButton": {. "corner_radius": 6,. "border_width": 0,. "fg_color": ["#3a7ebf", "#1f538d"],. "hover_color": ["#325882", "#14375e"],. "border_color": ["#3E454A", "#949A9F"],. "text_color": ["#DCE4EE", "#DCE4EE"],. "text_color_disabled": ["gray74", "gray60"]. },. "CTkLabel": {. "corner_radius": 0,. "fg_color": "transparent",. "text_color": ["gray14", "gray84"]. },. "CTkEntry": {. "corner_radius": 6,. "border_width": 2,. "fg_color": ["#F9F9FA", "#343638"],. "border_color": ["#979DA2", "#565B5E"],. "text_color": ["gray14", "gray84"],. "placeholder_text_color": ["gray52", "gray62"]. },. "CTkCheckBox": {. "corner_radius": 6,. "bor
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:JSON data
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4515
                                                                                                                                                                                                            Entropy (8bit):4.878000714435556
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:KupscL34QyzmGvt1GNgdWgW1WgKKuvQdVJFvLpwRun8Q+Gga1c4:KupN3FiPPDJGPKK1/vlfN+4
                                                                                                                                                                                                            MD5:39A2D34C52E66F16B396C48BC39FD19C
                                                                                                                                                                                                            SHA1:4F0077DAB6C986A64AB9392630024CB09772B1E8
                                                                                                                                                                                                            SHA-256:79AD86BFEA7F0557AC1E20802892ABB44A967AF15B9315B0039CD75C8B72A776
                                                                                                                                                                                                            SHA-512:F1D31067A25B1F98B83AAB17CE2605FA2C6342BCF0EBCF1D3E32F864E33350F2B7DD2F7E22832ED8AA6879ABA4BA144495BB32AB2696A71537F197462C245ABB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:{. "CTk": {. "fg_color": ["gray92", "gray14"]. },. "CTkToplevel": {. "fg_color": ["gray92", "gray14"]. },. "CTkFrame": {. "corner_radius": 6,. "border_width": 0,. "fg_color": ["gray86", "gray17"],. "top_fg_color": ["gray81", "gray20"],. "border_color": ["gray65", "gray28"]. },. "CTkButton": {. "corner_radius": 6,. "border_width": 0,. "fg_color": ["#2CC985", "#2FA572"],. "hover_color": ["#0C955A", "#106A43"],. "border_color": ["#3E454A", "#949A9F"],. "text_color": ["gray98", "#DCE4EE"],. "text_color_disabled": ["gray78", "gray68"]. },. "CTkLabel": {. "corner_radius": 0,. "fg_color": "transparent",. "text_color": ["gray10", "#DCE4EE"]. },. "CTkEntry": {. "corner_radius": 6,. "border_width": 2,. "fg_color": ["#F9F9FA", "#343638"],. "border_color": ["#979DA2", "#565B5E"],. "text_color":["gray10", "#DCE4EE"],. "placeholder_text_color": ["gray52", "gray62"]. },. "CTkCheckBox": {. "corner_radius": 6,. "bor
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):5232408
                                                                                                                                                                                                            Entropy (8bit):5.940072183736028
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:98304:/V+Qs2NuR5YV0L8PQ1CPwDvt3uFlDC4SC9c:9rs2NuDYV0L841CPwDvt3uFlDC4SCa
                                                                                                                                                                                                            MD5:123AD0908C76CCBA4789C084F7A6B8D0
                                                                                                                                                                                                            SHA1:86DE58289C8200ED8C1FC51D5F00E38E32C1AAD5
                                                                                                                                                                                                            SHA-256:4E5D5D20D6D31E72AB341C81E97B89E514326C4C861B48638243BDF0918CFA43
                                                                                                                                                                                                            SHA-512:80FAE0533BA9A2F5FA7806E86F0DB8B6AAB32620DDE33B70A3596938B529F3822856DE75BDDB1B06721F8556EC139D784BC0BB9C8DA0D391DF2C20A80D33CB04
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$..........._~.._~.._~..V.S.M~.....]~.....[~.....W~.....S~.._~...~......T~..J....~..J...7}..J...^~..J.?.^~..J...^~..Rich_~..........................PE..d......f.........." ...(..7..<......v........................................0P.......O...`...........................................H.0.....O.@....@O.|.... L. .....O../...PO.$...`{D.8............................yD.@.............O..............................text.....7.......7................. ..`.rdata........7.......7.............@..@.data...Ao....K..<....K.............@....pdata....... L.......K.............@..@.idata...%....O..&....N.............@..@.00cfg..u....0O.......N.............@..@.rsrc...|....@O.......N.............@..@.reloc..~....PO.......N.............@..B................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):39696
                                                                                                                                                                                                            Entropy (8bit):6.641880464695502
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:NiQfxQemQJNrPN+moyijAc5YiSyvkIPxWEqG:dfxIQvPkmoyijP7SytPxF
                                                                                                                                                                                                            MD5:0F8E4992CA92BAAF54CC0B43AACCCE21
                                                                                                                                                                                                            SHA1:C7300975DF267B1D6ADCBAC0AC93FD7B1AB49BD2
                                                                                                                                                                                                            SHA-256:EFF52743773EB550FCC6CE3EFC37C85724502233B6B002A35496D828BD7B280A
                                                                                                                                                                                                            SHA-512:6E1B223462DC124279BFCA74FD2C66FE18B368FFBCA540C84E82E0F5BCBEA0E10CC243975574FA95ACE437B9D8B03A446ED5EE0C9B1B094147CEFAF704DFE978
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........iV...8...8...8..p....8.t9...8.p9...8...9...8.t=...8.t<...8.t;...8.1t<...8.1t;...8.1t8...8.1t:...8.Rich..8.........................PE..d...Sh.c.........." ...".H...(.......L...............................................n....`......................................... l.......p..P...............P....l.../......,...@d...............................c..@............`.. ............................text....G.......H.................. ..`.rdata..h....`.......L..............@..@.data................b..............@....pdata..P............d..............@..@.reloc..,............j..............@..B................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):792856
                                                                                                                                                                                                            Entropy (8bit):5.57949182561317
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12288:7LN1sdyIzHHZp5c3nlUa6lxzAG11rbmFe9Xbv:7LgfzH5I3nlUa2AU2Fe9Xbv
                                                                                                                                                                                                            MD5:4FF168AAA6A1D68E7957175C8513F3A2
                                                                                                                                                                                                            SHA1:782F886709FEBC8C7CEBCEC4D92C66C4D5DBCF57
                                                                                                                                                                                                            SHA-256:2E4D35B681A172D3298CAF7DC670451BE7A8BA27C26446EFC67470742497A950
                                                                                                                                                                                                            SHA-512:C372B759B8C7817F2CBB78ECCC5A42FA80BDD8D549965BD925A97C3EEBDCE0335FBFEC3995430064DEAD0F4DB68EBB0134EB686A0BE195630C49F84B468113E3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........l.>..|m..|m..|m.u.m..|m+.}l..|m.u}l..|m+..l..|m+.xl..|m+.yl..|m..}l..|m..}m..|m..xl..|m..|l..|m...m..|m..~l..|mRich..|m................PE..d......f.........." ...(.>..........K........................................0......!+....`..........................................x...Q..............s.... ...M......./......d...p...8...............................@............................................text....<.......>.................. ..`.rdata..hz...P...|...B..............@..@.data...qN.......H..................@....pdata..pV... ...X..................@..@.idata...c.......d...^..............@..@.00cfg..u...........................@..@.rsrc...s...........................@..@.reloc..C...........................@..B........................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):201496
                                                                                                                                                                                                            Entropy (8bit):6.37966632089213
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3072:gLWGOBH4P4xPmoeIUBEfZp6fcZW9i4pBgSdQn5UbLiiZcAAn7FJX7r5IvLh8N:1BH4PkPmoeIUKfZp6fceqmQ5U4Nr/
                                                                                                                                                                                                            MD5:B34CA0FCD5E0E4F060FE211273AC2946
                                                                                                                                                                                                            SHA1:F7E978EB8ADDA4BF74739EF71901E0E3AA12EA8C
                                                                                                                                                                                                            SHA-256:B6670D91A76E9F00609752AB19AAE0B1EBE00D24D9D8D22068989BBB24D0AA44
                                                                                                                                                                                                            SHA-512:010774770DD5C4355C336ECE7BFB729D2E616BBA62BFB9961324D3B314396F1F535B5ADF50621BFC0517C03587C912568E19602173A43F297A5F638AA9296500
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........1...P..P..P..(t..P.....P.....P.....P.....P....P.(..P..P.P....P....P.....P....P.Rich.P.........PE..d....g.f.........." ...)............p........................................ ......s.....`.............................................P................................/..........`4..T........................... 3..@............ ...............................text............................... ..`.rdata...... ......................@..@.data...p ..........................@....pdata..............................@..@.rsrc...............................@..@.reloc..............................@..B................................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):68376
                                                                                                                                                                                                            Entropy (8bit):6.149720380115211
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:XV1EbYGVXq6KC/prVHBN0cW18itCQDFPnOMFn+gikF/nFX14uewjBcCCC0yamM/c:XDmF61JFn+/Oi5IvL0b7Sykxr
                                                                                                                                                                                                            MD5:2E2BB725B92A3D30B1E42CC43275BB7B
                                                                                                                                                                                                            SHA1:83AF34FB6BBB3E24FF309E3EBC637DD3875592A5
                                                                                                                                                                                                            SHA-256:D52BACA085F88B40F30C855E6C55791E5375C80F60F94057061E77E33F4CAD7A
                                                                                                                                                                                                            SHA-512:E4A500287F7888B1935DF40FD0D0F303B82CBCF0D5621592805F3BB507E8EE8DE6B51BA2612500838D653566FAD18A04F76322C3AB405CE2FDBBEFB5AB89069E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......%?..a^e.a^e.a^e.).m.`^e.).e.`^e.)..`^e.).g.`^e.Richa^e.........PE..d....g.f.........." ...)............................................................'.....`.........................................`...H................................/..............T............................................................................rdata..............................@..@.rsrc...............................@..@................................................................................................................................................................................................................................................................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):6916376
                                                                                                                                                                                                            Entropy (8bit):5.766275790250782
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:49152:YeceS1L2qpQvgBciWdyVahNTjy8VtvUt1wX/n8gRymPMVTBl2XhXNtMH2lt6cSA/:+RzBHWwuVGij3vwHDMiEHtSzW
                                                                                                                                                                                                            MD5:B243D61F4248909BC721674D70A633DE
                                                                                                                                                                                                            SHA1:1D2FB44B29C4AC3CFD5A7437038A0C541FCE82FC
                                                                                                                                                                                                            SHA-256:93488FA7E631CC0A2BD808B9EEE8617280EE9B6FF499AB424A1A1CBF24D77DC7
                                                                                                                                                                                                            SHA-512:10460C443C7B9A6D7E39AD6E2421B8CA4D8329F1C4A0FF5B71CE73352D2E9438D45F7D59EDB13CE30FAD3B4F260BD843F4D9B48522D448310D43E0988E075FCB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........>._..._..._......_....|.._......_......_......_...'..._...'..._..._...^.....B_......_....~.._......_..Rich._..................PE..d....g.f.........." ...)..'...B......h.......................................Pj......"j...`..........................................<N.......O.......h......._.8J...Zi../....h..Z..0u2.T....................qH.(....s2.@.............(..............................text.....'.......'................. ..`.rdata...0'...(..2'...'.............@..@.data....H...@O.......O.............@....pdata..8J...._..L....^.............@..@PyRuntimh.....a.......`.............@....rsrc.........h.......g.............@..@.reloc...Z....h..\....g.............@..B................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):31000
                                                                                                                                                                                                            Entropy (8bit):6.555355105424351
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:TRVBP9tKLhuosHfwTgDo90Y5IvQGsHQIYiSy1pCQzpuKAM+o/8E9VF0Ny33H:5FyMHfv2H5IvQGW5YiSyvIKAMxkEtH
                                                                                                                                                                                                            MD5:7E871444CA23860A25B888EE263E2EAF
                                                                                                                                                                                                            SHA1:AA43C9D3ABDB1AABDA8379F301F8116D0674B590
                                                                                                                                                                                                            SHA-256:DCA5E6D39C5094CE599143CB82F6D8470F0C2A4CE4443499E73F32ED13333FD0
                                                                                                                                                                                                            SHA-512:2E260D3123F7CA612901513B90FE40739E85248DA913297D4CCA3B2EBD398D9697880D148830E168E474EBFC3D30EDE10668C7316ED7668F8B39DA7BCA59E57D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........tV..'V..'V..'_.j'T..'F:.&T..'F:.&R..'F:.&^..'F:.&Z..'.;.&T..'V..'...'...&S..'.;.&W..'.;.&W..'.;.'W..'.;.&W..'RichV..'................PE..d....g.f.........." ...).....2......................................................fT....`..........................................@..L...<A..x....p.......`.......J.../......L....3..T............................2..@............0...............................text............................... ..`.rdata.......0......................@..@.data...`....P.......8..............@....pdata.......`.......:..............@..@.rsrc........p.......>..............@..@.reloc..L............H..............@..B........................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7634
                                                                                                                                                                                                            Entropy (8bit):4.503638339817033
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:qnJvhVL0qhYqlpIle4RrJQSqOBng4kS/cKM6b:4vjxhYWpce48engvK
                                                                                                                                                                                                            MD5:8466CFC6533376D42EFA6F7423F2B8E8
                                                                                                                                                                                                            SHA1:2BC8926FDBB07DB2AF0A8E3FF7A3BE545C8BDF6B
                                                                                                                                                                                                            SHA-256:ADE78D04982D69972D444A8E14A94F87A2334DD3855CC80348EA8E240AA0DF2D
                                                                                                                                                                                                            SHA-512:CC45DC470E107E63659B502F77E9EF44335F9427BE87639252D85181A8DEA65FA9D1B5F1BD196F782186BC61B144467888199537806A8CC15E2B462CAC0D46A5
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:GNU LESSER GENERAL PUBLIC LICENSE. Version 3, 29 June 2007.. Copyright (C) 2007 Free Software Foundation, Inc. <https://fsf.org/>. Everyone is permitted to copy and distribute verbatim copies. of this license document, but changing it is not allowed.... This version of the GNU Lesser General Public License incorporates.the terms and conditions of version 3 of the GNU General Public.License, supplemented by the additional permissions listed below... 0. Additional Definitions... As used herein, "this License" refers to version 3 of the GNU Lesser.General Public License, and the "GNU GPL" refers to version 3 of the GNU.General Public License... "The Library" refers to a covered work governed by this License,.other than an Application or a Combined Work as defined below... An "Application" is any work that makes use of an interface provided.by the Library, but which is not otherwise based on the Library..Defining a subclass of a class defined by the Library is de
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Python script, ASCII text executable, with very long lines (855)
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):15006
                                                                                                                                                                                                            Entropy (8bit):4.800156894367144
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:S037UxjwUbQd1Ak++k59jg8dXRNInXF2IOxcme+kQBd9Clb:d37U1LbQd1Z+3e8dhwXFacb+kQjQb
                                                                                                                                                                                                            MD5:542BA4FBC993C39A0BC952BE72E8717F
                                                                                                                                                                                                            SHA1:4310DB58F98C12B23286E5FA37F0E27ABEFB6A4A
                                                                                                                                                                                                            SHA-256:3800D9B91DCEEA2065A6ED6279383362E97AC38B8E56B9343F404EE531860099
                                                                                                                                                                                                            SHA-512:E3672EA056E5F2EFD3685C98DC0CF47E9A44F5A84DC457FC8AB31CD6DE09559C6E566D2D00F5B3CE55511E81A050DBB0DED6CF941916A6FF1019392FD96E1636
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:Metadata-Version: 2.1.Name: autocommand.Version: 2.2.2.Summary: A library to create a command-line program from a function.Home-page: https://github.com/Lucretiel/autocommand.Author: Nathan West.License: LGPLv3.Project-URL: Homepage, https://github.com/Lucretiel/autocommand.Project-URL: Bug Tracker, https://github.com/Lucretiel/autocommand/issues.Platform: any.Classifier: Development Status :: 6 - Mature.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: GNU Lesser General Public License v3 (LGPLv3).Classifier: Programming Language :: Python.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3 :: Only.Classifier: Topic :: Software Development.Classifier: Topic :: Software Development :: Libraries.Classifier: Topic :: Software Development :: Libraries :: Python Modules.Requires-Python: >=3.7.Description-Content-Type: text/markdown.License-File: LICENSE..[![PyPI version](https://badge.fury.io/py/autocommand.svg)](
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1308
                                                                                                                                                                                                            Entropy (8bit):5.721750099226425
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:kn/2zDcMvX4owkE+RlpGUttyvUMDtuH5p4D127cyOMT34:knuXNv4LkEMl0UWMF5p45AcuT34
                                                                                                                                                                                                            MD5:52BF4937018B88B9D28ED98A76B5E2AC
                                                                                                                                                                                                            SHA1:C8D5B732C154A2D4D501454647FAFEB356B93C4E
                                                                                                                                                                                                            SHA-256:822BBA66B41526FA547186B80221F85DA50D652BEE5493DBFE5D14085112F0C3
                                                                                                                                                                                                            SHA-512:30E4DEFE09FB8907166682F9A33E0F7CC0203B65113155BBEC6548A1EADF7250882AF295FF2551803703274F9F387E00439D95CBBCB63D2E04E371B94556B3EE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:autocommand-2.2.2.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..autocommand-2.2.2.dist-info/LICENSE,sha256=reeNBJgtaZctREqOFKlPh6IzTdOFXMgDSOqOJAqg3y0,7634..autocommand-2.2.2.dist-info/METADATA,sha256=OADZuR3O6iBlpu1ieTgzYul6w4uOVrk0P0BO5TGGAJk,15006..autocommand-2.2.2.dist-info/RECORD,,..autocommand-2.2.2.dist-info/WHEEL,sha256=2wepM1nk4DS4eFpYrW1TTqPcoGNfHhhO_i5m4cOimbo,92..autocommand-2.2.2.dist-info/top_level.txt,sha256=AzfhgKKS8EdAwWUTSF8mgeVQbXOY9kokHB6kSqwwqu0,12..autocommand/__init__.py,sha256=zko5Rnvolvb-UXjCx_2ArPTGBWwUK5QY4LIQIKYR7As,1037..autocommand/__pycache__/__init__.cpython-312.pyc,,..autocommand/__pycache__/autoasync.cpython-312.pyc,,..autocommand/__pycache__/autocommand.cpython-312.pyc,,..autocommand/__pycache__/automain.cpython-312.pyc,,..autocommand/__pycache__/autoparse.cpython-312.pyc,,..autocommand/__pycache__/errors.cpython-312.pyc,,..autocommand/autoasync.py,sha256=AMdyrxNS4pqWJfP_xuoOcImOHWD-qT7x06wmKN1Vp-U,5680..autocommand/autoco
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):92
                                                                                                                                                                                                            Entropy (8bit):4.842566724466667
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeX7MWcSlViJR4KgP+tPCCfA5S:RtBMwlVifAWBBf
                                                                                                                                                                                                            MD5:88F09A0EC874FD86ABCB9BC4E265B874
                                                                                                                                                                                                            SHA1:786AB44FFD2F5C632B4DC5C1BF4AA2E91E579A05
                                                                                                                                                                                                            SHA-256:DB07A93359E4E034B8785A58AD6D534EA3DCA0635F1E184EFE2E66E1C3A299BA
                                                                                                                                                                                                            SHA-512:7FFEF1EC782D590D2879294C2895A5A8064ECD5FE7243CF602FCCE66A8A715F64436F17CE96070B613123847EE0C18AB0AA5BC87DB13E98A792DC07DD95E4BAB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: bdist_wheel (0.38.4).Root-Is-Purelib: true.Tag: py3-none-any..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):12
                                                                                                                                                                                                            Entropy (8bit):3.084962500721156
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:5EEln:aM
                                                                                                                                                                                                            MD5:C3FBD7931840D987F261BEBA8C77C4D2
                                                                                                                                                                                                            SHA1:F7EE740BCB5C39966173CC377817A157D55844F7
                                                                                                                                                                                                            SHA-256:0337E180A292F04740C16513485F2681E5506D7398F64A241C1EA44AAC30AAED
                                                                                                                                                                                                            SHA-512:E1FA2DE0EE416AE68C57A0173C82D42A8F24DDD1E5143A1B76A3743B5EC3DDF11FB3950F27469D3D8FCAC4958CE267A7321D2F888671EDD7C2E95D0F3F8F7455
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:autocommand.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1023
                                                                                                                                                                                                            Entropy (8bit):5.059832621894572
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:OrmJHcwH0MP3gt8Hw1hj9QHOsUv4eOk4/+/m3oqMSFJ:OaJ8YHvEH5QHOs5exm3oEFJ
                                                                                                                                                                                                            MD5:141643E11C48898150DAA83802DBC65F
                                                                                                                                                                                                            SHA1:0445ED0F69910EEAEE036F09A39A13C6E1F37E12
                                                                                                                                                                                                            SHA-256:86DA0F01AEAE46348A3C3D465195DC1CECCDE79F79E87769A64B8DA04B2A4741
                                                                                                                                                                                                            SHA-512:EF62311602B466397BAF0B23CACA66114F8838F9E78E1B067787CEB709D09E0530E85A47BBCD4C5A0905B74FDB30DF0CC640910C6CC2E67886E5B18794A3583F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to.deal in the Software without restriction, including without limitation the.rights to use, copy, modify, merge, publish, distribute, sublicense, and/or.sell copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING.FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEA
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2020
                                                                                                                                                                                                            Entropy (8bit):5.0469065437932175
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:DfdqaaC3P1xe9okGw1w8wQwywbM0kvsJib0ts++kv0gMzvy0htC+heU01:DfdqaaC/12G2bHZokO+/36
                                                                                                                                                                                                            MD5:18B352E2051962B9F65C33BC651426BF
                                                                                                                                                                                                            SHA1:3DD8D93CF7695D1C9D7574751AB5B0DEE5DD7F9A
                                                                                                                                                                                                            SHA-256:8215C54EAD77D9DC5A108A25C6BDC72B5999AA6F62C9499A440359412AFA5A51
                                                                                                                                                                                                            SHA-512:D966BC2899079C0D9AC763C96EA59A550E00A54BDCEEB6D96B0A8CAA9F6A1C408E7E3946915432978EDE9EDF669EEC68035A55B094B69671A28428458760D99E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Metadata-Version: 2.1.Name: backports.tarfile.Version: 1.2.0.Summary: Backport of CPython tarfile module.Author-email: "Jason R. Coombs" <jaraco@jaraco.com>.Project-URL: Homepage, https://github.com/jaraco/backports.tarfile.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: MIT License.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3 :: Only.Requires-Python: >=3.8.Description-Content-Type: text/x-rst.License-File: LICENSE.Provides-Extra: docs.Requires-Dist: sphinx >=3.5 ; extra == 'docs'.Requires-Dist: jaraco.packaging >=9.3 ; extra == 'docs'.Requires-Dist: rst.linker >=1.9 ; extra == 'docs'.Requires-Dist: furo ; extra == 'docs'.Requires-Dist: sphinx-lint ; extra == 'docs'.Provides-Extra: testing.Requires-Dist: pytest !=8.1.*,>=6 ; extra == 'testing'.Requires-Dist: pytest-checkdocs >=2.4 ; extra == 'testing'.Requires-Dist: pytest-cov ; extra == 'testing
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1360
                                                                                                                                                                                                            Entropy (8bit):5.753738299642538
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:U6rn/2zDJ6rvbqfuG6rJnB6rU6rEsJYB6rXamx6rlCHmTKjaQliwxJlp5DQljQls:NnuXIzUurJwN5JjfAlqYK9liSlp5DQlP
                                                                                                                                                                                                            MD5:CF347AE8E31132435B127226F358F8CD
                                                                                                                                                                                                            SHA1:2C857B300638FF291651234BBB2C077BEEF494E4
                                                                                                                                                                                                            SHA-256:258A1F1C849E1175069A55A5D6CE357AFDD04E34CD5DE27093E4ACEC7A9D2CE1
                                                                                                                                                                                                            SHA-512:2A46C7FDFA2F9883BB1D761646B33BE9CE7B07280A5BF38992C1C84AB0449944EB0CAF34620CCC82DDBBC193F0D54AE67797D97863F70CA0C24EE55A3B401F9C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:backports.tarfile-1.2.0.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..backports.tarfile-1.2.0.dist-info/LICENSE,sha256=htoPAa6uRjSKPD1GUZXcHOzN55956HdppkuNoEsqR0E,1023..backports.tarfile-1.2.0.dist-info/METADATA,sha256=ghXFTq132dxaEIolxr3HK1mZqm9iyUmaRANZQSr6WlE,2020..backports.tarfile-1.2.0.dist-info/RECORD,,..backports.tarfile-1.2.0.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..backports.tarfile-1.2.0.dist-info/WHEEL,sha256=GJ7t_kWBFywbagK5eo9IoUwLW6oyOeTKmQ-9iHFVNxQ,92..backports.tarfile-1.2.0.dist-info/top_level.txt,sha256=cGjaLMOoBR1FK0ApojtzWVmViTtJ7JGIK_HwXiEsvtU,10..backports/__init__.py,sha256=iOEMwnlORWezdO8-2vxBIPSR37D7JGjluZ8f55vzxls,81..backports/__pycache__/__init__.cpython-312.pyc,,..backports/tarfile/__init__.py,sha256=Pwf2qUIfB0SolJPCKcx3vz3UEu_aids4g4sAfxy94qg,108491..backports/tarfile/__main__.py,sha256=Yw2oGT1afrz2eBskzdPYL8ReB_3liApmhFkN2EbDmc4,59..backports/tarfile/__pycache__/__init__.cpython-312.pyc,,..back
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):92
                                                                                                                                                                                                            Entropy (8bit):4.812622295095324
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeX7MWcSlVlFxP+tPCCfA5S:RtBMwlVTxWBBf
                                                                                                                                                                                                            MD5:43136DDE7DD276932F6197BB6D676EF4
                                                                                                                                                                                                            SHA1:6B13C105452C519EA0B65AC1A975BD5E19C50122
                                                                                                                                                                                                            SHA-256:189EEDFE4581172C1B6A02B97A8F48A14C0B5BAA3239E4CA990FBD8871553714
                                                                                                                                                                                                            SHA-512:E7712BA7D36DEB083EBCC3B641AD3E7D19FB071EE64AE3A35AD6A50EE882B20CD2E60CA1319199DF12584FE311A6266EC74F96A3FB67E59F90C7B5909668AEE1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: bdist_wheel (0.43.0).Root-Is-Purelib: true.Tag: py3-none-any..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):10
                                                                                                                                                                                                            Entropy (8bit):3.321928094887362
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:21v:ev
                                                                                                                                                                                                            MD5:9BA458821AD258B6EF62B47E91302982
                                                                                                                                                                                                            SHA1:9EDB9E6BA5C4001CE2FCCF328739292404EA9604
                                                                                                                                                                                                            SHA-256:7068DA2CC3A8051D452B4029A23B73595995893B49EC91882BF1F05E212CBED5
                                                                                                                                                                                                            SHA-512:3A296E5DADD5B406330BA088BFED33BE6960F8FF42DB6651E185FF14F2272FC819EF520D1A15BC40DA4E20B9CA0E5D79170EDF33F3D50937C7FBEDB338CAC730
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:backports.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):11358
                                                                                                                                                                                                            Entropy (8bit):4.4267168336581415
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:nU6G5KXSD9VYUKhu1JVF9hFGvV/QiGkS594drFjuHYx5dvTrLh3kTSEn7HbHR:U9vlKM1zJlFvmNz5VrlkTS07Ht
                                                                                                                                                                                                            MD5:3B83EF96387F14655FC854DDC3C6BD57
                                                                                                                                                                                                            SHA1:2B8B815229AA8A61E483FB4BA0588B8B6C491890
                                                                                                                                                                                                            SHA-256:CFC7749B96F63BD31C3C42B5C471BF756814053E847C10F3EB003417BC523D30
                                                                                                                                                                                                            SHA-512:98F6B79B778F7B0A15415BD750C3A8A097D650511CB4EC8115188E115C47053FE700F578895C097051C9BC3DFB6197C2B13A15DE203273E1A3218884F86E90E8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:. Apache License. Version 2.0, January 2004. http://www.apache.org/licenses/.. TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION.. 1. Definitions... "License" shall mean the terms and conditions for use, reproduction,. and distribution as defined by Sections 1 through 9 of this document... "Licensor" shall mean the copyright owner or entity authorized by. the copyright owner that is granting the License... "Legal Entity" shall mean the union of the acting entity and all. other entities that control, are controlled by, or are under common. control with that entity. For the purposes of this definition,. "control" means (i) the power, direct or indirect, to cause the. direction or management of such entity, whether by contract or. otherwise, or (ii) ownership of fifty percent (50%) or more of the. outstanding shares, or (iii) beneficial own
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4648
                                                                                                                                                                                                            Entropy (8bit):5.006900644756252
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:Dx2ZSaCSmS8R902Vpnu386eLQ9Ac+fFZpDN00x2jZ2SBXZJSwTE:9Smzf02Vpnu386mQ9B+TP0vJHJSwTE
                                                                                                                                                                                                            MD5:98ABEAACC0E0E4FC385DFF67B607071A
                                                                                                                                                                                                            SHA1:E8C830D8B0942300C7C87B3B8FD15EA1396E07BD
                                                                                                                                                                                                            SHA-256:6A7B90EFFEE1E09D5B484CDF7232016A43E2D9CC9543BCBB8E494B1EC05E1F59
                                                                                                                                                                                                            SHA-512:F1D59046FFA5B0083A5259CEB03219CCDB8CC6AAC6247250CBD83E70F080784391FCC303F7630E1AD40E5CCF5041A57CB9B68ADEFEC1EBC6C31FCF7FFC65E9B7
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Metadata-Version: 2.1.Name: importlib_metadata.Version: 8.0.0.Summary: Read metadata from Python packages.Author-email: "Jason R. Coombs" <jaraco@jaraco.com>.Project-URL: Source, https://github.com/python/importlib_metadata.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: Apache Software License.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3 :: Only.Requires-Python: >=3.8.Description-Content-Type: text/x-rst.License-File: LICENSE.Requires-Dist: zipp >=0.5.Requires-Dist: typing-extensions >=3.6.4 ; python_version < "3.8".Provides-Extra: doc.Requires-Dist: sphinx >=3.5 ; extra == 'doc'.Requires-Dist: jaraco.packaging >=9.3 ; extra == 'doc'.Requires-Dist: rst.linker >=1.9 ; extra == 'doc'.Requires-Dist: furo ; extra == 'doc'.Requires-Dist: sphinx-lint ; extra == 'doc'.Requires-Dist: jaraco.tidelift >=1.4 ; extra == 'doc'.Provides-Extra: perf.Requires-D
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2518
                                                                                                                                                                                                            Entropy (8bit):5.6307766747793275
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:UnuXTg06U5J/Vw9l/gfNX7/XzBk9pvJq/fwJOfYrBfnJ/V0XJnzN/3WJV:bXzP/EgdzzBkDJsoIYrBfJ/CXNz9qV
                                                                                                                                                                                                            MD5:EB513CAFA5226DDA7D54AFDCC9AD8A74
                                                                                                                                                                                                            SHA1:B394C7AEC158350BAF676AE3197BEF4D7158B31C
                                                                                                                                                                                                            SHA-256:0D8D3C6EEB9EBBE86CAC7D60861552433C329DA9EA51248B61D02BE2E5E64030
                                                                                                                                                                                                            SHA-512:A0017CFAFF47FDA6067E3C31775FACEE4728C3220C2D4BD70DEF328BD20AA71A343E39DA15CD6B406F62311894C518DFCF5C8A4AE6F853946F26A4B4E767924E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:importlib_metadata-8.0.0.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..importlib_metadata-8.0.0.dist-info/LICENSE,sha256=z8d0m5b2O9McPEK1xHG_dWgUBT6EfBDz6wA0F7xSPTA,11358..importlib_metadata-8.0.0.dist-info/METADATA,sha256=anuQ7_7h4J1bSEzfcjIBakPi2cyVQ7y7jklLHsBeH1k,4648..importlib_metadata-8.0.0.dist-info/RECORD,,..importlib_metadata-8.0.0.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..importlib_metadata-8.0.0.dist-info/WHEEL,sha256=mguMlWGMX-VHnMpKOjjQidIo1ssRlCFu4a4mBpz1s2M,91..importlib_metadata-8.0.0.dist-info/top_level.txt,sha256=CO3fD9yylANiXkrMo4qHLV_mqXL2sC5JFKgt1yWAT-A,19..importlib_metadata/__init__.py,sha256=tZNB-23h8Bixi9uCrQqj9Yf0aeC--Josdy3IZRIQeB0,33798..importlib_metadata/__pycache__/__init__.cpython-312.pyc,,..importlib_metadata/__pycache__/_adapters.cpython-312.pyc,,..importlib_metadata/__pycache__/_collections.cpython-312.pyc,,..importlib_metadata/__pycache__/_compat.cpython-312.pyc,,..importlib_metadata/__pycac
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):91
                                                                                                                                                                                                            Entropy (8bit):4.687870576189661
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeXMRYFAVLMvhRRP+tPCCfA5S:RtC1VLMvhjWBBf
                                                                                                                                                                                                            MD5:7D09837492494019EA51F4E97823D79F
                                                                                                                                                                                                            SHA1:7829B4324BB542799494131A270EC3BDAD4DEDEF
                                                                                                                                                                                                            SHA-256:9A0B8C95618C5FE5479CCA4A3A38D089D228D6CB1194216EE1AE26069CF5B363
                                                                                                                                                                                                            SHA-512:A0063220ECDD22C3E735ACFF6DE559ACF3AC4C37B81D37633975A22A28B026F1935CD1957C0FF7D2ECC8B7F83F250310795EECC5273B893FFAB115098F7B9C38
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: setuptools (70.1.1).Root-Is-Purelib: true.Tag: py3-none-any..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):19
                                                                                                                                                                                                            Entropy (8bit):3.536886723742169
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:JSej0EBERG:50o4G
                                                                                                                                                                                                            MD5:A24465F7850BA59507BF86D89165525C
                                                                                                                                                                                                            SHA1:4E61F9264DE74783B5924249BCFE1B06F178B9AD
                                                                                                                                                                                                            SHA-256:08EDDF0FDCB29403625E4ACCA38A872D5FE6A972F6B02E4914A82DD725804FE0
                                                                                                                                                                                                            SHA-512:ECF1F6B777970F5257BDDD353305447083008CEBD8E5A27C3D1DA9C7BDC3F9BF3ABD6881265906D6D5E11992653185C04A522F4DB5655FF75EEDB766F93D5D48
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:importlib_metadata.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):11358
                                                                                                                                                                                                            Entropy (8bit):4.4267168336581415
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:nU6G5KXSD9VYUKhu1JVF9hFGvV/QiGkS594drFjuHYx5dvTrLh3kTSEn7HbHR:U9vlKM1zJlFvmNz5VrlkTS07Ht
                                                                                                                                                                                                            MD5:3B83EF96387F14655FC854DDC3C6BD57
                                                                                                                                                                                                            SHA1:2B8B815229AA8A61E483FB4BA0588B8B6C491890
                                                                                                                                                                                                            SHA-256:CFC7749B96F63BD31C3C42B5C471BF756814053E847C10F3EB003417BC523D30
                                                                                                                                                                                                            SHA-512:98F6B79B778F7B0A15415BD750C3A8A097D650511CB4EC8115188E115C47053FE700F578895C097051C9BC3DFB6197C2B13A15DE203273E1A3218884F86E90E8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:. Apache License. Version 2.0, January 2004. http://www.apache.org/licenses/.. TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION.. 1. Definitions... "License" shall mean the terms and conditions for use, reproduction,. and distribution as defined by Sections 1 through 9 of this document... "Licensor" shall mean the copyright owner or entity authorized by. the copyright owner that is granting the License... "Legal Entity" shall mean the union of the acting entity and all. other entities that control, are controlled by, or are under common. control with that entity. For the purposes of this definition,. "control" means (i) the power, direct or indirect, to cause the. direction or management of such entity, whether by contract or. otherwise, or (ii) ownership of fifty percent (50%) or more of the. outstanding shares, or (iii) beneficial own
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3944
                                                                                                                                                                                                            Entropy (8bit):5.015824473130961
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:DHxQuiTaCP1nTGDbHRbnzQWHaiQq+fT5lWp8sSwTW:2PP9GDbHRbnp+rapPSwTW
                                                                                                                                                                                                            MD5:C3EB48CD13B50DDED7CD524E1E9DD4CE
                                                                                                                                                                                                            SHA1:7C9B0B50D0E667825DAB09902AD8376A5F2945B6
                                                                                                                                                                                                            SHA-256:83878CD8BB8BD0E89971454D0F4AB00C9529136F603AFB4EDC148F5D36CEF459
                                                                                                                                                                                                            SHA-512:056EBC250B7E82F91B5C5E96B1293F24D5E917E06846A9716A4D05B47C30FEB3781E439C77876CF7D8620BEBAA4A253039CA8DF122283DE304992E340F4DE8BF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Metadata-Version: 2.1.Name: importlib_resources.Version: 6.4.0.Summary: Read resources from Python packages.Home-page: https://github.com/python/importlib_resources.Author: Barry Warsaw.Author-email: barry@python.org.Project-URL: Documentation, https://importlib-resources.readthedocs.io/.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: Apache Software License.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3 :: Only.Requires-Python: >=3.8.License-File: LICENSE.Requires-Dist: zipp >=3.1.0 ; python_version < "3.10".Provides-Extra: docs.Requires-Dist: sphinx >=3.5 ; extra == 'docs'.Requires-Dist: sphinx <7.2.5 ; extra == 'docs'.Requires-Dist: jaraco.packaging >=9.3 ; extra == 'docs'.Requires-Dist: rst.linker >=1.9 ; extra == 'docs'.Requires-Dist: furo ; extra == 'docs'.Requires-Dist: sphinx-lint ; extra == 'docs'.Requires-Dist: jaraco.tidelift >=1.4 ; ext
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7620
                                                                                                                                                                                                            Entropy (8bit):5.560551717923108
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:lX7qdX7ZgsP7JtILSVAn5V26+XuVYmBXx:lX7wX7ZBP7ELSVAni6+iBh
                                                                                                                                                                                                            MD5:67F5E26385B6BDCF2236A005A2D2BA32
                                                                                                                                                                                                            SHA1:3DCD8685638A90D121FD484138AFCAC9775E5D66
                                                                                                                                                                                                            SHA-256:967DD56FEEA143F1D2C4E98AC1F937C055E61C9AA0425146D55F7AD7C82510FA
                                                                                                                                                                                                            SHA-512:30B5812E930A00A476E570EBCC4611D54C911A8B1E4646949A887F551FC5ABDC933311A554B197C602F0DA7626DFE8877A3F267EFBC6D724E24A3E9B5FCC2E30
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:importlib_resources-6.4.0.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..importlib_resources-6.4.0.dist-info/LICENSE,sha256=z8d0m5b2O9McPEK1xHG_dWgUBT6EfBDz6wA0F7xSPTA,11358..importlib_resources-6.4.0.dist-info/METADATA,sha256=g4eM2LuL0OiZcUVND0qwDJUpE29gOvtO3BSPXTbO9Fk,3944..importlib_resources-6.4.0.dist-info/RECORD,,..importlib_resources-6.4.0.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..importlib_resources-6.4.0.dist-info/WHEEL,sha256=GJ7t_kWBFywbagK5eo9IoUwLW6oyOeTKmQ-9iHFVNxQ,92..importlib_resources-6.4.0.dist-info/top_level.txt,sha256=fHIjHU1GZwAjvcydpmUnUrTnbvdiWjG4OEVZK8by0TQ,20..importlib_resources/__init__.py,sha256=uyp1kzYR6SawQBsqlyaXXfIxJx4Z2mM8MjmZn8qq2Gk,505..importlib_resources/__pycache__/__init__.cpython-312.pyc,,..importlib_resources/__pycache__/_adapters.cpython-312.pyc,,..importlib_resources/__pycache__/_common.cpython-312.pyc,,..importlib_resources/__pycache__/_itertools.cpython-312.pyc,,..importlib_resource
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):92
                                                                                                                                                                                                            Entropy (8bit):4.812622295095324
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeX7MWcSlVlFxP+tPCCfA5S:RtBMwlVTxWBBf
                                                                                                                                                                                                            MD5:43136DDE7DD276932F6197BB6D676EF4
                                                                                                                                                                                                            SHA1:6B13C105452C519EA0B65AC1A975BD5E19C50122
                                                                                                                                                                                                            SHA-256:189EEDFE4581172C1B6A02B97A8F48A14C0B5BAA3239E4CA990FBD8871553714
                                                                                                                                                                                                            SHA-512:E7712BA7D36DEB083EBCC3B641AD3E7D19FB071EE64AE3A35AD6A50EE882B20CD2E60CA1319199DF12584FE311A6266EC74F96A3FB67E59F90C7B5909668AEE1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: bdist_wheel (0.43.0).Root-Is-Purelib: true.Tag: py3-none-any..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):20
                                                                                                                                                                                                            Entropy (8bit):3.6841837197791887
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:JSe8AW6D:3fD
                                                                                                                                                                                                            MD5:0613840F692BD9E064FEDD915DFD477A
                                                                                                                                                                                                            SHA1:64DF38B36F541BA1714C15FCA1A9CA8C94EF2DAA
                                                                                                                                                                                                            SHA-256:7C72231D4D46670023BDCC9DA6652752B4E76EF7625A31B83845592BC6F2D134
                                                                                                                                                                                                            SHA-512:78AA888C24B3468C94FCB8EB882561D4B6F19A0537A4CFDDDFF94ED8A4BAFE8DF0C2B620E70B57A61E8BA3F877856DB9ADA548DFCA8CAE86D4C3C525A4E9B7EB
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:importlib_resources.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1023
                                                                                                                                                                                                            Entropy (8bit):5.059832621894572
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:OrmJHcwH0MP3gt8Hw1hj9QHOsUv4eOk4/+/m3oqMSFJ:OaJ8YHvEH5QHOs5exm3oEFJ
                                                                                                                                                                                                            MD5:141643E11C48898150DAA83802DBC65F
                                                                                                                                                                                                            SHA1:0445ED0F69910EEAEE036F09A39A13C6E1F37E12
                                                                                                                                                                                                            SHA-256:86DA0F01AEAE46348A3C3D465195DC1CECCDE79F79E87769A64B8DA04B2A4741
                                                                                                                                                                                                            SHA-512:EF62311602B466397BAF0B23CACA66114F8838F9E78E1B067787CEB709D09E0530E85A47BBCD4C5A0905B74FDB30DF0CC640910C6CC2E67886E5B18794A3583F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to.deal in the Software without restriction, including without limitation the.rights to use, copy, modify, merge, publish, distribute, sublicense, and/or.sell copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING.FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEA
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):21079
                                                                                                                                                                                                            Entropy (8bit):5.103530371859935
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:12Vpnu38/2K9tjUaNtT/yTCtYTnWDdg3GaXb51KLVgWTVPeEGsuPrAESM:12Vpnu38JZtT/yIdg3D51KLV7RPeEGs+
                                                                                                                                                                                                            MD5:1A287FAF08B125BC7C932AAD05E7DAEE
                                                                                                                                                                                                            SHA1:C37042ADC0D1270485F4B8B5B9E085A274DC035B
                                                                                                                                                                                                            SHA-256:66030D634580651B3E53CC19895D9231F8D22AA06B327817C8332CFC20303308
                                                                                                                                                                                                            SHA-512:D0BB0AD27A17007DF7D3281FB2F46EFB048B69532D082AB1D431E0BA28E592D897687708B4EC972F4BC21EDA29DDDDC9EF44BB950DFC4FFB03EA75CDA4DE414C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Metadata-Version: 2.1.Name: inflect.Version: 7.3.1.Summary: Correctly generate plurals, singular nouns, ordinals, indefinite articles.Author-email: Paul Dyson <pwdyson@yahoo.com>.Maintainer-email: "Jason R. Coombs" <jaraco@jaraco.com>.Project-URL: Source, https://github.com/jaraco/inflect.Keywords: plural,inflect,participle.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: MIT License.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3 :: Only.Classifier: Natural Language :: English.Classifier: Operating System :: OS Independent.Classifier: Topic :: Software Development :: Libraries :: Python Modules.Classifier: Topic :: Text Processing :: Linguistic.Requires-Python: >=3.8.Description-Content-Type: text/x-rst.License-File: LICENSE.Requires-Dist: more-itertools >=8.5.0.Requires-Dist: typeguard >=4.0.1.Requires-Dist: typing-extensions ; python_version < "3.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):943
                                                                                                                                                                                                            Entropy (8bit):5.828988691860191
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:IVn/2zDPvbqfuIpBntmuIcjlM+sVGXdbkDcnJopDvDK16bZWJV:unuXPzUuIpRtmuZjl9sVQgcnJo9bK16E
                                                                                                                                                                                                            MD5:C837BB3258448B7FCC6B77559C7F17B6
                                                                                                                                                                                                            SHA1:B15701449CD64A13756A70AD3704E26DB1FF416B
                                                                                                                                                                                                            SHA-256:5D7834AC1BA2612C6801050FDE57A7B98B0F36ACF88C3C2D4F376FD8911B3091
                                                                                                                                                                                                            SHA-512:2333CD86502C51607414390ECF43BD6D62E863D3DFB0501DAD3A8B45F5F4DFA81F910917183FC4F4A0DEEC82C8F8B3CF8D5B0A2C136DEB164226BABE68B74A33
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:inflect-7.3.1.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..inflect-7.3.1.dist-info/LICENSE,sha256=htoPAa6uRjSKPD1GUZXcHOzN55956HdppkuNoEsqR0E,1023..inflect-7.3.1.dist-info/METADATA,sha256=ZgMNY0WAZRs-U8wZiV2SMfjSKqBrMngXyDMs_CAwMwg,21079..inflect-7.3.1.dist-info/RECORD,,..inflect-7.3.1.dist-info/WHEEL,sha256=y4mX-SOX4fYIkonsAGA5N0Oy-8_gI4FXw5HNI1xqvWg,91..inflect-7.3.1.dist-info/top_level.txt,sha256=m52ujdp10CqT6jh1XQxZT6kEntcnv-7Tl7UiGNTzWZA,8..inflect/__init__.py,sha256=Jxy1HJXZiZ85kHeLAhkmvz6EMTdFqBe-duvt34R6IOc,103796..inflect/__pycache__/__init__.cpython-312.pyc,,..inflect/compat/__init__.py,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..inflect/compat/__pycache__/__init__.cpython-312.pyc,,..inflect/compat/__pycache__/py38.cpython-312.pyc,,..inflect/compat/py38.py,sha256=oObVfVnWX9_OpnOuEJn1mFbJxVhwyR5epbiTNXDDaso,160..inflect/py.typed,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):91
                                                                                                                                                                                                            Entropy (8bit):4.7098485981676825
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeXMRYFAVLKSgP+tPCCfA5S:RtC1VLKZWBBf
                                                                                                                                                                                                            MD5:EB46A94D39AC40E2EEA4A32729E0C8C3
                                                                                                                                                                                                            SHA1:E42EF49A7098269E1934932ECC3174B40967982A
                                                                                                                                                                                                            SHA-256:CB8997F92397E1F6089289EC0060393743B2FBCFE0238157C391CD235C6ABD68
                                                                                                                                                                                                            SHA-512:D89F0DA16AA37AAFAC0DE56A3DFBD72DC3C9DCC53C8E455094E7230DB21ABF95ED76EAC1848A4156DB422B9C10BE136201D871DCCB73AD38192E5536E41DBDFE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: setuptools (70.2.0).Root-Is-Purelib: true.Tag: py3-none-any..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8
                                                                                                                                                                                                            Entropy (8bit):3.0
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:KDpJ:K9J
                                                                                                                                                                                                            MD5:4571281D24750CBE7638EFE250E342AB
                                                                                                                                                                                                            SHA1:61E8A0AD5796F1CA67EAB0D8108A6402483D499B
                                                                                                                                                                                                            SHA-256:9B9DAE8DDA75D02A93EA38755D0C594FA9049ED727BFEED397B52218D4F35990
                                                                                                                                                                                                            SHA-512:E7807002E53CC228D6EFB307E928C6737796B29E31D25A342ED407F556FFBF540494FE92C27B5C31043D2D7FF427C78A29C4FF5595BC11BB643003026642254E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:inflect.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1023
                                                                                                                                                                                                            Entropy (8bit):5.059832621894572
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:OrmJHcwH0MP3gt8Hw1hj9QHOsUv4eOk4/+/m3oqMSFJ:OaJ8YHvEH5QHOs5exm3oEFJ
                                                                                                                                                                                                            MD5:141643E11C48898150DAA83802DBC65F
                                                                                                                                                                                                            SHA1:0445ED0F69910EEAEE036F09A39A13C6E1F37E12
                                                                                                                                                                                                            SHA-256:86DA0F01AEAE46348A3C3D465195DC1CECCDE79F79E87769A64B8DA04B2A4741
                                                                                                                                                                                                            SHA-512:EF62311602B466397BAF0B23CACA66114F8838F9E78E1B067787CEB709D09E0530E85A47BBCD4C5A0905B74FDB30DF0CC640910C6CC2E67886E5B18794A3583F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to.deal in the Software without restriction, including without limitation the.rights to use, copy, modify, merge, publish, distribute, sublicense, and/or.sell copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING.FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEA
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3933
                                                                                                                                                                                                            Entropy (8bit):4.993707893382395
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:D0duaC9zmnEh2S8xI0+4np+A+fbl7inVgQJSwT2:qq9KnEh2zxI0+4npn+zlmn+QJSwT2
                                                                                                                                                                                                            MD5:C9BA49C9B82CEFCCAC79CB5B76BCB1EE
                                                                                                                                                                                                            SHA1:AC0DB25AEFD2679B4C3265E713D00F6155A94465
                                                                                                                                                                                                            SHA-256:20C51A96236C0395F53B1F4C5D458E6A0721E51E16C1BFF733B7ABA76F5D06D8
                                                                                                                                                                                                            SHA-512:563C3BEC6FB8D137357130BADCB63A229A18A781B05E2F006F4A42AF7C9052D23D266908DA2E62FF283C9BA7BAA9B6CB6FB32A1999CB07F63471CA43003A34C0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Metadata-Version: 2.1.Name: jaraco.collections.Version: 5.1.0.Summary: Collection objects similar to those in stdlib by jaraco.Author-email: "Jason R. Coombs" <jaraco@jaraco.com>.Project-URL: Source, https://github.com/jaraco/jaraco.collections.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: MIT License.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3 :: Only.Requires-Python: >=3.8.Description-Content-Type: text/x-rst.License-File: LICENSE.Requires-Dist: jaraco.text.Provides-Extra: check.Requires-Dist: pytest-checkdocs >=2.4 ; extra == 'check'.Requires-Dist: pytest-ruff >=0.2.1 ; (sys_platform != "cygwin") and extra == 'check'.Provides-Extra: cover.Requires-Dist: pytest-cov ; extra == 'cover'.Provides-Extra: doc.Requires-Dist: sphinx >=3.5 ; extra == 'doc'.Requires-Dist: jaraco.packaging >=9.3 ; extra == 'doc'.Requires-Dist: rst.linker >=1.9 ; extra
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):873
                                                                                                                                                                                                            Entropy (8bit):5.770829319764291
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:T9bn/2zDabvbqfunb1AO5bGYbEsJvbp1blKzmKmJaaX9WJV:T9bnuXabzUunb1AgbBb5Jvbp1blscWJV
                                                                                                                                                                                                            MD5:0463062305AC30E7F3D6AB12DA825D90
                                                                                                                                                                                                            SHA1:AC83602461BF535C78EB4CCC13AB103C12110D57
                                                                                                                                                                                                            SHA-256:1E9B62BD70E4A5FA26E9594CBB80860FFECA3DEBFEE8773DAEFA774CD259CA06
                                                                                                                                                                                                            SHA-512:8F617D9A2DA41BDC8591D9EA9F2DBE79D7C5816BA7A94D4044AFF2A0504C9738E83FFCAA350CEF20764D430C261C9DC17DBB5E4ABB7AE54C3BE8715C8AD6BB71
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:jaraco.collections-5.1.0.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..jaraco.collections-5.1.0.dist-info/LICENSE,sha256=htoPAa6uRjSKPD1GUZXcHOzN55956HdppkuNoEsqR0E,1023..jaraco.collections-5.1.0.dist-info/METADATA,sha256=IMUaliNsA5X1Ox9MXUWOagch5R4Wwb_3M7erp29dBtg,3933..jaraco.collections-5.1.0.dist-info/RECORD,,..jaraco.collections-5.1.0.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..jaraco.collections-5.1.0.dist-info/WHEEL,sha256=Mdi9PDNwEZptOjTlUcAth7XJDFtKrHYaQMPulZeBCiQ,91..jaraco.collections-5.1.0.dist-info/top_level.txt,sha256=0JnN3LfXH4LIRfXL-QFOGCJzQWZO3ELx4R1d_louoQM,7..jaraco/collections/__init__.py,sha256=Pc1-SqjWm81ad1P0-GttpkwO_LWlnaY6gUq8gcKh2v0,26640..jaraco/collections/__pycache__/__init__.cpython-312.pyc,,..jaraco/collections/py.typed,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):91
                                                                                                                                                                                                            Entropy (8bit):4.696166043246402
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeXMRYFAWWHKRRP+tPCCfA5S:RtC1qjWBBf
                                                                                                                                                                                                            MD5:6FBE8610D7E48CA32AE774804C4A0B19
                                                                                                                                                                                                            SHA1:102D23C4ECB17ED83A6E43888B45FF2BBFE93E0B
                                                                                                                                                                                                            SHA-256:31D8BD3C3370119A6D3A34E551C02D87B5C90C5B4AAC761A40C3EE9597810A24
                                                                                                                                                                                                            SHA-512:78738099EC5B31FDEE5AE50F7840F17EFD526588835157CADF4249882462B1AF2E3BEDB77801A9FCB1D22A8FD41AA6A934B382F3E66309723D0E7F93C2F2868A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: setuptools (73.0.1).Root-Is-Purelib: true.Tag: py3-none-any..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7
                                                                                                                                                                                                            Entropy (8bit):2.5216406363433186
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:GEG0:GEG0
                                                                                                                                                                                                            MD5:0BA8D736B7B4AB182687318B0497E61E
                                                                                                                                                                                                            SHA1:311BA5FFD098689179F299EF20768EE1A29F586D
                                                                                                                                                                                                            SHA-256:D099CDDCB7D71F82C845F5CBF9014E18227341664EDC42F1E11D5DFE5A2EA103
                                                                                                                                                                                                            SHA-512:7CCCBB4AFA2FADE40D529482301BEAE152E0C71EE3CC41736EB19E35CFC5EE3B91EF958CF5CA6B7330333B8494FEB6682FD833D5AA16BF4A8F1F721FD859832C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:jaraco.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1023
                                                                                                                                                                                                            Entropy (8bit):5.059832621894572
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:OrmJHcwH0MP3gt8Hw1hj9QHOsUv4eOk4/+/m3oqMSFJ:OaJ8YHvEH5QHOs5exm3oEFJ
                                                                                                                                                                                                            MD5:141643E11C48898150DAA83802DBC65F
                                                                                                                                                                                                            SHA1:0445ED0F69910EEAEE036F09A39A13C6E1F37E12
                                                                                                                                                                                                            SHA-256:86DA0F01AEAE46348A3C3D465195DC1CECCDE79F79E87769A64B8DA04B2A4741
                                                                                                                                                                                                            SHA-512:EF62311602B466397BAF0B23CACA66114F8838F9E78E1B067787CEB709D09E0530E85A47BBCD4C5A0905B74FDB30DF0CC640910C6CC2E67886E5B18794A3583F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to.deal in the Software without restriction, including without limitation the.rights to use, copy, modify, merge, publish, distribute, sublicense, and/or.sell copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING.FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEA
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with very long lines (406)
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4020
                                                                                                                                                                                                            Entropy (8bit):4.99859161164956
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:D6P4YaCP1gGRbHneRohWYc+f/PCnG9rulJQ84UNxCUSwTcL:kPqGRbHneRohWJ+XPaqylW/USwTcL
                                                                                                                                                                                                            MD5:812F27A7C8C748351DC1643D58B6B250
                                                                                                                                                                                                            SHA1:AC9C92013B2F0FC65D741B32A9FE4B956DD6EB7D
                                                                                                                                                                                                            SHA-256:C43B60B897A3D2D37D8845C252FC44261D9AEF171E21154111A9012D2AFFFED6
                                                                                                                                                                                                            SHA-512:CAC62C3682F808D85233B69F1C142B5A0E95E316E4BDCBC6EE253583EC302FA42E635BAB6A837327D8CE5D26C08C8DCD9E45D5CFDD8346B4501C473250D66953
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Metadata-Version: 2.1.Name: jaraco.context.Version: 5.3.0.Summary: Useful decorators and context managers.Home-page: https://github.com/jaraco/jaraco.context.Author: Jason R. Coombs.Author-email: jaraco@jaraco.com.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: MIT License.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3 :: Only.Requires-Python: >=3.8.License-File: LICENSE.Requires-Dist: backports.tarfile ; python_version < "3.12".Provides-Extra: docs.Requires-Dist: sphinx >=3.5 ; extra == 'docs'.Requires-Dist: jaraco.packaging >=9.3 ; extra == 'docs'.Requires-Dist: rst.linker >=1.9 ; extra == 'docs'.Requires-Dist: furo ; extra == 'docs'.Requires-Dist: sphinx-lint ; extra == 'docs'.Requires-Dist: jaraco.tidelift >=1.4 ; extra == 'docs'.Provides-Extra: testing.Requires-Dist: pytest !=8.1.1,>=6 ; extra == 'testing'.Requires-Dist: pytest-checkdocs >=2.4
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):641
                                                                                                                                                                                                            Entropy (8bit):5.76835538630355
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:TGA0a/2zDJAv/TnqfQlWJAL/fy9vKAGvAXCaaryBAl2VrkEQCXvbAT2r1S:TBn/2zDCvbqfuLO9FGoXamalKSCXzB1S
                                                                                                                                                                                                            MD5:2B0A77624AE3903E42C3A8213E593796
                                                                                                                                                                                                            SHA1:D63027FF018995D0620E2497BCE9678888A57667
                                                                                                                                                                                                            SHA-256:55197B88A78443297BB2D827A75BAAE740B33896251D872835D4B4C75EC2F57E
                                                                                                                                                                                                            SHA-512:C02FB1554F8F40158BB60F2B4EC07D80F71CFBFFB38463C5809385A7A2FF8DDB2BDFEFE9AE5E67F4DEC3D904A6E0925E565B0EE6363DD0C2ED5B03A96B056B18
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:jaraco.context-5.3.0.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..jaraco.context-5.3.0.dist-info/LICENSE,sha256=htoPAa6uRjSKPD1GUZXcHOzN55956HdppkuNoEsqR0E,1023..jaraco.context-5.3.0.dist-info/METADATA,sha256=xDtguJej0tN9iEXCUvxEJh2a7xceIRVBEakBLSr__tY,4020..jaraco.context-5.3.0.dist-info/RECORD,,..jaraco.context-5.3.0.dist-info/WHEEL,sha256=GJ7t_kWBFywbagK5eo9IoUwLW6oyOeTKmQ-9iHFVNxQ,92..jaraco.context-5.3.0.dist-info/top_level.txt,sha256=0JnN3LfXH4LIRfXL-QFOGCJzQWZO3ELx4R1d_louoQM,7..jaraco/__pycache__/context.cpython-312.pyc,,..jaraco/context.py,sha256=REoLIxDkO5MfEYowt_WoupNCRoxBS5v7YX2PbW8lIcs,9552..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):92
                                                                                                                                                                                                            Entropy (8bit):4.812622295095324
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeX7MWcSlVlFxP+tPCCfA5S:RtBMwlVTxWBBf
                                                                                                                                                                                                            MD5:43136DDE7DD276932F6197BB6D676EF4
                                                                                                                                                                                                            SHA1:6B13C105452C519EA0B65AC1A975BD5E19C50122
                                                                                                                                                                                                            SHA-256:189EEDFE4581172C1B6A02B97A8F48A14C0B5BAA3239E4CA990FBD8871553714
                                                                                                                                                                                                            SHA-512:E7712BA7D36DEB083EBCC3B641AD3E7D19FB071EE64AE3A35AD6A50EE882B20CD2E60CA1319199DF12584FE311A6266EC74F96A3FB67E59F90C7B5909668AEE1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: bdist_wheel (0.43.0).Root-Is-Purelib: true.Tag: py3-none-any..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7
                                                                                                                                                                                                            Entropy (8bit):2.5216406363433186
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:GEG0:GEG0
                                                                                                                                                                                                            MD5:0BA8D736B7B4AB182687318B0497E61E
                                                                                                                                                                                                            SHA1:311BA5FFD098689179F299EF20768EE1A29F586D
                                                                                                                                                                                                            SHA-256:D099CDDCB7D71F82C845F5CBF9014E18227341664EDC42F1E11D5DFE5A2EA103
                                                                                                                                                                                                            SHA-512:7CCCBB4AFA2FADE40D529482301BEAE152E0C71EE3CC41736EB19E35CFC5EE3B91EF958CF5CA6B7330333B8494FEB6682FD833D5AA16BF4A8F1F721FD859832C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:jaraco.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1023
                                                                                                                                                                                                            Entropy (8bit):5.059832621894572
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:OrmJHcwH0MP3gt8Hw1hj9QHOsUv4eOk4/+/m3oqMSFJ:OaJ8YHvEH5QHOs5exm3oEFJ
                                                                                                                                                                                                            MD5:141643E11C48898150DAA83802DBC65F
                                                                                                                                                                                                            SHA1:0445ED0F69910EEAEE036F09A39A13C6E1F37E12
                                                                                                                                                                                                            SHA-256:86DA0F01AEAE46348A3C3D465195DC1CECCDE79F79E87769A64B8DA04B2A4741
                                                                                                                                                                                                            SHA-512:EF62311602B466397BAF0B23CACA66114F8838F9E78E1B067787CEB709D09E0530E85A47BBCD4C5A0905B74FDB30DF0CC640910C6CC2E67886E5B18794A3583F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to.deal in the Software without restriction, including without limitation the.rights to use, copy, modify, merge, publish, distribute, sublicense, and/or.sell copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING.FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEA
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2891
                                                                                                                                                                                                            Entropy (8bit):5.034580807599395
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:DEmbsaC3J1x9Ie9okNGwQw8wQw2wTw0zCPU0+I65Jib0H++kv0gM5d0DT+heU04u:DEmgaCZ1nTGDbHRAnzpI6o+fX5dFSwTm
                                                                                                                                                                                                            MD5:C2E6BDA7F1B03B39BF42D31B6DBF6C38
                                                                                                                                                                                                            SHA1:B7A18F079DE22D10C4C318E54BD8C48177F91333
                                                                                                                                                                                                            SHA-256:8B86946900D7FA38DD1102B9C1EBE17A0CB1F09C8B7E29F61F2BDA4A4DC51ECA
                                                                                                                                                                                                            SHA-512:F4E892B3D41482E3B17642B1D722B6E2A8E8DD4833F0623C29ED2D50D55CFC68DA1F9756B4E08723DC89F3E552424096C92912AC4DA533FE8E2DC59DC19EA9CF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Metadata-Version: 2.1.Name: jaraco.functools.Version: 4.0.1.Summary: Functools like those found in stdlib.Author-email: "Jason R. Coombs" <jaraco@jaraco.com>.Project-URL: Homepage, https://github.com/jaraco/jaraco.functools.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: MIT License.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3 :: Only.Requires-Python: >=3.8.Description-Content-Type: text/x-rst.License-File: LICENSE.Requires-Dist: more-itertools.Provides-Extra: docs.Requires-Dist: sphinx >=3.5 ; extra == 'docs'.Requires-Dist: sphinx <7.2.5 ; extra == 'docs'.Requires-Dist: jaraco.packaging >=9.3 ; extra == 'docs'.Requires-Dist: rst.linker >=1.9 ; extra == 'docs'.Requires-Dist: furo ; extra == 'docs'.Requires-Dist: sphinx-lint ; extra == 'docs'.Requires-Dist: jaraco.tidelift >=1.4 ; extra == 'docs'.Provides-Extra: testing.Requires-Dist: pytest >=6 ;
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):843
                                                                                                                                                                                                            Entropy (8bit):5.807846597836061
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:Tmn/2zDRvbqfuggoaGnXamZlKZBX3vpBvt+c0X4yWJV:TmnuXRzUuggDifZlmX/aWJV
                                                                                                                                                                                                            MD5:85FB54BAFB143CD57D1787F7EF74FDB2
                                                                                                                                                                                                            SHA1:A915BBCDF108A58F3DFC1783D9D4DD3B7F3CE23A
                                                                                                                                                                                                            SHA-256:632AA7C04F7C4BCC01C027AF5B9BC76FE8958F4A181035B957A3BD3014BA248B
                                                                                                                                                                                                            SHA-512:2A39B4C6F221F88EC61D584C8CD3CAD358E8C7B50E529192105A0A4144ED3C2A4CE8B630C39C18D20E27FE226A23E2DE23CDFF8E3D3693959B165A9A2F9047CD
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:jaraco.functools-4.0.1.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..jaraco.functools-4.0.1.dist-info/LICENSE,sha256=htoPAa6uRjSKPD1GUZXcHOzN55956HdppkuNoEsqR0E,1023..jaraco.functools-4.0.1.dist-info/METADATA,sha256=i4aUaQDX-jjdEQK5wevhegyx8JyLfin2HyvaSk3FHso,2891..jaraco.functools-4.0.1.dist-info/RECORD,,..jaraco.functools-4.0.1.dist-info/WHEEL,sha256=GJ7t_kWBFywbagK5eo9IoUwLW6oyOeTKmQ-9iHFVNxQ,92..jaraco.functools-4.0.1.dist-info/top_level.txt,sha256=0JnN3LfXH4LIRfXL-QFOGCJzQWZO3ELx4R1d_louoQM,7..jaraco/functools/__init__.py,sha256=hEAJaS2uSZRuF_JY4CxCHIYh79ZpxaPp9OiHyr9EJ1w,16642..jaraco/functools/__init__.pyi,sha256=gk3dsgHzo5F_U74HzAvpNivFAPCkPJ1b2-yCd62dfnw,3878..jaraco/functools/__pycache__/__init__.cpython-312.pyc,,..jaraco/functools/py.typed,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):92
                                                                                                                                                                                                            Entropy (8bit):4.812622295095324
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeX7MWcSlVlFxP+tPCCfA5S:RtBMwlVTxWBBf
                                                                                                                                                                                                            MD5:43136DDE7DD276932F6197BB6D676EF4
                                                                                                                                                                                                            SHA1:6B13C105452C519EA0B65AC1A975BD5E19C50122
                                                                                                                                                                                                            SHA-256:189EEDFE4581172C1B6A02B97A8F48A14C0B5BAA3239E4CA990FBD8871553714
                                                                                                                                                                                                            SHA-512:E7712BA7D36DEB083EBCC3B641AD3E7D19FB071EE64AE3A35AD6A50EE882B20CD2E60CA1319199DF12584FE311A6266EC74F96A3FB67E59F90C7B5909668AEE1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: bdist_wheel (0.43.0).Root-Is-Purelib: true.Tag: py3-none-any..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7
                                                                                                                                                                                                            Entropy (8bit):2.5216406363433186
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:GEG0:GEG0
                                                                                                                                                                                                            MD5:0BA8D736B7B4AB182687318B0497E61E
                                                                                                                                                                                                            SHA1:311BA5FFD098689179F299EF20768EE1A29F586D
                                                                                                                                                                                                            SHA-256:D099CDDCB7D71F82C845F5CBF9014E18227341664EDC42F1E11D5DFE5A2EA103
                                                                                                                                                                                                            SHA-512:7CCCBB4AFA2FADE40D529482301BEAE152E0C71EE3CC41736EB19E35CFC5EE3B91EF958CF5CA6B7330333B8494FEB6682FD833D5AA16BF4A8F1F721FD859832C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:jaraco.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1023
                                                                                                                                                                                                            Entropy (8bit):5.059832621894572
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:OrmJHcwH0MP3gt8Hw1hj9QHOsUv4eOk4/+/m3oqMSFJ:OaJ8YHvEH5QHOs5exm3oEFJ
                                                                                                                                                                                                            MD5:141643E11C48898150DAA83802DBC65F
                                                                                                                                                                                                            SHA1:0445ED0F69910EEAEE036F09A39A13C6E1F37E12
                                                                                                                                                                                                            SHA-256:86DA0F01AEAE46348A3C3D465195DC1CECCDE79F79E87769A64B8DA04B2A4741
                                                                                                                                                                                                            SHA-512:EF62311602B466397BAF0B23CACA66114F8838F9E78E1B067787CEB709D09E0530E85A47BBCD4C5A0905B74FDB30DF0CC640910C6CC2E67886E5B18794A3583F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to.deal in the Software without restriction, including without limitation the.rights to use, copy, modify, merge, publish, distribute, sublicense, and/or.sell copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING.FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEA
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3658
                                                                                                                                                                                                            Entropy (8bit):5.02710641474483
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:DYMaCFS802Vpnu388Ksc+fIybwFiR8g6RSwTsL:pFz02Vpnu388KB+gybwgRd6RSwTsL
                                                                                                                                                                                                            MD5:70FE732EDE8F8E6C84DA4EA21D4933E5
                                                                                                                                                                                                            SHA1:A7763789FA56CEBBAA849368FAAC7D386F170399
                                                                                                                                                                                                            SHA-256:03359D9BA56231F0CE3E840C7CB5A7DB380141218949CCAA78DDBD4DCB965D52
                                                                                                                                                                                                            SHA-512:4C8D3D5078840BD4DBE20458EBF52890585C5911C22C3EFCE2FB28985461BC80469339DDAF6016FB099C84BDF9B41A26FF1884B456422A8D0C682104D7950D91
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Metadata-Version: 2.1.Name: jaraco.text.Version: 3.12.1.Summary: Module for text manipulation.Author-email: "Jason R. Coombs" <jaraco@jaraco.com>.Project-URL: Homepage, https://github.com/jaraco/jaraco.text.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: MIT License.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3 :: Only.Requires-Python: >=3.8.Description-Content-Type: text/x-rst.License-File: LICENSE.Requires-Dist: jaraco.functools.Requires-Dist: jaraco.context >=4.1.Requires-Dist: autocommand.Requires-Dist: inflect.Requires-Dist: more-itertools.Requires-Dist: importlib-resources ; python_version < "3.9".Provides-Extra: doc.Requires-Dist: sphinx >=3.5 ; extra == 'doc'.Requires-Dist: jaraco.packaging >=9.3 ; extra == 'doc'.Requires-Dist: rst.linker >=1.9 ; extra == 'doc'.Requires-Dist: furo ; extra == 'doc'.Requires-Dist: sphinx-lint ; extra == 'doc
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1500
                                                                                                                                                                                                            Entropy (8bit):5.794249493238335
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:TkLFn/2zDVLFvbqfuaLFo2kXLFGnLFEsJiLFXamdLFlKbkZ6d3JpPXu/1XWXYXw2:TcnuXDzUuuCw5Jmfblyz3Jp2/NUsM0bN
                                                                                                                                                                                                            MD5:39FCCE64BC768C2046067E4AAD8465F0
                                                                                                                                                                                                            SHA1:2EFC0FC776576A8FE01BBACD0760A49EEE6481DA
                                                                                                                                                                                                            SHA-256:816D945741DCA246099388CA3EED74FC0667ACBAA36F70B559B2494C3979B1F6
                                                                                                                                                                                                            SHA-512:FB2335A6675F9CADEEE38B666FAB9EA1D8BFBA6B7768253D42F44149591A3239F4B2FA19DDF2C282DC7E47A01D7DCA69AADBBCDAC9107EDBCB2C22D11BA81287
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:jaraco.text-3.12.1.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..jaraco.text-3.12.1.dist-info/LICENSE,sha256=htoPAa6uRjSKPD1GUZXcHOzN55956HdppkuNoEsqR0E,1023..jaraco.text-3.12.1.dist-info/METADATA,sha256=AzWdm6ViMfDOPoQMfLWn2zgBQSGJScyqeN29TcuWXVI,3658..jaraco.text-3.12.1.dist-info/RECORD,,..jaraco.text-3.12.1.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..jaraco.text-3.12.1.dist-info/WHEEL,sha256=GJ7t_kWBFywbagK5eo9IoUwLW6oyOeTKmQ-9iHFVNxQ,92..jaraco.text-3.12.1.dist-info/top_level.txt,sha256=0JnN3LfXH4LIRfXL-QFOGCJzQWZO3ELx4R1d_louoQM,7..jaraco/text/Lorem ipsum.txt,sha256=N_7c_79zxOufBY9HZ3yzMgOkNv-TkOTTio4BydrSjgs,1335..jaraco/text/__init__.py,sha256=Y2YUqXR_orUoDaY4SkPRe6ZZhb5HUHB_Ah9RCNsVyho,16250..jaraco/text/__pycache__/__init__.cpython-312.pyc,,..jaraco/text/__pycache__/layouts.cpython-312.pyc,,..jaraco/text/__pycache__/show-newlines.cpython-312.pyc,,..jaraco/text/__pycache__/strip-prefix.cpython-312.pyc,,..jaraco/text/__py
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):92
                                                                                                                                                                                                            Entropy (8bit):4.812622295095324
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeX7MWcSlVlFxP+tPCCfA5S:RtBMwlVTxWBBf
                                                                                                                                                                                                            MD5:43136DDE7DD276932F6197BB6D676EF4
                                                                                                                                                                                                            SHA1:6B13C105452C519EA0B65AC1A975BD5E19C50122
                                                                                                                                                                                                            SHA-256:189EEDFE4581172C1B6A02B97A8F48A14C0B5BAA3239E4CA990FBD8871553714
                                                                                                                                                                                                            SHA-512:E7712BA7D36DEB083EBCC3B641AD3E7D19FB071EE64AE3A35AD6A50EE882B20CD2E60CA1319199DF12584FE311A6266EC74F96A3FB67E59F90C7B5909668AEE1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: bdist_wheel (0.43.0).Root-Is-Purelib: true.Tag: py3-none-any..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):7
                                                                                                                                                                                                            Entropy (8bit):2.5216406363433186
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:GEG0:GEG0
                                                                                                                                                                                                            MD5:0BA8D736B7B4AB182687318B0497E61E
                                                                                                                                                                                                            SHA1:311BA5FFD098689179F299EF20768EE1A29F586D
                                                                                                                                                                                                            SHA-256:D099CDDCB7D71F82C845F5CBF9014E18227341664EDC42F1E11D5DFE5A2EA103
                                                                                                                                                                                                            SHA-512:7CCCBB4AFA2FADE40D529482301BEAE152E0C71EE3CC41736EB19E35CFC5EE3B91EF958CF5CA6B7330333B8494FEB6682FD833D5AA16BF4A8F1F721FD859832C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:jaraco.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with very long lines (888)
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1335
                                                                                                                                                                                                            Entropy (8bit):4.226823573023539
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:FP6Hbz+g9RPZ14bJi04L6GEbX4UQF4UkZQhxI2EIhNyu:9E+i6bJmLm43+Uxxnh0u
                                                                                                                                                                                                            MD5:4CE7501F6608F6CE4011D627979E1AE4
                                                                                                                                                                                                            SHA1:78363672264D9CD3F72D5C1D3665E1657B1A5071
                                                                                                                                                                                                            SHA-256:37FEDCFFBF73C4EB9F058F47677CB33203A436FF9390E4D38A8E01C9DAD28E0B
                                                                                                                                                                                                            SHA-512:A4CDF92725E1D740758DA4DD28DF5D1131F70CEF46946B173FE6956CC0341F019D7C4FECC3C9605F354E1308858721DADA825B4C19F59C5AD1CE01AB84C46B24
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Lorem ipsum dolor sit amet, consectetur adipiscing elit, sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat. Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum..Curabitur pretium tincidunt lacus. Nulla gravida orci a odio. Nullam varius, turpis et commodo pharetra, est eros bibendum elit, nec luctus magna felis sollicitudin mauris. Integer in mauris eu nibh euismod gravida. Duis ac tellus et risus vulputate vehicula. Donec lobortis risus a elit. Etiam tempor. Ut ullamcorper, ligula eu tempor congue, eros est euismod turpis, id tincidunt sapien risus a quam. Maecenas fermentum consequat mi. Donec fermentum. Pellentesque malesuada nulla a mi. Duis sapien sem, aliquet nec, commodo eget, consequat quis, neque.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1053
                                                                                                                                                                                                            Entropy (8bit):5.0945274555157285
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:arOJH7H0yxgtUHw1hC09QHOsUv4eOk4/+/m3oqLFh:aSJrlxEvdQHOs5exm3ogFh
                                                                                                                                                                                                            MD5:3396EA30F9D21389D7857719816F83B5
                                                                                                                                                                                                            SHA1:0D43A836DAC65C0EA426AD49C881A1086600BF85
                                                                                                                                                                                                            SHA-256:09F1C8C9E941AF3E584D59641EA9B87D83C0CB0FD007EB5EF391A7E2643C1A46
                                                                                                                                                                                                            SHA-512:D43092223392EDDA3BD777625F5BF54ACB0CC00C25555A4F8A16DB9CCDAFC380D3204486CB2A5FDC9D3F9E459B1FED948FFC7000AA0E40F37B807A01F4421294
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Copyright (c) 2012 Erik Rose..Permission is hereby granted, free of charge, to any person obtaining a copy of.this software and associated documentation files (the "Software"), to deal in.the Software without restriction, including without limitation the rights to.use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies.of the Software, and to permit persons to whom the Software is furnished to do.so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,.OUT OF OR IN CONNECTION WITH THE SO
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):36293
                                                                                                                                                                                                            Entropy (8bit):3.717596190655759
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:bs9cnyPtWIRmL0QnCHx4Zi3XBB9GcF89oi+odVBqCv9d3m24TeYH5AvDpG27IFf5:Ua+H1Nsg/
                                                                                                                                                                                                            MD5:5BA05B51B603386707E1E3A101CDD6B3
                                                                                                                                                                                                            SHA1:FFCCEC7FD799CC4AB07530954FEF3BE2472E2C23
                                                                                                                                                                                                            SHA-256:0453BDD0EF9F2CD89540CA63EE8212E73B73809514419DD3037D8FE471F737E0
                                                                                                                                                                                                            SHA-512:FE7F7D6B6C8089B09A18930EF462BA4C7A15EAF6D3E8610AC655ECADE16CE31D9C01ECE84C88A3C2D9DD34DE70E194A020E28179CF33B21389EE3EEFC7229B74
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Metadata-Version: 2.1.Name: more-itertools.Version: 10.3.0.Summary: More routines for operating on iterables, beyond itertools.Keywords: itertools,iterator,iteration,filter,peek,peekable,chunk,chunked.Author-email: Erik Rose <erikrose@grinchcentral.com>.Requires-Python: >=3.8.Description-Content-Type: text/x-rst.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: Natural Language :: English.Classifier: License :: OSI Approved :: MIT License.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3.8.Classifier: Programming Language :: Python :: 3.9.Classifier: Programming Language :: Python :: 3.10.Classifier: Programming Language :: Python :: 3.11.Classifier: Programming Language :: Python :: 3.12.Classifier: Programming Language :: Python :: 3 :: Only.Classifier: Programming Language :: Python :: Implementation :: CPython.Classifier: Programming Language :: Python :: Implementation :: Py
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1259
                                                                                                                                                                                                            Entropy (8bit):5.794423512787632
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:Bhxn/2zDahxvIhxphxBhxEsJXhxzvXiCflBJRHXoggtqgmf7WJhmsxmwG:hnuXwOph5J3zvXi4Lo7qgQ7WJhS
                                                                                                                                                                                                            MD5:178EE325409DD28809AD3661E8819EF8
                                                                                                                                                                                                            SHA1:F5844FAC6E3C9133FE5F1B8195EE801959801DF3
                                                                                                                                                                                                            SHA-256:77C8E73E018DC0FD7E9ED6C80B05A4404545F641FB085220CE42B368B59AA3D3
                                                                                                                                                                                                            SHA-512:2DB06B622F644674BF7D7AD8B780F9802858D15D73B5075139C2D82181DD6D589B90172BCA7AE9C785E705F447F523DB2AE641826C550C599551A7D8C2396FC2
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:more_itertools-10.3.0.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..more_itertools-10.3.0.dist-info/LICENSE,sha256=CfHIyelBrz5YTVlkHqm4fYPAyw_QB-te85Gn4mQ8GkY,1053..more_itertools-10.3.0.dist-info/METADATA,sha256=BFO90O-fLNiVQMpj7oIS5ztzgJUUQZ3TA32P5HH3N-A,36293..more_itertools-10.3.0.dist-info/RECORD,,..more_itertools-10.3.0.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..more_itertools-10.3.0.dist-info/WHEEL,sha256=rSgq_JpHF9fHR1lx53qwg_1-2LypZE_qmcuXbVUq948,81..more_itertools/__init__.py,sha256=dtAbGjTDmn_ghiU5YXfhyDy0phAlXVdt5klZA5fUa-Q,149..more_itertools/__init__.pyi,sha256=5B3eTzON1BBuOLob1vCflyEb2lSd6usXQQ-Cv-hXkeA,43..more_itertools/__pycache__/__init__.cpython-312.pyc,,..more_itertools/__pycache__/more.cpython-312.pyc,,..more_itertools/__pycache__/recipes.cpython-312.pyc,,..more_itertools/more.py,sha256=1E5kzFncRKTDw0cYv1yRXMgDdunstLQd1QStcnL6U90,148370..more_itertools/more.pyi,sha256=iXXeqt48Nxe8VGmIWpkVXuKpR2FYNuu2DU8nQL
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):81
                                                                                                                                                                                                            Entropy (8bit):4.672346887071811
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeX/QFML6KjP+tPCCfA5I:Rt1QqL6gWBB3
                                                                                                                                                                                                            MD5:FE76A5D309B5416824C2034FBF8A16CD
                                                                                                                                                                                                            SHA1:5975EB6043863B0D018A5D751293F38E0B8E2874
                                                                                                                                                                                                            SHA-256:AD282AFC9A4717D7C7475971E77AB083FD7ED8BCA9644FEA99CB976D552AF78F
                                                                                                                                                                                                            SHA-512:6E4610171DD4E7E49FB4570CF3562D26A4F171FF67DA0F3A259A77916ACB939C8FCA7DA9F473EFAD839947796AC8CD7385DAA3264ADB150FF131A5C0FAC9329C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: flit 3.8.0.Root-Is-Purelib: true.Tag: py3-none-any.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):197
                                                                                                                                                                                                            Entropy (8bit):4.510719529760597
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:hWDncJhByZmJgXPForADu1QjygQuaAJygT2d5GeWreBNA2eBKmJozlMHuO:h9Co8FyQjkDYc5tWreBN0n2mH1
                                                                                                                                                                                                            MD5:FAADAEDCA9251A90B205C9167578CE91
                                                                                                                                                                                                            SHA1:ED1FCABA1DBBF55113ABB419A484F3DF63E7ECFC
                                                                                                                                                                                                            SHA-256:CAD1EF5BD340D73E074BA614D26F7DEACA5C7940C3D8C34852E65C4909686C48
                                                                                                                                                                                                            SHA-512:1E69C89558FFE39E5C1EBB6728C4F0EB6023563C7A7F31B5417A8EFCC906378D2E2AF7B0E06A66980FBAAB7996AEB2AE1EA3918FDBE5FFCC3F77EA888A68EFBC
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:This software is made available under the terms of *either* of the licenses.found in LICENSE.APACHE or LICENSE.BSD. Contributions to this software is made.under the terms of *both* these licenses..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):10174
                                                                                                                                                                                                            Entropy (8bit):4.3908324771089084
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:nU6G5KXSD9VYUKhu1JVF9hFGvV/QiGkS594drFjuHYx5dvTrLhP:U9vlKM1zJlFvmNz5VrZ
                                                                                                                                                                                                            MD5:2EE41112A44FE7014DCE33E26468BA93
                                                                                                                                                                                                            SHA1:598F87F072F66E2269DD6919292B2934DBB20492
                                                                                                                                                                                                            SHA-256:0D542E0C8804E39AA7F37EB00DA5A762149DC682D7829451287E11B938E94594
                                                                                                                                                                                                            SHA-512:27B8C0252EAE50CA3CE02AB7C5670664C0C824E03EB3DA1089F3F0A00D23E648A956BCB9F53645C6D79674A87C4CC86D1085DC335911BE0210D691336B121857
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:. Apache License. Version 2.0, January 2004. http://www.apache.org/licenses/.. TERMS AND CONDITIONS FOR USE, REPRODUCTION, AND DISTRIBUTION.. 1. Definitions... "License" shall mean the terms and conditions for use, reproduction,. and distribution as defined by Sections 1 through 9 of this document... "Licensor" shall mean the copyright owner or entity authorized by. the copyright owner that is granting the License... "Legal Entity" shall mean the union of the acting entity and all. other entities that control, are controlled by, or are under common. control with that entity. For the purposes of this definition,. "control" means (i) the power, direct or indirect, to cause the. direction or management of such entity, whether by contract or. otherwise, or (ii) ownership of fifty percent (50%) or more of the. outstanding shares, or (iii) beneficial own
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1344
                                                                                                                                                                                                            Entropy (8bit):5.070827944686827
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:fjUnoorbOFFTJJyRrYFTjz796432s4EOkUs8gROF32s3yTtTf413tf9fsZlTHv:fkOFJSrYJR6432svI32s3Stc13tfyTHv
                                                                                                                                                                                                            MD5:7BEF9BF4A8E4263634D0597E7BA100B8
                                                                                                                                                                                                            SHA1:FDC0E4EABC45522B079DEFF7D03D70528D775DC0
                                                                                                                                                                                                            SHA-256:B70E7E9B742F1CC6F948B34C16AA39FFECE94196364BC88FF0D2180F0028FAC5
                                                                                                                                                                                                            SHA-512:96C3273D51B83B6AE1AB85FEFB814DCD6C1E60D311D412242405AA429CC860412477CBD6ECE171408DBB85F0C4FD742E3AF20C758015BC48406AA65A1AB6F60A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Copyright (c) Donald Stufft and individual contributors..All rights reserved...Redistribution and use in source and binary forms, with or without.modification, are permitted provided that the following conditions are met:.. 1. Redistributions of source code must retain the above copyright notice,. this list of conditions and the following disclaimer... 2. Redistributions in binary form must reproduce the above copyright. notice, this list of conditions and the following disclaimer in the. documentation and/or other materials provided with the distribution...THIS SOFTWARE IS PROVIDED BY THE COPYRIGHT HOLDERS AND CONTRIBUTORS "AS IS" AND.ANY EXPRESS OR IMPLIED WARRANTIES, INCLUDING, BUT NOT LIMITED TO, THE IMPLIED.WARRANTIES OF MERCHANTABILITY AND FITNESS FOR A PARTICULAR PURPOSE ARE.DISCLAIMED. IN NO EVENT SHALL THE COPYRIGHT HOLDER OR CONTRIBUTORS BE LIABLE.FOR ANY DIRECT, INDIRECT, INCIDENTAL, SPECIAL, EXEMPLARY, OR CONSEQUENTIAL.DAMAGES (INCLUDING, BUT NOT LIM
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3204
                                                                                                                                                                                                            Entropy (8bit):4.9859857663557925
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:DRKnOkaMktjaVMxsxCp5QXFfFKiYEvA9TzBnyD:psZfFhgXNG
                                                                                                                                                                                                            MD5:3236C0D7091D4A6577FA30E061480CEC
                                                                                                                                                                                                            SHA1:F99865B8D3B90AD64A0060F7F2F4C6E4FAEB0A39
                                                                                                                                                                                                            SHA-256:5F7A283B75A709FCCD481AEA42379F083D4F3801753365922E6B0732042515D9
                                                                                                                                                                                                            SHA-512:A9F0BC43A135732510B98E9C0B7F997D9557A6069352372F1AC3216F0E66FA617D9597990904935D58E5139FB34E17995BFA8B95B90C71997206A2B6955FE867
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Metadata-Version: 2.1.Name: packaging.Version: 24.1.Summary: Core utilities for Python packages.Author-email: Donald Stufft <donald@stufft.io>.Requires-Python: >=3.8.Description-Content-Type: text/x-rst.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: Apache Software License.Classifier: License :: OSI Approved :: BSD License.Classifier: Programming Language :: Python.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3 :: Only.Classifier: Programming Language :: Python :: 3.8.Classifier: Programming Language :: Python :: 3.9.Classifier: Programming Language :: Python :: 3.10.Classifier: Programming Language :: Python :: 3.11.Classifier: Programming Language :: Python :: 3.12.Classifier: Programming Language :: Python :: 3.13.Classifier: Programming Language :: Python :: Implementation :: CPython.Classifier: Programming Language :: Python :: Implementation
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2565
                                                                                                                                                                                                            Entropy (8bit):5.780503861671858
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:bsnuXksXW2Bsv8VsQ7lEsahOsbs5Jhsde8UogvtJkHpHAfEcysrD5WJeCzESowj:vXrW2s8JsMdVogvtJkJgfksP5qeCzOwj
                                                                                                                                                                                                            MD5:88FBF3C6BD08040482212DAD5A8EAB02
                                                                                                                                                                                                            SHA1:E7EE66942F7321FB77888D492D57C2EEEA1A5171
                                                                                                                                                                                                            SHA-256:38A6898306293627C81E2B2D8A93E5F6857D5F7EDB73F0334E8D9A53DAD53B6E
                                                                                                                                                                                                            SHA-512:786AE1F883A999A0939C22A756F90D74CC7F87AAF13F6FFF22D8D962D213A1ECBC6AAE2890A5D7347487824CD0E9EB440A3923F01F938EEF068719DFEEE96554
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:packaging-24.1.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..packaging-24.1.dist-info/LICENSE,sha256=ytHvW9NA1z4HS6YU0m996spceUDD2MNIUuZcSQlobEg,197..packaging-24.1.dist-info/LICENSE.APACHE,sha256=DVQuDIgE45qn836wDaWnYhSdxoLXgpRRKH4RuTjpRZQ,10174..packaging-24.1.dist-info/LICENSE.BSD,sha256=tw5-m3QvHMb5SLNMFqo5_-zpQZY2S8iP8NIYDwAo-sU,1344..packaging-24.1.dist-info/METADATA,sha256=X3ooO3WnCfzNSBrqQjefCD1POAF1M2WSLmsHMgQlFdk,3204..packaging-24.1.dist-info/RECORD,,..packaging-24.1.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..packaging-24.1.dist-info/WHEEL,sha256=EZbGkh7Ie4PoZfRQ8I0ZuP9VklN_TvcZ6DSE5Uar4z4,81..packaging/__init__.py,sha256=dtw2bNmWCQ9WnMoK3bk_elL1svSlikXtLpZhCFIB9SE,496..packaging/__pycache__/__init__.cpython-312.pyc,,..packaging/__pycache__/_elffile.cpython-312.pyc,,..packaging/__pycache__/_manylinux.cpython-312.pyc,,..packaging/__pycache__/_musllinux.cpython-312.pyc,,..packaging/__pycache__/_parser.cpython-312.pyc,,
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):81
                                                                                                                                                                                                            Entropy (8bit):4.672346887071811
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeX/QFM+vxP+tPCCfA5I:Rt1Qq2WBB3
                                                                                                                                                                                                            MD5:24019423EA7C0C2DF41C8272A3791E7B
                                                                                                                                                                                                            SHA1:AAE9ECFB44813B68CA525BA7FA0D988615399C86
                                                                                                                                                                                                            SHA-256:1196C6921EC87B83E865F450F08D19B8FF5592537F4EF719E83484E546ABE33E
                                                                                                                                                                                                            SHA-512:09AB8E4DAA9193CFDEE6CF98CCAE9DB0601F3DCD4944D07BF3AE6FA5BCB9DC0DCAFD369DE9A650A38D1B46C758DB0721EBA884446A8A5AD82BB745FD5DB5F9B1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: flit 3.9.0.Root-Is-Purelib: true.Tag: py3-none-any.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Unicode text, UTF-8 text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):11429
                                                                                                                                                                                                            Entropy (8bit):5.039575520713946
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:n9x/tlCtlsaCUpVQ7yHwgNF8NFvWVDM1RnzadSibNTTh+fOnnxa6jlES4h8a8KAH:3/tlCfsqpq7ydZzM0dGiCbvHcjNj61TA
                                                                                                                                                                                                            MD5:12306075DF09A0DBB93315FADDDF73FB
                                                                                                                                                                                                            SHA1:1AC8A3679AFCFEEC0BA00851F5F8095DD1B060CD
                                                                                                                                                                                                            SHA-256:CE6B227B4D46D4CB57474C2022FE57A557933BB89DAF4596BDF9B12AC296B869
                                                                                                                                                                                                            SHA-512:BA0A72B888A14F82FD44FB103C01EF0900B5302F18E986A8264A9A08AB77D1C655C392374FD7B0A98BEF9B9511F6EC78AF3EF8936091C80A0B5364F7A53DC20A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Metadata-Version: 2.3.Name: platformdirs.Version: 4.2.2.Summary: A small Python package for determining appropriate platform-specific dirs, e.g. a `user data dir`..Project-URL: Documentation, https://platformdirs.readthedocs.io.Project-URL: Homepage, https://github.com/platformdirs/platformdirs.Project-URL: Source, https://github.com/platformdirs/platformdirs.Project-URL: Tracker, https://github.com/platformdirs/platformdirs/issues.Maintainer-email: Bern.t G.bor <gaborjbernat@gmail.com>, Julian Berman <Julian@GrayVines.com>, Ofek Lev <oss@ofek.dev>, Ronny Pfannschmidt <opensource@ronnypfannschmidt.de>.License-Expression: MIT.License-File: LICENSE.Keywords: appdirs,application,cache,directory,log,user.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: MIT License.Classifier: Operating System :: OS Independent.Classifier: Programming Language :: Python.Classifier: Programming Language :: Python :: 3
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1642
                                                                                                                                                                                                            Entropy (8bit):5.780720255872038
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:bn/2zDzoobEsJhfPWcs013+pj456szN6lnhta57WJ+guQg4:bnuXcob5Jhfucs+d49hta9WJ+g1X
                                                                                                                                                                                                            MD5:0E141A28570FC62974FC5CEADFE808E3
                                                                                                                                                                                                            SHA1:7B92561C5BBBA83D6E16A1C7B195089ACA1766AF
                                                                                                                                                                                                            SHA-256:4C211D76D42ED40EFC3ACFCC866D8912A718AFBCA2B7E51849442366D6E99FE8
                                                                                                                                                                                                            SHA-512:830721C18A35AECD1EFB81A5FAAF8AC0EA02428EDC5B294458556343788D894B76035F1E661214D975DF2A64DC8C3D6AAA7A53A99BE64B9413B6A5D89D549F9D
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:platformdirs-4.2.2.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..platformdirs-4.2.2.dist-info/METADATA,sha256=zmsie01G1MtXR0wgIv5XpVeTO7idr0WWvfmxKsKWuGk,11429..platformdirs-4.2.2.dist-info/RECORD,,..platformdirs-4.2.2.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..platformdirs-4.2.2.dist-info/WHEEL,sha256=zEMcRr9Kr03x1ozGwg5v9NQBKn3kndp6LSoSlVg-jhU,87..platformdirs-4.2.2.dist-info/licenses/LICENSE,sha256=KeD9YukphQ6G6yjD_czwzv30-pSHkBHP-z0NS-1tTbY,1089..platformdirs/__init__.py,sha256=EMGE8qeHRR9CzDFr8kL3tA8hdZZniYjXBVZd0UGTWK0,22225..platformdirs/__main__.py,sha256=HnsUQHpiBaiTxwcmwVw-nFaPdVNZtQIdi1eWDtI-MzI,1493..platformdirs/__pycache__/__init__.cpython-312.pyc,,..platformdirs/__pycache__/__main__.cpython-312.pyc,,..platformdirs/__pycache__/android.cpython-312.pyc,,..platformdirs/__pycache__/api.cpython-312.pyc,,..platformdirs/__pycache__/macos.cpython-312.pyc,,..platformdirs/__pycache__/unix.cpython-312.pyc,,..platformdirs/__p
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):87
                                                                                                                                                                                                            Entropy (8bit):4.730668933656452
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeXAaCTR73RP+tPCCfA5I:Rt2PFRWBB3
                                                                                                                                                                                                            MD5:8895639B8515B3094302B59E28AFB562
                                                                                                                                                                                                            SHA1:FBD4DA759EA5BEB65AE820DFBC47F9B569E89519
                                                                                                                                                                                                            SHA-256:CC431C46BF4AAF4DF1D68CC6C20E6FF4D4012A7DE49DDA7A2D2A1295583E8E15
                                                                                                                                                                                                            SHA-512:B53C0978DAD2A7195058ABC7B7D20A229EC617BDDBB364D8ED2354F37D5071208735774350F9FBBA5C804BEFCEFE71C27BC5E468E12899DF4687189C468785A0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: hatchling 1.24.2.Root-Is-Purelib: true.Tag: py3-none-any.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1089
                                                                                                                                                                                                            Entropy (8bit):5.119723466133474
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:VrmJHHH0yN3gtsHw1hC09QHOsUv4eOk4/+/m3oqLFh:VaJHlxE3dQHOs5exm3ogFh
                                                                                                                                                                                                            MD5:EA4F5A41454746A9ED111E3D8723D17A
                                                                                                                                                                                                            SHA1:F511A8A63AF8C6E36004B593478436BBC560EE0C
                                                                                                                                                                                                            SHA-256:29E0FD62E929850E86EB28C3FDCCF0CEFDF4FA94879011CFFB3D0D4BED6D4DB6
                                                                                                                                                                                                            SHA-512:CACA68A5589CA2EAB7C0D74BA5D2B25E3367B9902DFC7578BBA911AC8F8BF1C3A13F25E663C5B6B19BA71BF611943E23F4D0A99BE92A8F7D7FF60732DC3DD409
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:MIT License..Copyright (c) 2010-202x The platformdirs developers..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1072
                                                                                                                                                                                                            Entropy (8bit):5.10135495500641
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:f9rmJHHH0yN3gtsHw1hC09QHOsUv4eOk4/+/m3oqLFh:1aJHlxE3dQHOs5exm3ogFh
                                                                                                                                                                                                            MD5:AAAAF0879D17DF0110D1AA8C8C9F46F5
                                                                                                                                                                                                            SHA1:9DA6CA26337A886FB3E8D30EFD4AEDA623DC9ADE
                                                                                                                                                                                                            SHA-256:B80816B0D530B8ACCB4C2211783790984A6E3B61922C2B5EE92F3372AB2742FE
                                                                                                                                                                                                            SHA-512:EECD0C29FEBF51ADEFB02F970E66EFE7E24D573686DFDB3BEEA63CEFEA012A79CE3C49A899B4F26E9B67DC27176B397F6041909227281F9866BEEDC97389095C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:MIT License..Copyright (c) 2021 Taneli Hukkinen..Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to deal.in the Software without restriction, including without limitation the rights.to use, copy, modify, merge, publish, distribute, sublicense, and/or sell.copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all.copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,.OUT OF OR IN CON
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Python script, ASCII text executable
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):8875
                                                                                                                                                                                                            Entropy (8bit):4.884349533695185
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:h15VsahrDzoGlmLxUJyLIPXR/yrKK3Trclclg2pj4VRR6V8wNVonQd:3swrAamWuIPA2K3v2g
                                                                                                                                                                                                            MD5:CBBF7047A51FEDA58386E86182B85B8A
                                                                                                                                                                                                            SHA1:D3EA3BDA227794AE35FE7FFC5BD6E5FA2A5EF250
                                                                                                                                                                                                            SHA-256:CCF0DC78A98FC0918B5AD67292B1E2C4BED65575A6246CD9D63C914F9942A0F2
                                                                                                                                                                                                            SHA-512:A994914F1676790730C6BDACA26FE5F1B18BA9A3B9F0D24D708C722424DED255360A0CC88E239C6BFE467BD2763DF7339BB6B760AB090FAE474A7C9C8AFA8948
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:Metadata-Version: 2.1.Name: tomli.Version: 2.0.1.Summary: A lil' TOML parser.Keywords: toml.Author-email: Taneli Hukkinen <hukkin@users.noreply.github.com>.Requires-Python: >=3.7.Description-Content-Type: text/markdown.Classifier: License :: OSI Approved :: MIT License.Classifier: Operating System :: MacOS.Classifier: Operating System :: Microsoft :: Windows.Classifier: Operating System :: POSIX :: Linux.Classifier: Programming Language :: Python :: 3 :: Only.Classifier: Programming Language :: Python :: 3.7.Classifier: Programming Language :: Python :: 3.8.Classifier: Programming Language :: Python :: 3.9.Classifier: Programming Language :: Python :: 3.10.Classifier: Programming Language :: Python :: Implementation :: CPython.Classifier: Programming Language :: Python :: Implementation :: PyPy.Classifier: Topic :: Software Development :: Libraries :: Python Modules.Classifier: Typing :: Typed.Project-URL: Changelog, https://github.com/hukkin/tomli/blob/master/CHANGELOG.md.Project-URL:
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):999
                                                                                                                                                                                                            Entropy (8bit):5.89030761653127
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:4n/2zDRv53Pb4EsJWc6QtD8r8N8bh8WNdop2+oM8+kzAL5+1:4nuXR1Pb45JWc6QmIebKWcpHoM8JMLy
                                                                                                                                                                                                            MD5:D5FAB61E3DB6B54B51FBA607865C195B
                                                                                                                                                                                                            SHA1:B94D9126E8FC9D5F29FAFBB67F068E2D111D17FC
                                                                                                                                                                                                            SHA-256:0CB9F9A451A1E365AC54B4C88662E1DA0CB54A72D16A5258FB0ABFF9D3E1C022
                                                                                                                                                                                                            SHA-512:ABD3EF61D8D578C1DE609560A6985503E60BD53F90DCFF54EBEE23714D9CD88DBA4036ED19B24EC62B8432550311894FCC47BDCCD7CE4DCDE82518F4E02E123C
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:tomli-2.0.1.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..tomli-2.0.1.dist-info/LICENSE,sha256=uAgWsNUwuKzLTCIReDeQmEpuO2GSLCte6S8zcqsnQv4,1072..tomli-2.0.1.dist-info/METADATA,sha256=zPDceKmPwJGLWtZykrHixL7WVXWmJGzZ1jyRT5lCoPI,8875..tomli-2.0.1.dist-info/RECORD,,..tomli-2.0.1.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..tomli-2.0.1.dist-info/WHEEL,sha256=jPMR_Dzkc4X4icQtmz81lnNY_kAsfog7ry7qoRvYLXw,81..tomli/__init__.py,sha256=JhUwV66DB1g4Hvt1UQCVMdfCu-IgAV8FXmvDU9onxd4,396..tomli/__pycache__/__init__.cpython-312.pyc,,..tomli/__pycache__/_parser.cpython-312.pyc,,..tomli/__pycache__/_re.cpython-312.pyc,,..tomli/__pycache__/_types.cpython-312.pyc,,..tomli/_parser.py,sha256=g9-ENaALS-B8dokYpCuzUFalWlog7T-SIYMjLZSWrtM,22633..tomli/_re.py,sha256=dbjg5ChZT23Ka9z9DHOXfdtSpPwUfdgMXnj8NOoly-w,2943..tomli/_types.py,sha256=-GTG2VUqkpxwMqzmVO4F7ybKddIbAnuAHXfmWQcTi3Q,254..tomli/py.typed,sha256=8PjyZ1aVoQpRVvt71muvuq5qE-jTFZkK-GLHkhdebmc,26..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):81
                                                                                                                                                                                                            Entropy (8bit):4.672346887071811
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeX/QFMthP+tPCCfA5I:Rt1QqDWBB3
                                                                                                                                                                                                            MD5:FF39892A240316BD62B5832C03D504BC
                                                                                                                                                                                                            SHA1:3883FC4406CC9A73BE0B839C1A0C31D3DDD64829
                                                                                                                                                                                                            SHA-256:8CF311FC3CE47385F889C42D9B3F35967358FE402C7E883BAF2EEAA11BD82D7C
                                                                                                                                                                                                            SHA-512:B2E57D9C81BBFB7364B8216FC086B8F73C2F2B537E300FB250EFB7972E3908F77A3D504363676C50A195D307822C69EE9B689DE6C48A4E6B8A6BA89A5A99AC32
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: flit 3.6.0.Root-Is-Purelib: true.Tag: py3-none-any.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Unicode text, UTF-8 text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1130
                                                                                                                                                                                                            Entropy (8bit):5.118590213496374
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:qt4rWHvH0yPP3Gt6Hw1hP9QHmsUv48OV/+dho3BoqxFB:/S/lPvKhlQHms5QK3WmFB
                                                                                                                                                                                                            MD5:F0E423EEA5C91E7AA21BDB70184B3E53
                                                                                                                                                                                                            SHA1:A51CCDCB7A9D8C2116D1DFC16F11B3C8A5830F67
                                                                                                                                                                                                            SHA-256:6163F7987DFB38D6BC320CE2B70B2F02B862BC41126516D552EF1CD43247E758
                                                                                                                                                                                                            SHA-512:8BE742880E6E8495C7EC4C9ECC8F076A9FC9D64FC84B3AEBBC8D2D10DC62AC2C5053F33B716212DCB76C886A9C51619F262C460FC4B39A335CE1AE2C9A8769A8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:This is the MIT license: http://www.opensource.org/licenses/mit-license.php..Copyright (c) Alex Gr.nholm..Permission is hereby granted, free of charge, to any person obtaining a copy of this.software and associated documentation files (the "Software"), to deal in the Software.without restriction, including without limitation the rights to use, copy, modify, merge,.publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons.to whom the Software is furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all copies or.substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,.INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR.PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE.FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF C
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Unicode text, UTF-8 text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3717
                                                                                                                                                                                                            Entropy (8bit):4.986068381037722
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:DSQRbraktjaAckH94jQnJIK04Fak/grjspC3EklAJj:/Rakd4jA7ak/gvspNWmj
                                                                                                                                                                                                            MD5:B6DAAC02F66AC8403E9061881322BABE
                                                                                                                                                                                                            SHA1:9A94672CCFEA06156A5F8A321CD0626CFD233AE8
                                                                                                                                                                                                            SHA-256:CF675C1C0A744F08580855390DE87CC77D676B312582E8D4CFDB5BB8FD298D21
                                                                                                                                                                                                            SHA-512:9C6B7326C90396AA9E962C2731A1085EDB672B5696F95F552D13350843C09A246E0BBF0EC484862DFF434FA5A86DE4C0B7C963958ADE35A066B9D2384076DD47
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Metadata-Version: 2.1.Name: typeguard.Version: 4.3.0.Summary: Run-time type checker for Python.Author-email: Alex Gr.nholm <alex.gronholm@nextday.fi>.License: MIT.Project-URL: Documentation, https://typeguard.readthedocs.io/en/latest/.Project-URL: Change log, https://typeguard.readthedocs.io/en/latest/versionhistory.html.Project-URL: Source code, https://github.com/agronholm/typeguard.Project-URL: Issue tracker, https://github.com/agronholm/typeguard/issues.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: MIT License.Classifier: Programming Language :: Python.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3.8.Classifier: Programming Language :: Python :: 3.9.Classifier: Programming Language :: Python :: 3.10.Classifier: Programming Language :: Python :: 3.11.Classifier: Programming Language :: Python :: 3.12.Requires-Python: >=3.8.Description-Content
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2402
                                                                                                                                                                                                            Entropy (8bit):5.729208478282605
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:eDnuX3DVED9HDDeDfPDLkAosGDlDiVoBFj7XH0H3HuwVB6Kgfkx7J/Q1NK1cQyxk:eyX3WRHDiLPjksV7I47J/Q1U6Qyx5fsJ
                                                                                                                                                                                                            MD5:D680B2881597974ACD91750E5AB61010
                                                                                                                                                                                                            SHA1:E00ED2416B5CE21641E3946905504D62D536972F
                                                                                                                                                                                                            SHA-256:48A51959582478352275428CEECD78EF77D79AC9DAE796E39A2EAF2540282552
                                                                                                                                                                                                            SHA-512:112172ACB515B0712AC58D78898EB159580ADA3DD3F16AABB37CB7A8D964F9E4BADF2869A245927B83B208D56904831C0F04ED925C95DFCB705801734FB0C7BA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:typeguard-4.3.0.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..typeguard-4.3.0.dist-info/LICENSE,sha256=YWP3mH37ONa8MgzitwsvArhivEESZRbVUu8c1DJH51g,1130..typeguard-4.3.0.dist-info/METADATA,sha256=z2dcHAp0TwhYCFU5Deh8x31nazElgujUz9tbuP0pjSE,3717..typeguard-4.3.0.dist-info/RECORD,,..typeguard-4.3.0.dist-info/WHEEL,sha256=GJ7t_kWBFywbagK5eo9IoUwLW6oyOeTKmQ-9iHFVNxQ,92..typeguard-4.3.0.dist-info/entry_points.txt,sha256=qp7NQ1aLtiSgMQqo6gWlfGpy0IIXzoMJmeQTLpzqFZQ,48..typeguard-4.3.0.dist-info/top_level.txt,sha256=4z28AhuDodwRS_c1J_l8H51t5QuwfTseskYzlxp6grs,10..typeguard/__init__.py,sha256=Onh4w38elPCjtlcU3JY9k3h70NjsxXIkAflmQn-Z0FY,2071..typeguard/__pycache__/__init__.cpython-312.pyc,,..typeguard/__pycache__/_checkers.cpython-312.pyc,,..typeguard/__pycache__/_config.cpython-312.pyc,,..typeguard/__pycache__/_decorators.cpython-312.pyc,,..typeguard/__pycache__/_exceptions.cpython-312.pyc,,..typeguard/__pycache__/_functions.cpython-312.pyc,,..typeguard/__pycache__/_i
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):92
                                                                                                                                                                                                            Entropy (8bit):4.812622295095324
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeX7MWcSlVlFxP+tPCCfA5S:RtBMwlVTxWBBf
                                                                                                                                                                                                            MD5:43136DDE7DD276932F6197BB6D676EF4
                                                                                                                                                                                                            SHA1:6B13C105452C519EA0B65AC1A975BD5E19C50122
                                                                                                                                                                                                            SHA-256:189EEDFE4581172C1B6A02B97A8F48A14C0B5BAA3239E4CA990FBD8871553714
                                                                                                                                                                                                            SHA-512:E7712BA7D36DEB083EBCC3B641AD3E7D19FB071EE64AE3A35AD6A50EE882B20CD2E60CA1319199DF12584FE311A6266EC74F96A3FB67E59F90C7B5909668AEE1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: bdist_wheel (0.43.0).Root-Is-Purelib: true.Tag: py3-none-any..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):48
                                                                                                                                                                                                            Entropy (8bit):4.155187698990101
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:mWSJCQEjMitjHfLvn:mrMJHfbn
                                                                                                                                                                                                            MD5:AEAB5BCF8BF89A51C97C4CDF70578848
                                                                                                                                                                                                            SHA1:2E9C1617560AB66431AAB90700DB901985293485
                                                                                                                                                                                                            SHA-256:AA9ECD43568BB624A0310AA8EA05A57C6A72D08217CE830999E4132E9CEA1594
                                                                                                                                                                                                            SHA-512:2BE73E99296DF26A28835F91DD8BC50EB104AF06A3C54666175FAF322E0AD4620453DB0388531C4113B052A92C1D2E4C3088E25AF43CDE42AA852CF7B0CB5B05
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:[pytest11].typeguard = typeguard._pytest_plugin.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):10
                                                                                                                                                                                                            Entropy (8bit):3.321928094887362
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:LEJn:M
                                                                                                                                                                                                            MD5:004A2A8CE1AB120A63902A27D76BD964
                                                                                                                                                                                                            SHA1:A4E367AB40410598DADD1FC5F680ED7A176BEB09
                                                                                                                                                                                                            SHA-256:E33DBC021B83A1DC114BF73527F97C1F9D6DE50BB07D3B1EB24633971A7A82BB
                                                                                                                                                                                                            SHA-512:0D8FF9A43897AB390AB41AFE5BAC8BD38A68C2BEF88E844E5B49BF70E3164B226975CC2717AE3DC3428D1CFBB0BE068C243F104915FEE1FFA58C23FBE76FDB89
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:typeguard.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):13936
                                                                                                                                                                                                            Entropy (8bit):5.135214154002924
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:384:cke8RQ6KSAdxC9ad9iqsibQtKti9zpQpzu9Jkh:K8RQ6q7C9ad9iqT8cti9zpQpzu7kh
                                                                                                                                                                                                            MD5:FCF6B249C2641540219A727F35D8D2C2
                                                                                                                                                                                                            SHA1:C6E195F9AA30CC9B675D1612CA4FB7F74111BD35
                                                                                                                                                                                                            SHA-256:3B2F81FE21D181C499C59A256C8E1968455D6689D269AA85373BFB6AF41DA3BF
                                                                                                                                                                                                            SHA-512:70367B908204B5922E5D9D2ACE39437DBAA1EEFDAD1797B50CC6E7DCA168D9B59199353BADDDCAEEE12B49D328FC8132F628952383CFE6803CB4F4BF9B9D6D86
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:A. HISTORY OF THE SOFTWARE.==========================..Python was created in the early 1990s by Guido van Rossum at Stichting.Mathematisch Centrum (CWI, see https://www.cwi.nl) in the Netherlands.as a successor of a language called ABC. Guido remains Python's.principal author, although it includes many contributions from others...In 1995, Guido continued his work on Python at the Corporation for.National Research Initiatives (CNRI, see https://www.cnri.reston.va.us).in Reston, Virginia where he released several versions of the.software...In May 2000, Guido and the Python core development team moved to.BeOpen.com to form the BeOpen PythonLabs team. In October of the same.year, the PythonLabs team moved to Digital Creations, which became.Zope Corporation. In 2001, the Python Software Foundation (PSF, see.https://www.python.org/psf/) was formed, a non-profit organization.created specifically to own Python-related Intellectual Property..Zope Corporation was a sponsoring member of the PS
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Unicode text, UTF-8 text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3018
                                                                                                                                                                                                            Entropy (8bit):5.0579916471633
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:DtkCMU2ymXbFX1QI/aMktjaVQEBu+FOK+W6i+qXd0qme28mIp9DvvV+Vz+nlh:DtkCD/mxX1QI/aMktjaVBroBBqd0VODD
                                                                                                                                                                                                            MD5:8303191AC93E4D32457A4A9E3CDAD8E5
                                                                                                                                                                                                            SHA1:B6ADA54B9516D20B69A5DD5CDED868DA22C5E252
                                                                                                                                                                                                            SHA-256:05E51021AF1C9D86EB8D6C7E37C4CECE733D5065B91A6D8389C5690ED440F16D
                                                                                                                                                                                                            SHA-512:F2F5DBE5EA55ED720FA4191180076E9EFFCB9C811C3C7BF1A1201E9D78590B381E125EAF7B8366B28A03383C2958449423548576605E8DCB5CC11C33C9B0E709
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Metadata-Version: 2.1.Name: typing_extensions.Version: 4.12.2.Summary: Backported and Experimental Type Hints for Python 3.8+.Keywords: annotations,backport,checker,checking,function,hinting,hints,type,typechecking,typehinting,typehints,typing.Author-email: "Guido van Rossum, Jukka Lehtosalo, .ukasz Langa, Michael Lee" <levkivskyi@gmail.com>.Requires-Python: >=3.8.Description-Content-Type: text/markdown.Classifier: Development Status :: 5 - Production/Stable.Classifier: Environment :: Console.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: Python Software Foundation License.Classifier: Operating System :: OS Independent.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3 :: Only.Classifier: Programming Language :: Python :: 3.8.Classifier: Programming Language :: Python :: 3.9.Classifier: Programming Language :: Python :: 3.10.Classifier: Programming Language :: Python :: 3.11.Classifier: Programming Langua
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):571
                                                                                                                                                                                                            Entropy (8bit):5.751670348693122
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12:rCA89x0a/2zDuxv/vjWaxLbSaLjxjxXaefIE12BATqyo/C:mA87n/2zD6vXCulVZf5Cc4C
                                                                                                                                                                                                            MD5:B884E8832BFB336C2D7F54271F11EE1C
                                                                                                                                                                                                            SHA1:5A3BAABEE79E0CF32D2E87C9AF0FBB3AAD8CACAD
                                                                                                                                                                                                            SHA-256:7710002D81971E632AA6A2FC33DC5D74AAF5D7CAAE22040A65D3E31503B05EE9
                                                                                                                                                                                                            SHA-512:0A5EB3ABED212C474CB5FDDEF47F8E62DAA130128F2BB368A8E1F12E143DAE2F8B2EF4A9B85A883A03C67195829AD637DB7CF7CC4B41535AF6CA5668F8F2BD0B
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:__pycache__/typing_extensions.cpython-312.pyc,,..typing_extensions-4.12.2.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..typing_extensions-4.12.2.dist-info/LICENSE,sha256=Oy-B_iHRgcSZxZolbI4ZaEVdZonSaaqFNzv7avQdo78,13936..typing_extensions-4.12.2.dist-info/METADATA,sha256=BeUQIa8cnYbrjWx-N8TOznM9UGW5Gm2DicVpDtRA8W0,3018..typing_extensions-4.12.2.dist-info/RECORD,,..typing_extensions-4.12.2.dist-info/WHEEL,sha256=EZbGkh7Ie4PoZfRQ8I0ZuP9VklN_TvcZ6DSE5Uar4z4,81..typing_extensions.py,sha256=gwekpyG9DVG3lxWKX4ni8u7nk3We5slG98mA9F3DJQw,134451..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):81
                                                                                                                                                                                                            Entropy (8bit):4.672346887071811
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeX/QFM+vxP+tPCCfA5I:Rt1Qq2WBB3
                                                                                                                                                                                                            MD5:24019423EA7C0C2DF41C8272A3791E7B
                                                                                                                                                                                                            SHA1:AAE9ECFB44813B68CA525BA7FA0D988615399C86
                                                                                                                                                                                                            SHA-256:1196C6921EC87B83E865F450F08D19B8FF5592537F4EF719E83484E546ABE33E
                                                                                                                                                                                                            SHA-512:09AB8E4DAA9193CFDEE6CF98CCAE9DB0601F3DCD4944D07BF3AE6FA5BCB9DC0DCAFD369DE9A650A38D1B46C758DB0721EBA884446A8A5AD82BB745FD5DB5F9B1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: flit 3.9.0.Root-Is-Purelib: true.Tag: py3-none-any.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1107
                                                                                                                                                                                                            Entropy (8bit):5.115074330424529
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:PWmrRONJHLH0cPP3gtkHw1h39QHOsUv4eOk4/+jvho3nPz:ttONJbbvE/NQHOs5eNS3n7
                                                                                                                                                                                                            MD5:7FFB0DB04527CFE380E4F2726BD05EBF
                                                                                                                                                                                                            SHA1:5B39C45A91A556E5F1599604F1799E4027FA0E60
                                                                                                                                                                                                            SHA-256:30C23618679108F3E8EA1D2A658C7CA417BDFC891C98EF1A89FA4FF0C9828654
                                                                                                                                                                                                            SHA-512:205F284F3A7E8E696C70ED7B856EE98C1671C68893F0952EEC40915A383BC452B99899BDC401F9FE161A1BF9B6E2CEA3BCD90615EEE9173301657A2CE4BAFE14
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:MIT License..Copyright (c) 2012 Daniel Holth <dholth@fastmail.fm> and contributors..Permission is hereby granted, free of charge, to any person obtaining a.copy of this software and associated documentation files (the "Software"),.to deal in the Software without restriction, including without limitation.the rights to use, copy, modify, merge, publish, distribute, sublicense,.and/or sell copies of the Software, and to permit persons to whom the.Software is furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included.in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL.THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR.OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERW
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Unicode text, UTF-8 text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2153
                                                                                                                                                                                                            Entropy (8bit):5.088249746074878
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:DEhpFu5MktjaywDK48d+md+7uT8RfkD1UKd+mOl1Awry:DEhpiMktjayq/7kOfsUzmbYy
                                                                                                                                                                                                            MD5:EBEA27DA14E3F453119DC72D84343E8C
                                                                                                                                                                                                            SHA1:7CEB6DBE498B69ABF4087637C6F500742FF7E2B4
                                                                                                                                                                                                            SHA-256:59BAC22B00A59D3E5608A56B8CF8EFC43831A36B72792EE4389C9CD4669C7841
                                                                                                                                                                                                            SHA-512:A41593939B9325D40CB67FD3F41CD1C9E9978F162487FB469094C41440B5F48016B9A66BE2E6E4A0406D6EEDB25CE4F5A860BA1E3DC924B81F63CEEE3AE31117
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Metadata-Version: 2.1.Name: wheel.Version: 0.43.0.Summary: A built-package format for Python.Keywords: wheel,packaging.Author-email: Daniel Holth <dholth@fastmail.fm>.Maintainer-email: Alex Gr.nholm <alex.gronholm@nextday.fi>.Requires-Python: >=3.8.Description-Content-Type: text/x-rst.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: Topic :: System :: Archiving :: Packaging.Classifier: License :: OSI Approved :: MIT License.Classifier: Programming Language :: Python.Classifier: Programming Language :: Python :: 3 :: Only.Classifier: Programming Language :: Python :: 3.8.Classifier: Programming Language :: Python :: 3.9.Classifier: Programming Language :: Python :: 3.10.Classifier: Programming Language :: Python :: 3.11.Classifier: Programming Language :: Python :: 3.12.Requires-Dist: pytest >= 6.0.0 ; extra == "test".Requires-Dist: setuptools >= 65 ; extra == "test".Project-URL: Changelog, https://wheel.readthedocs.io/en/s
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4557
                                                                                                                                                                                                            Entropy (8bit):5.714200636114494
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:QXVuEmegx01TQIvFCiq9H/H7vp88FxTXiJPkGJP4CWweXQHmnDpMI78IegK5EeZR:QXVxAbYkU4CWweXQHmnDpMeV2BvTRqQF
                                                                                                                                                                                                            MD5:44D352C4997560C7BFB82D9360F5985A
                                                                                                                                                                                                            SHA1:BE58C7B8AB32790384E4E4F20865C4A88414B67A
                                                                                                                                                                                                            SHA-256:783E654742611AF88CD9F00BF01A431A219DB536556E63FF981C7BD673070AC9
                                                                                                                                                                                                            SHA-512:281B1D939A560E6A08D0606E5E8CE15F086B4B45738AB41ED6B5821968DC8D764CD6B25DB6BA562A07018C271ABF17A6BC5A380FAD05696ADF1D11EE2C5749C8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:../../bin/wheel,sha256=cT2EHbrv-J-UyUXu26cDY-0I7RgcruysJeHFanT1Xfo,249..wheel-0.43.0.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..wheel-0.43.0.dist-info/LICENSE.txt,sha256=MMI2GGeRCPPo6h0qZYx8pBe9_IkcmO8aifpP8MmChlQ,1107..wheel-0.43.0.dist-info/METADATA,sha256=WbrCKwClnT5WCKVrjPjvxDgxo2tyeS7kOJyc1GaceEE,2153..wheel-0.43.0.dist-info/RECORD,,..wheel-0.43.0.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..wheel-0.43.0.dist-info/WHEEL,sha256=EZbGkh7Ie4PoZfRQ8I0ZuP9VklN_TvcZ6DSE5Uar4z4,81..wheel-0.43.0.dist-info/entry_points.txt,sha256=rTY1BbkPHhkGMm4Q3F0pIzJBzW2kMxoG1oriffvGdA0,104..wheel/__init__.py,sha256=D6jhH00eMzbgrXGAeOwVfD5i-lCAMMycuG1L0useDlo,59..wheel/__main__.py,sha256=NkMUnuTCGcOkgY0IBLgBCVC_BGGcWORx2K8jYGS12UE,455..wheel/__pycache__/__init__.cpython-312.pyc,,..wheel/__pycache__/__main__.cpython-312.pyc,,..wheel/__pycache__/_setuptools_logging.cpython-312.pyc,,..wheel/__pycache__/bdist_wheel.cpython-312.pyc,,..wheel/__pycache
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):81
                                                                                                                                                                                                            Entropy (8bit):4.672346887071811
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeX/QFM+vxP+tPCCfA5I:Rt1Qq2WBB3
                                                                                                                                                                                                            MD5:24019423EA7C0C2DF41C8272A3791E7B
                                                                                                                                                                                                            SHA1:AAE9ECFB44813B68CA525BA7FA0D988615399C86
                                                                                                                                                                                                            SHA-256:1196C6921EC87B83E865F450F08D19B8FF5592537F4EF719E83484E546ABE33E
                                                                                                                                                                                                            SHA-512:09AB8E4DAA9193CFDEE6CF98CCAE9DB0601F3DCD4944D07BF3AE6FA5BCB9DC0DCAFD369DE9A650A38D1B46C758DB0721EBA884446A8A5AD82BB745FD5DB5F9B1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: flit 3.9.0.Root-Is-Purelib: true.Tag: py3-none-any.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):104
                                                                                                                                                                                                            Entropy (8bit):4.271713330022269
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:1SSAnAYgh+MWTMhk6WjrAM5t5ln:1Jb9WTMhk9jUM5t5ln
                                                                                                                                                                                                            MD5:6180E17C30BAE5B30DB371793FCE0085
                                                                                                                                                                                                            SHA1:E3A12C421562A77D90A13D8539A3A0F4D3228359
                                                                                                                                                                                                            SHA-256:AD363505B90F1E1906326E10DC5D29233241CD6DA4331A06D68AE27DFBC6740D
                                                                                                                                                                                                            SHA-512:69EAE7B1E181D7BA1D3E2864D31E1320625A375E76D3B2FBF8856B3B6515936ACE3138D4D442CABDE7576FCFBCBB0DEED054D90B95CFA1C99829DB12A9031E26
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:[console_scripts].wheel=wheel.cli:main..[distutils.commands].bdist_wheel=wheel.bdist_wheel:bdist_wheel..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1023
                                                                                                                                                                                                            Entropy (8bit):5.059832621894572
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:OrmJHcwH0MP3gt8Hw1hj9QHOsUv4eOk4/+/m3oqMSFJ:OaJ8YHvEH5QHOs5exm3oEFJ
                                                                                                                                                                                                            MD5:141643E11C48898150DAA83802DBC65F
                                                                                                                                                                                                            SHA1:0445ED0F69910EEAEE036F09A39A13C6E1F37E12
                                                                                                                                                                                                            SHA-256:86DA0F01AEAE46348A3C3D465195DC1CECCDE79F79E87769A64B8DA04B2A4741
                                                                                                                                                                                                            SHA-512:EF62311602B466397BAF0B23CACA66114F8838F9E78E1B067787CEB709D09E0530E85A47BBCD4C5A0905B74FDB30DF0CC640910C6CC2E67886E5B18794A3583F
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Permission is hereby granted, free of charge, to any person obtaining a copy.of this software and associated documentation files (the "Software"), to.deal in the Software without restriction, including without limitation the.rights to use, copy, modify, merge, publish, distribute, sublicense, and/or.sell copies of the Software, and to permit persons to whom the Software is.furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in.all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE.AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER.LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING.FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEA
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3575
                                                                                                                                                                                                            Entropy (8bit):5.085545958857746
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:D0h4aC/S802Vpnu3pyt1Q+/+DeVb0ksYSwTgD:Oc/z02Vpnu3pytS+2DeVNfSwTW
                                                                                                                                                                                                            MD5:F659E7F578CE6FD3753871DBBBA1F939
                                                                                                                                                                                                            SHA1:C53B0E6A2E3D94093E2FE4978926A7439B47D43C
                                                                                                                                                                                                            SHA-256:508AE4FE43081C64B0B0A2828588B3A8CC3430C6693D1676662569400B0DFDB1
                                                                                                                                                                                                            SHA-512:2C0496B76D259259A8F1E57F3ED2224A7E3E99FF309F764C00A8377BB5BD1C94035BDDF24BD1BA637209677CB9F4E8109F84C50B3488B5B8FC372B6BEDAB9AE0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Metadata-Version: 2.1.Name: zipp.Version: 3.19.2.Summary: Backport of pathlib-compatible object wrapper for zip files.Author-email: "Jason R. Coombs" <jaraco@jaraco.com>.Project-URL: Homepage, https://github.com/jaraco/zipp.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: MIT License.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3 :: Only.Requires-Python: >=3.8.Description-Content-Type: text/x-rst.License-File: LICENSE.Provides-Extra: doc.Requires-Dist: sphinx >=3.5 ; extra == 'doc'.Requires-Dist: jaraco.packaging >=9.3 ; extra == 'doc'.Requires-Dist: rst.linker >=1.9 ; extra == 'doc'.Requires-Dist: furo ; extra == 'doc'.Requires-Dist: sphinx-lint ; extra == 'doc'.Requires-Dist: jaraco.tidelift >=1.4 ; extra == 'doc'.Provides-Extra: test.Requires-Dist: pytest !=8.1.*,>=6 ; extra == 'test'.Requires-Dist: pytest-checkdocs >=2.4 ; extra == 'test'.Requir
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1039
                                                                                                                                                                                                            Entropy (8bit):5.8094923667268965
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:An/2zDlvbqfuiwbWk/EsJ6Xam9lpW8OWq3tW36nJA3u3iWwksYW:AnuXlzUuitk/5J6f9lpW8OW4tM6nJSkE
                                                                                                                                                                                                            MD5:1E77310EF3277C93430D969FEAC8FDFC
                                                                                                                                                                                                            SHA1:173240337F249E2A6D54206AA0D0ACB0FDED12D7
                                                                                                                                                                                                            SHA-256:F316F2E03FD9ADE7EBBC0B154706848E2BB8FD568B90935109F0D8E3CE2B9BFE
                                                                                                                                                                                                            SHA-512:68F752DAF2DBEB79644337E4DB9B8CEAEAE3606A865EDC32BE16785DC97BDCF38EF200F0EDC86DC9D71ABA72E108D2851A510F0EB598FFEA286503F0C9772E5E
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:zipp-3.19.2.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..zipp-3.19.2.dist-info/LICENSE,sha256=htoPAa6uRjSKPD1GUZXcHOzN55956HdppkuNoEsqR0E,1023..zipp-3.19.2.dist-info/METADATA,sha256=UIrk_kMIHGSwsKKChYizqMw0MMZpPRZ2ZiVpQAsN_bE,3575..zipp-3.19.2.dist-info/RECORD,,..zipp-3.19.2.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..zipp-3.19.2.dist-info/WHEEL,sha256=GJ7t_kWBFywbagK5eo9IoUwLW6oyOeTKmQ-9iHFVNxQ,92..zipp-3.19.2.dist-info/top_level.txt,sha256=iAbdoSHfaGqBfVb2XuR9JqSQHCoOsOtG6y9C_LSpqFw,5..zipp/__init__.py,sha256=QuI1g00G4fRAcGt-HqbV0oWIkmSgedCGGYsHHYzNa8A,13412..zipp/__pycache__/__init__.cpython-312.pyc,,..zipp/__pycache__/glob.cpython-312.pyc,,..zipp/compat/__init__.py,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..zipp/compat/__pycache__/__init__.cpython-312.pyc,,..zipp/compat/__pycache__/py310.cpython-312.pyc,,..zipp/compat/py310.py,sha256=eZpkW0zRtunkhEh8jjX3gCGe22emoKCBJw72Zt4RkhA,219..zipp/glob.py,sha256=etWpnfEoRyf
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):92
                                                                                                                                                                                                            Entropy (8bit):4.812622295095324
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeX7MWcSlVlFxP+tPCCfA5S:RtBMwlVTxWBBf
                                                                                                                                                                                                            MD5:43136DDE7DD276932F6197BB6D676EF4
                                                                                                                                                                                                            SHA1:6B13C105452C519EA0B65AC1A975BD5E19C50122
                                                                                                                                                                                                            SHA-256:189EEDFE4581172C1B6A02B97A8F48A14C0B5BAA3239E4CA990FBD8871553714
                                                                                                                                                                                                            SHA-512:E7712BA7D36DEB083EBCC3B641AD3E7D19FB071EE64AE3A35AD6A50EE882B20CD2E60CA1319199DF12584FE311A6266EC74F96A3FB67E59F90C7B5909668AEE1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: bdist_wheel (0.43.0).Root-Is-Purelib: true.Tag: py3-none-any..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):5
                                                                                                                                                                                                            Entropy (8bit):1.9219280948873623
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:m:m
                                                                                                                                                                                                            MD5:9B929466EC7848714DE24BCF75AE57CB
                                                                                                                                                                                                            SHA1:ECC9237295CDA9B690BE094E58FAE1458A4B0389
                                                                                                                                                                                                            SHA-256:8806DDA121DF686A817D56F65EE47D26A4901C2A0EB0EB46EB2F42FCB4A9A85C
                                                                                                                                                                                                            SHA-512:C8D8967BE2B5094A5D72BA4BEF5DBDA2CBF539BF3B8B916CF86854087A12DF82B51B7BF5B6EFA79898692EFD22FAD9688058448CAAB198FB708A0E661DC685EA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:zipp.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1816344
                                                                                                                                                                                                            Entropy (8bit):6.49505595200629
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24576:pAZ2kQrvqkPY6i6ktWc2uMOxmWu1/0lglMkgshwlfjwtorWy2eMdPhOC9JlQ5ZDA:pA0W9jEoSy2nd9JlQjaq5vWHZ7XM2eDi
                                                                                                                                                                                                            MD5:BED46AA40C392C9068AED5F94857D398
                                                                                                                                                                                                            SHA1:227561D5F6A592DEDD7A8B0FFE0C284F9BBF23E8
                                                                                                                                                                                                            SHA-256:22A1746363151A19E02F92F9B7BC4849038783BE34C04F311A11DF69FDC1A039
                                                                                                                                                                                                            SHA-512:04850421617366FAEAA711FD28DCF58FF1BC5AA2B0CB962FBFC47B5AE645B3726F3DECC19D0B36B23C6B00210BADEEFC67F83BA6F0A81D6DE57DC27001AC19BE
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@................................... ...........!..L.!This program cannot be run in DOS mode....$.......1.y+u..xu..xu..x...yw..x...xv..x...yx..x...y}..x...yq..x..yw..x|..xg..x...yt..x...yx..xu..x]..x...y...x...yt..x...xt..x...yt..xRichu..x........................PE..d...1,.c.........." ...!............................................................4.....`..............................................`.. _..h.......8................/..........................................`...@............0...............................text............................... ..`.rdata..|L...0...N..................@..@.data...."...........f..............@....pdata...............n..............@..@.rsrc...8............f..............@..@.reloc...............j..............@..B................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):11707
                                                                                                                                                                                                            Entropy (8bit):5.03328629946697
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:rXlm2LnoZ7k2mOEhYoKVtWD2xLsmF+MNlPQ4lJ+B0O0DgryYY/+zy7go:rXlm2Lng7kvF2VtWD2xLeMNT+B0O0Urk
                                                                                                                                                                                                            MD5:A0B269D76DB613C2D927EFA84FEE88E2
                                                                                                                                                                                                            SHA1:F9C7AD375F4D4223F0668FA1E2C4E5A83CAC2D03
                                                                                                                                                                                                            SHA-256:32348D51F3637F375B056FE99E9B4D89D85D45DB907847DC370BD72812A2E2FE
                                                                                                                                                                                                            SHA-512:5427762147825DC2ED3FEEE4011BBF2100932A4D93F3242CCAD15499C9DC39F42A82AEB42ED5DB5839560CD7AAE5D30621AC3694552FFC650A1F572CEE32FA54
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# -*- tcl -*-..# ### ### ### ######### ######### #########..## Overview....# Heuristics to assemble a platform identifier from publicly available..# information. The identifier describes the platform of the currently..# running tcl shell. This is a mixture of the runtime environment and..# of build-time properties of the executable itself...#..# Examples:..# <1> A tcl shell executing on a x86_64 processor, but having a..# wordsize of 4 was compiled for the x86 environment, i.e. 32..# bit, and loaded packages have to match that, and not the..# actual cpu...#..# <2> The hp/solaris 32/64 bit builds of the core cannot be..# distinguished by looking at tcl_platform. As packages have to..# match the 32/64 information we have to look in more places. In..# this case we inspect the executable itself (magic numbers,..# i.e. fileutil::magic::filetype)...#..# The basic information used comes out of the 'os' and 'machine'..# entries of the 'tcl_platform' array. A number of general and
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Tcl script, ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):6218
                                                                                                                                                                                                            Entropy (8bit):4.843141834641668
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:192:PV5U+VLnNUPVvH+knNUPVUHD5ngWftN+IgMufIdqi+g0SYiCXVDjqL:Nm6MFXN5uwq51iCFD2
                                                                                                                                                                                                            MD5:8ABC3029963E433D1D9865AAA7E1057B
                                                                                                                                                                                                            SHA1:A88091DC98B2FD0AE3A258B59F8BE43F41F04323
                                                                                                                                                                                                            SHA-256:0A6B4B109CFDFC4B40FBDEFDB2282F9B1AF3CC2F9624DD39958EEBD78781AFB2
                                                                                                                                                                                                            SHA-512:D5068375615A2200DDC13EEB852B2E21B7E4AA416FB7A0E97C98B8B106D7701792C523739E8BF266D2ABE411D4298A0B5B3884CFB9DF820FD4A2B61B22F9DECF
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:..# -*- tcl -*-..# ### ### ### ######### ######### #########..## Overview....# Higher-level commands which invoke the functionality of this package..# for an arbitrary tcl shell (tclsh, wish, ...). This is required by a..# repository as while the tcl shell executing packages uses the same..# platform in general as a repository application there can be..# differences in detail (i.e. 32/64 bit builds).....# ### ### ### ######### ######### #########..## Requirements....package require platform..namespace eval ::platform::shell {}....# ### ### ### ######### ######### #########..## Implementation....# -- platform::shell::generic....proc ::platform::shell::generic {shell} {.. # Argument is the path to a tcl shell..... CHECK $shell.. LOCATE base out.... set code {}.. # Forget any pre-existing platform package, it might be in.. # conflict with this one... lappend code {package forget platform}.. # Inject our platform package.. lappend code [list source $base]..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Tcl script, ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):35136
                                                                                                                                                                                                            Entropy (8bit):4.945501767273492
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:768:m3xQvCzasI/rHPG2yfkZ0Kbh91iQ3Lnq5MIVYB8mbgijsPIWtw4qvUm:4xQvCzasIDHPG2yW0kJ32imXmUij6JjG
                                                                                                                                                                                                            MD5:BD4FF2A1F742D9E6E699EEEE5E678AD1
                                                                                                                                                                                                            SHA1:811AD83AFF80131BA73ABC546C6BD78453BF3EB9
                                                                                                                                                                                                            SHA-256:6774519F179872EC5292523F2788B77B2B839E15665037E097A0D4EDDDD1C6FB
                                                                                                                                                                                                            SHA-512:B77E4A68017BA57C06876B21B8110C636F9BA1DD0BA9D7A0C50096F3F6391508CF3562DD94ACEAF673113DBD336109DA958044AEFAC0AFB0F833A652E4438F43
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# msgcat.tcl --..#..#.This file defines various procedures which implement a..#.message catalog facility for Tcl programs. It should be..#.loaded with the command "package require msgcat"...#..# Copyright (c) 2010-2015 Harald Oehlmann...# Copyright (c) 1998-2000 Ajuba Solutions...# Copyright (c) 1998 Mark Harrison...#..# See the file "license.terms" for information on usage and redistribution..# of this file, and for a DISCLAIMER OF ALL WARRANTIES.....package require Tcl 8.5-..# When the version number changes, be sure to update the pkgIndex.tcl file,..# and the installation directory in the Makefiles...package provide msgcat 1.6.1....namespace eval msgcat {.. namespace export mc mcexists mcload mclocale mcmax mcmset mcpreferences mcset\.. mcunknown mcflset mcflmset mcloadedlocales mcforgetpackage\... mcpackageconfig mcpackagelocale.... # Records the list of locales to search.. variable Loclist {}.... # List of currently loaded locales.. variable LoadedLoc
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Tcl script, Unicode text, UTF-8 text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):107674
                                                                                                                                                                                                            Entropy (8bit):4.841458743618635
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3072:74s6YTLsaoi4N8uBPM5PP9AlGXJL/ciBh:7N6Y9oi4N8uBPM5PP9AYXJL/ciBh
                                                                                                                                                                                                            MD5:655EC828777244F9F048E0D08203482F
                                                                                                                                                                                                            SHA1:790446D04FE7BE12FD5DCF6E6FBD4C5A08C45C98
                                                                                                                                                                                                            SHA-256:35A88F56DF57E6AC6F2CCC4D193210FBB9BD224AC99670603E077DDF8C5610BC
                                                                                                                                                                                                            SHA-512:C249CAA5DA76A0B0876DD1BD201FF2D249D4FCD8467992C9DE51BA5A1C5471F98C10D69C46DF5B25DBA7941F4301B446D90CBF17BCCFB8B0ED27B22BF4DA20F3
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# tcltest.tcl --..#..#.This file contains support code for the Tcl test suite. It..# defines the tcltest namespace and finds and defines the output..# directory, constraints available, output and error channels,..#.etc. used by Tcl tests. See the tcltest man page for more..#.details...#..# This design was based on the Tcl testing approach designed and..# initially implemented by Mary Ann May-Pumphrey of Sun..#.Microsystems...#..# Copyright . 1994-1997 Sun Microsystems, Inc...# Copyright . 1998-1999 Scriptics Corporation...# Copyright . 2000 Ajuba Solutions..# Contributions from Don Porter, NIST, 2002. (not subject to US copyright)..# All rights reserved.....package require Tcl 8.5-..;# -verbose line uses [info frame]..namespace eval tcltest {.... # When the version number changes, be sure to update the pkgIndex.tcl file,.. # and the install directory in the Makefiles. When the minor version.. # changes (new feature) be sure to update the man page
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Tcl script, ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):118419
                                                                                                                                                                                                            Entropy (8bit):4.888789841897662
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:1536:RYY1IO/KuUhIW17zr1DLJuuBuFsj6aIsGc3e6xGxjndp72y4ebBxIQ30Ik:RbyOCuUv9r5LJmsjlxTxGxjndpCBeAQ0
                                                                                                                                                                                                            MD5:ACB85FEB97B27F1362E1D76B686D498F
                                                                                                                                                                                                            SHA1:92C370F838BD67C72E153FBF7AD05E26FF40A393
                                                                                                                                                                                                            SHA-256:7A30E7A49C1F6939537EB7A80CF2F5BC7A4969F2B2AD99BA4E26DB85BBC2FCC7
                                                                                                                                                                                                            SHA-512:EA504863386817E1B21549376148FD05C7EAF74F91A3A8DA97EFCF3784530ED3CF1910DF9B2431EC47D1175759CDEB1A0E9E9E02BBA94EC2123EAFB7CBD2B90A
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:# http.tcl --..#..#.Client-side HTTP for GET, POST, and HEAD commands. These routines can..#.be used in untrusted code that uses the Safesock security policy...#.These procedures use a callback interface to avoid using vwait, which..#.is not defined in the safe base...#..# See the file "license.terms" for information on usage and redistribution of..# this file, and for a DISCLAIMER OF ALL WARRANTIES.....package require Tcl 8.6-..# Keep this in sync with pkgIndex.tcl and with the install directories in..# Makefiles..package provide http 2.9.8....namespace eval http {.. # Allow resourcing to not clobber existing data.... variable http.. if {![info exists http]} {...array set http {... -accept */*... -pipeline 1... -postfresh 0... -proxyhost {}... -proxyport {}... -proxyfilter http::ProxyRequired... -repost 0... -urlencoding utf-8... -zip 1...}...# We need a useragent string of this style or various servers will...# refuse to send us compressed content
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1555736
                                                                                                                                                                                                            Entropy (8bit):6.18213758091142
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24576:gF3uXVFKflt2zwvzPYHURwgVdF9EWyCzfdmHQnveD4CGan9nViFoHb15K3cmwdbs:2eFSpvzg0RwgVdF9EWyCzfdmHQnveD4N
                                                                                                                                                                                                            MD5:6DDB534EF5C74627802CEEF0C90B38F3
                                                                                                                                                                                                            SHA1:FFA3B78435E7A121BA6A3DE32A7C3950A3F1CB28
                                                                                                                                                                                                            SHA-256:F44FA94865D17E4F0266C8F9A1DD89825D8A0C6C3A63CF4192FC08C8796ACABF
                                                                                                                                                                                                            SHA-512:0CF66EEAA3AEF2C7DA560C370865BBD84AC2E94536BF751907BF42F36C05B5D0C46F883B1F35DAF9E21E8EEC1A7FCAD439E21A23E114AB0A3A0DAF39E8C95EB0
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......y.P.=n>.=n>.=n>...?.?n>...;.1n>...:.5n>...=.9n>...:.>n>...:.<n>.4...-n>...?.(n>.=n?.wo>...6..n>...>.<n>.....<n>...<.<n>.Rich=n>.................PE..d...],.c.........." ...!............|...............................................V.....`..........................................?..L@..,...|........{...P..D......../.......E...T...............................S..@...............@............................text...h........................... ..`.rdata..0...........................@..@.data...............................@....pdata..D....P......................@..@.rsrc....{.......|..................@..@.reloc...E.......F...H..............@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Unicode text, UTF-8 text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1130
                                                                                                                                                                                                            Entropy (8bit):5.118590213496374
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:qt4rWHvH0yPP3Gt6Hw1hP9QHmsUv48OV/+dho3BoqxFB:/S/lPvKhlQHms5QK3WmFB
                                                                                                                                                                                                            MD5:F0E423EEA5C91E7AA21BDB70184B3E53
                                                                                                                                                                                                            SHA1:A51CCDCB7A9D8C2116D1DFC16F11B3C8A5830F67
                                                                                                                                                                                                            SHA-256:6163F7987DFB38D6BC320CE2B70B2F02B862BC41126516D552EF1CD43247E758
                                                                                                                                                                                                            SHA-512:8BE742880E6E8495C7EC4C9ECC8F076A9FC9D64FC84B3AEBBC8D2D10DC62AC2C5053F33B716212DCB76C886A9C51619F262C460FC4B39A335CE1AE2C9A8769A8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:This is the MIT license: http://www.opensource.org/licenses/mit-license.php..Copyright (c) Alex Gr.nholm..Permission is hereby granted, free of charge, to any person obtaining a copy of this.software and associated documentation files (the "Software"), to deal in the Software.without restriction, including without limitation the rights to use, copy, modify, merge,.publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons.to whom the Software is furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included in all copies or.substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED,.INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR.PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE.FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF C
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Unicode text, UTF-8 text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):3717
                                                                                                                                                                                                            Entropy (8bit):4.986068381037722
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:DSQRbraktjaAckH94jQnJIK04Fak/grjspC3EklAJj:/Rakd4jA7ak/gvspNWmj
                                                                                                                                                                                                            MD5:B6DAAC02F66AC8403E9061881322BABE
                                                                                                                                                                                                            SHA1:9A94672CCFEA06156A5F8A321CD0626CFD233AE8
                                                                                                                                                                                                            SHA-256:CF675C1C0A744F08580855390DE87CC77D676B312582E8D4CFDB5BB8FD298D21
                                                                                                                                                                                                            SHA-512:9C6B7326C90396AA9E962C2731A1085EDB672B5696F95F552D13350843C09A246E0BBF0EC484862DFF434FA5A86DE4C0B7C963958ADE35A066B9D2384076DD47
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Metadata-Version: 2.1.Name: typeguard.Version: 4.3.0.Summary: Run-time type checker for Python.Author-email: Alex Gr.nholm <alex.gronholm@nextday.fi>.License: MIT.Project-URL: Documentation, https://typeguard.readthedocs.io/en/latest/.Project-URL: Change log, https://typeguard.readthedocs.io/en/latest/versionhistory.html.Project-URL: Source code, https://github.com/agronholm/typeguard.Project-URL: Issue tracker, https://github.com/agronholm/typeguard/issues.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: License :: OSI Approved :: MIT License.Classifier: Programming Language :: Python.Classifier: Programming Language :: Python :: 3.Classifier: Programming Language :: Python :: 3.8.Classifier: Programming Language :: Python :: 3.9.Classifier: Programming Language :: Python :: 3.10.Classifier: Programming Language :: Python :: 3.11.Classifier: Programming Language :: Python :: 3.12.Requires-Python: >=3.8.Description-Content
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2402
                                                                                                                                                                                                            Entropy (8bit):5.729208478282605
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:eDnuX3DVED9HDDeDfPDLkAosGDlDiVoBFj7XH0H3HuwVB6Kgfkx7J/Q1NK1cQyxk:eyX3WRHDiLPjksV7I47J/Q1U6Qyx5fsJ
                                                                                                                                                                                                            MD5:D680B2881597974ACD91750E5AB61010
                                                                                                                                                                                                            SHA1:E00ED2416B5CE21641E3946905504D62D536972F
                                                                                                                                                                                                            SHA-256:48A51959582478352275428CEECD78EF77D79AC9DAE796E39A2EAF2540282552
                                                                                                                                                                                                            SHA-512:112172ACB515B0712AC58D78898EB159580ADA3DD3F16AABB37CB7A8D964F9E4BADF2869A245927B83B208D56904831C0F04ED925C95DFCB705801734FB0C7BA
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:typeguard-4.3.0.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..typeguard-4.3.0.dist-info/LICENSE,sha256=YWP3mH37ONa8MgzitwsvArhivEESZRbVUu8c1DJH51g,1130..typeguard-4.3.0.dist-info/METADATA,sha256=z2dcHAp0TwhYCFU5Deh8x31nazElgujUz9tbuP0pjSE,3717..typeguard-4.3.0.dist-info/RECORD,,..typeguard-4.3.0.dist-info/WHEEL,sha256=GJ7t_kWBFywbagK5eo9IoUwLW6oyOeTKmQ-9iHFVNxQ,92..typeguard-4.3.0.dist-info/entry_points.txt,sha256=qp7NQ1aLtiSgMQqo6gWlfGpy0IIXzoMJmeQTLpzqFZQ,48..typeguard-4.3.0.dist-info/top_level.txt,sha256=4z28AhuDodwRS_c1J_l8H51t5QuwfTseskYzlxp6grs,10..typeguard/__init__.py,sha256=Onh4w38elPCjtlcU3JY9k3h70NjsxXIkAflmQn-Z0FY,2071..typeguard/__pycache__/__init__.cpython-312.pyc,,..typeguard/__pycache__/_checkers.cpython-312.pyc,,..typeguard/__pycache__/_config.cpython-312.pyc,,..typeguard/__pycache__/_decorators.cpython-312.pyc,,..typeguard/__pycache__/_exceptions.cpython-312.pyc,,..typeguard/__pycache__/_functions.cpython-312.pyc,,..typeguard/__pycache__/_i
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):92
                                                                                                                                                                                                            Entropy (8bit):4.812622295095324
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeX7MWcSlVlFxP+tPCCfA5S:RtBMwlVTxWBBf
                                                                                                                                                                                                            MD5:43136DDE7DD276932F6197BB6D676EF4
                                                                                                                                                                                                            SHA1:6B13C105452C519EA0B65AC1A975BD5E19C50122
                                                                                                                                                                                                            SHA-256:189EEDFE4581172C1B6A02B97A8F48A14C0B5BAA3239E4CA990FBD8871553714
                                                                                                                                                                                                            SHA-512:E7712BA7D36DEB083EBCC3B641AD3E7D19FB071EE64AE3A35AD6A50EE882B20CD2E60CA1319199DF12584FE311A6266EC74F96A3FB67E59F90C7B5909668AEE1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: bdist_wheel (0.43.0).Root-Is-Purelib: true.Tag: py3-none-any..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):48
                                                                                                                                                                                                            Entropy (8bit):4.155187698990101
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:mWSJCQEjMitjHfLvn:mrMJHfbn
                                                                                                                                                                                                            MD5:AEAB5BCF8BF89A51C97C4CDF70578848
                                                                                                                                                                                                            SHA1:2E9C1617560AB66431AAB90700DB901985293485
                                                                                                                                                                                                            SHA-256:AA9ECD43568BB624A0310AA8EA05A57C6A72D08217CE830999E4132E9CEA1594
                                                                                                                                                                                                            SHA-512:2BE73E99296DF26A28835F91DD8BC50EB104AF06A3C54666175FAF322E0AD4620453DB0388531C4113B052A92C1D2E4C3088E25AF43CDE42AA852CF7B0CB5B05
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:[pytest11].typeguard = typeguard._pytest_plugin.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):10
                                                                                                                                                                                                            Entropy (8bit):3.321928094887362
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:LEJn:M
                                                                                                                                                                                                            MD5:004A2A8CE1AB120A63902A27D76BD964
                                                                                                                                                                                                            SHA1:A4E367AB40410598DADD1FC5F680ED7A176BEB09
                                                                                                                                                                                                            SHA-256:E33DBC021B83A1DC114BF73527F97C1F9D6DE50BB07D3B1EB24633971A7A82BB
                                                                                                                                                                                                            SHA-512:0D8FF9A43897AB390AB41AFE5BAC8BD38A68C2BEF88E844E5B49BF70E3164B226975CC2717AE3DC3428D1CFBB0BE068C243F104915FEE1FFA58C23FBE76FDB89
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:typeguard.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (GUI) x86-64, for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1138456
                                                                                                                                                                                                            Entropy (8bit):5.4617453207817395
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:12288:FrEHdcM6hbaCjJ43w9hIpCQvb0QN8MdIEQ+U2BNNmD+99FfcQoC:FrEX/Cjfk7bPNfv42BN6yzUQoC
                                                                                                                                                                                                            MD5:098CC6AD04199442C3E2A60E1243C2DC
                                                                                                                                                                                                            SHA1:4C92C464A8E1E56E1C4D77CD30A0DA474A026AAF
                                                                                                                                                                                                            SHA-256:64A162D6B11BA10CB11509F3CC445F17BEB7ACFD064F030B4D59FAA1C9894B29
                                                                                                                                                                                                            SHA-512:73C28488B42A0BC2F0D2861FED3F5DCCCF8959CE19D3121C13C998DB496F2822DEB40F36F86240C8D3954FD2DC2BA5D63C8A125B62324DCD92FB6C8BA49FF170
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$........................(.....(.....(.....(.....)................).....).....)x....)....Rich..........................PE..d....g.f.........." ...).@..........0*.......................................p......U.....`.........................................p...X............P.......@.......0.../...`......P^..T............................]..@............P..p............................text....>.......@.................. ..`.rdata..\....P.......D..............@..@.data........ ......................@....pdata.......@......................@..@.rsrc........P.......$..............@..@.reloc.......`......................@..B................................................................................................................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4
                                                                                                                                                                                                            Entropy (8bit):1.5
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:Mn:M
                                                                                                                                                                                                            MD5:365C9BFEB7D89244F2CE01C1DE44CB85
                                                                                                                                                                                                            SHA1:D7A03141D5D6B1E88B6B59EF08B6681DF212C599
                                                                                                                                                                                                            SHA-256:CEEBAE7B8927A3227E5303CF5E0F1F7B34BB542AD7250AC03FBCDE36EC2F1508
                                                                                                                                                                                                            SHA-512:D220D322A4053D84130567D626A9F7BB2FB8F0B854DA1621F001826DC61B0ED6D3F91793627E6F0AC2AC27AEA2B986B6A7A63427F05FE004D8A2ADFBDADC13C1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:pip.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):1107
                                                                                                                                                                                                            Entropy (8bit):5.115074330424529
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:24:PWmrRONJHLH0cPP3gtkHw1h39QHOsUv4eOk4/+jvho3nPz:ttONJbbvE/NQHOs5eNS3n7
                                                                                                                                                                                                            MD5:7FFB0DB04527CFE380E4F2726BD05EBF
                                                                                                                                                                                                            SHA1:5B39C45A91A556E5F1599604F1799E4027FA0E60
                                                                                                                                                                                                            SHA-256:30C23618679108F3E8EA1D2A658C7CA417BDFC891C98EF1A89FA4FF0C9828654
                                                                                                                                                                                                            SHA-512:205F284F3A7E8E696C70ED7B856EE98C1671C68893F0952EEC40915A383BC452B99899BDC401F9FE161A1BF9B6E2CEA3BCD90615EEE9173301657A2CE4BAFE14
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:MIT License..Copyright (c) 2012 Daniel Holth <dholth@fastmail.fm> and contributors..Permission is hereby granted, free of charge, to any person obtaining a.copy of this software and associated documentation files (the "Software"),.to deal in the Software without restriction, including without limitation.the rights to use, copy, modify, merge, publish, distribute, sublicense,.and/or sell copies of the Software, and to permit persons to whom the.Software is furnished to do so, subject to the following conditions:..The above copyright notice and this permission notice shall be included.in all copies or substantial portions of the Software...THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR.IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,.FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL.THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR.OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERW
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:Unicode text, UTF-8 text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):2153
                                                                                                                                                                                                            Entropy (8bit):5.088249746074878
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:48:DEhpFu5MktjaywDK48d+md+7uT8RfkD1UKd+mOl1Awry:DEhpiMktjayq/7kOfsUzmbYy
                                                                                                                                                                                                            MD5:EBEA27DA14E3F453119DC72D84343E8C
                                                                                                                                                                                                            SHA1:7CEB6DBE498B69ABF4087637C6F500742FF7E2B4
                                                                                                                                                                                                            SHA-256:59BAC22B00A59D3E5608A56B8CF8EFC43831A36B72792EE4389C9CD4669C7841
                                                                                                                                                                                                            SHA-512:A41593939B9325D40CB67FD3F41CD1C9E9978F162487FB469094C41440B5F48016B9A66BE2E6E4A0406D6EEDB25CE4F5A860BA1E3DC924B81F63CEEE3AE31117
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Metadata-Version: 2.1.Name: wheel.Version: 0.43.0.Summary: A built-package format for Python.Keywords: wheel,packaging.Author-email: Daniel Holth <dholth@fastmail.fm>.Maintainer-email: Alex Gr.nholm <alex.gronholm@nextday.fi>.Requires-Python: >=3.8.Description-Content-Type: text/x-rst.Classifier: Development Status :: 5 - Production/Stable.Classifier: Intended Audience :: Developers.Classifier: Topic :: System :: Archiving :: Packaging.Classifier: License :: OSI Approved :: MIT License.Classifier: Programming Language :: Python.Classifier: Programming Language :: Python :: 3 :: Only.Classifier: Programming Language :: Python :: 3.8.Classifier: Programming Language :: Python :: 3.9.Classifier: Programming Language :: Python :: 3.10.Classifier: Programming Language :: Python :: 3.11.Classifier: Programming Language :: Python :: 3.12.Requires-Dist: pytest >= 6.0.0 ; extra == "test".Requires-Dist: setuptools >= 65 ; extra == "test".Project-URL: Changelog, https://wheel.readthedocs.io/en/s
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:CSV text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):4557
                                                                                                                                                                                                            Entropy (8bit):5.714200636114494
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:96:QXVuEmegx01TQIvFCiq9H/H7vp88FxTXiJPkGJP4CWweXQHmnDpMI78IegK5EeZR:QXVxAbYkU4CWweXQHmnDpMeV2BvTRqQF
                                                                                                                                                                                                            MD5:44D352C4997560C7BFB82D9360F5985A
                                                                                                                                                                                                            SHA1:BE58C7B8AB32790384E4E4F20865C4A88414B67A
                                                                                                                                                                                                            SHA-256:783E654742611AF88CD9F00BF01A431A219DB536556E63FF981C7BD673070AC9
                                                                                                                                                                                                            SHA-512:281B1D939A560E6A08D0606E5E8CE15F086B4B45738AB41ED6B5821968DC8D764CD6B25DB6BA562A07018C271ABF17A6BC5A380FAD05696ADF1D11EE2C5749C8
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:../../bin/wheel,sha256=cT2EHbrv-J-UyUXu26cDY-0I7RgcruysJeHFanT1Xfo,249..wheel-0.43.0.dist-info/INSTALLER,sha256=zuuue4knoyJ-UwPPXg8fezS7VCrXJQrAP7zeNuwvFQg,4..wheel-0.43.0.dist-info/LICENSE.txt,sha256=MMI2GGeRCPPo6h0qZYx8pBe9_IkcmO8aifpP8MmChlQ,1107..wheel-0.43.0.dist-info/METADATA,sha256=WbrCKwClnT5WCKVrjPjvxDgxo2tyeS7kOJyc1GaceEE,2153..wheel-0.43.0.dist-info/RECORD,,..wheel-0.43.0.dist-info/REQUESTED,sha256=47DEQpj8HBSa-_TImW-5JCeuQeRkm5NMpJWZG3hSuFU,0..wheel-0.43.0.dist-info/WHEEL,sha256=EZbGkh7Ie4PoZfRQ8I0ZuP9VklN_TvcZ6DSE5Uar4z4,81..wheel-0.43.0.dist-info/entry_points.txt,sha256=rTY1BbkPHhkGMm4Q3F0pIzJBzW2kMxoG1oriffvGdA0,104..wheel/__init__.py,sha256=D6jhH00eMzbgrXGAeOwVfD5i-lCAMMycuG1L0useDlo,59..wheel/__main__.py,sha256=NkMUnuTCGcOkgY0IBLgBCVC_BGGcWORx2K8jYGS12UE,455..wheel/__pycache__/__init__.cpython-312.pyc,,..wheel/__pycache__/__main__.cpython-312.pyc,,..wheel/__pycache__/_setuptools_logging.cpython-312.pyc,,..wheel/__pycache__/bdist_wheel.cpython-312.pyc,,..wheel/__pycache
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):81
                                                                                                                                                                                                            Entropy (8bit):4.672346887071811
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:RtEeX/QFM+vxP+tPCCfA5I:Rt1Qq2WBB3
                                                                                                                                                                                                            MD5:24019423EA7C0C2DF41C8272A3791E7B
                                                                                                                                                                                                            SHA1:AAE9ECFB44813B68CA525BA7FA0D988615399C86
                                                                                                                                                                                                            SHA-256:1196C6921EC87B83E865F450F08D19B8FF5592537F4EF719E83484E546ABE33E
                                                                                                                                                                                                            SHA-512:09AB8E4DAA9193CFDEE6CF98CCAE9DB0601F3DCD4944D07BF3AE6FA5BCB9DC0DCAFD369DE9A650A38D1B46C758DB0721EBA884446A8A5AD82BB745FD5DB5F9B1
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:Wheel-Version: 1.0.Generator: flit 3.9.0.Root-Is-Purelib: true.Tag: py3-none-any.
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):104
                                                                                                                                                                                                            Entropy (8bit):4.271713330022269
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:1SSAnAYgh+MWTMhk6WjrAM5t5ln:1Jb9WTMhk9jUM5t5ln
                                                                                                                                                                                                            MD5:6180E17C30BAE5B30DB371793FCE0085
                                                                                                                                                                                                            SHA1:E3A12C421562A77D90A13D8539A3A0F4D3228359
                                                                                                                                                                                                            SHA-256:AD363505B90F1E1906326E10DC5D29233241CD6DA4331A06D68AE27DFBC6740D
                                                                                                                                                                                                            SHA-512:69EAE7B1E181D7BA1D3E2864D31E1320625A375E76D3B2FBF8856B3B6515936ACE3138D4D442CABDE7576FCFBCBB0DEED054D90B95CFA1C99829DB12A9031E26
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:[console_scripts].wheel=wheel.cli:main..[distutils.commands].bdist_wheel=wheel.bdist_wheel:bdist_wheel..
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:PE32+ executable (DLL) (console) x86-64 (stripped to external PDB), for MS Windows
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):146712
                                                                                                                                                                                                            Entropy (8bit):6.608853986750337
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3072:hqLKjJj3yg1shVjm4OvfqnKAh2mrohmR5JHDbuNm:hqGEgSefI3roCDbd
                                                                                                                                                                                                            MD5:2849986DADC875A7A92889ECED861A36
                                                                                                                                                                                                            SHA1:C723D5E55DEB07699F2FC83999B07BD9DAB1182E
                                                                                                                                                                                                            SHA-256:84CC14C704067BFFD2B4DD411ABE752EB492431814CF9AC13417D061A3DB0EC3
                                                                                                                                                                                                            SHA-512:B8376FE9EAD1F43EEBBAEE92E649BA528B3EB2D2B774534F46511EA0A1DA743438E03BB793B9BC02A59FBADD5AE32E537C29522DD205D2A4D3E584357FA1BDD6
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Antivirus:
                                                                                                                                                                                                            • Antivirus: ReversingLabs, Detection: 0%
                                                                                                                                                                                                            Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.......PE..d...x.Oc..........."...'............P..........A..........................................`... ......................................@.......P..8......................../......................................(....................Q..p............................text...............................`..`.data...............................@....rdata...W.......X..................@..@.pdata..............................@..@.xdata....... ......................@..@.bss.........0...........................edata.......@......................@..@.idata..8....P......................@....CRT....X....`......................@....tls.........p......................@....rsrc...............................@....reloc..............................@..B................................................................................................................................
                                                                                                                                                                                                            Process:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            File Type:ASCII text, with CRLF line terminators
                                                                                                                                                                                                            Category:dropped
                                                                                                                                                                                                            Size (bytes):78
                                                                                                                                                                                                            Entropy (8bit):4.72240987273103
                                                                                                                                                                                                            Encrypted:false
                                                                                                                                                                                                            SSDEEP:3:HZBFReNmI4S2UUAuF5QEyn:HNMmI4S2UP3
                                                                                                                                                                                                            MD5:ACF70D72A3024E921FCA2F7D20481241
                                                                                                                                                                                                            SHA1:C0D6D4A1618D636F3BA9B505FC500DCC309F04D3
                                                                                                                                                                                                            SHA-256:F7FB0977E6FA86A4F48391356E522715EBF2E22A96A165E311D038332C4C0060
                                                                                                                                                                                                            SHA-512:BB997E1DEB212837C3A142F8279E2BB2A1B8C99FDAE680081B4509FBDA60658B7CADF48D7C71FF54B10F0B9906966C94104ABBA9BCDC8E815A701390FB4F9F10
                                                                                                                                                                                                            Malicious:false
                                                                                                                                                                                                            Preview:[PYI-7696:ERROR] Failed to execute script 'main' due to unhandled exception!..
                                                                                                                                                                                                            File type:PE32+ executable (console) x86-64, for MS Windows
                                                                                                                                                                                                            Entropy (8bit):7.996354346854429
                                                                                                                                                                                                            TrID:
                                                                                                                                                                                                            • Win64 Executable Console (202006/5) 77.37%
                                                                                                                                                                                                            • InstallShield setup (43055/19) 16.49%
                                                                                                                                                                                                            • Win64 Executable (generic) (12005/4) 4.60%
                                                                                                                                                                                                            • Generic Win/DOS Executable (2004/3) 0.77%
                                                                                                                                                                                                            • DOS Executable Generic (2002/1) 0.77%
                                                                                                                                                                                                            File name:main.exe
                                                                                                                                                                                                            File size:20'202'747 bytes
                                                                                                                                                                                                            MD5:91d6288da150030f5bb3520d313b4c3b
                                                                                                                                                                                                            SHA1:cddd9dd6abaed79d89c7acd0c679db7173d55a9f
                                                                                                                                                                                                            SHA256:a661cd857dc41135f7f2f95bc7cc257d020ebbe44b80e9c8d1c9436ccc322c6c
                                                                                                                                                                                                            SHA512:efb10d7eaa26c8a04293f7df819ffa3ef8f1d082806e1a0856abab54462c26eab7ae3888ff52d1c531b8fd1905f0707ae7738d916daff574164b867b5ee8624a
                                                                                                                                                                                                            SSDEEP:393216:hl825UmDW8/QhZ2YsHFUK2JS0TXMCHWUjPodaI8rqZKEXC8697YrRu/2:nqmDW8/QZ2YwUlJS0TXMb8PDIWcKESt/
                                                                                                                                                                                                            TLSH:EA173354376314BDE8DB51398AE6D34786D2B8E60BB4C78A5BF40A122E630D4DF3C762
                                                                                                                                                                                                            File Content Preview:MZ......................@...............................................!..L.!This program cannot be run in DOS mode....$.........a..............f.......f..)....f......Y.......Y.......Y.......Y........f..............................Rich...................
                                                                                                                                                                                                            Icon Hash:2e1e7c4c4c61e979
                                                                                                                                                                                                            Entrypoint:0x14000c320
                                                                                                                                                                                                            Entrypoint Section:.text
                                                                                                                                                                                                            Digitally signed:false
                                                                                                                                                                                                            Imagebase:0x140000000
                                                                                                                                                                                                            Subsystem:windows cui
                                                                                                                                                                                                            Image File Characteristics:EXECUTABLE_IMAGE, LARGE_ADDRESS_AWARE
                                                                                                                                                                                                            DLL Characteristics:HIGH_ENTROPY_VA, DYNAMIC_BASE, NX_COMPAT, GUARD_CF, TERMINAL_SERVER_AWARE
                                                                                                                                                                                                            Time Stamp:0x670486C7 [Tue Oct 8 01:11:35 2024 UTC]
                                                                                                                                                                                                            TLS Callbacks:
                                                                                                                                                                                                            CLR (.Net) Version:
                                                                                                                                                                                                            OS Version Major:6
                                                                                                                                                                                                            OS Version Minor:0
                                                                                                                                                                                                            File Version Major:6
                                                                                                                                                                                                            File Version Minor:0
                                                                                                                                                                                                            Subsystem Version Major:6
                                                                                                                                                                                                            Subsystem Version Minor:0
                                                                                                                                                                                                            Import Hash:a06f302f71edd380da3d5bf4a6d94ebd
                                                                                                                                                                                                            Instruction
                                                                                                                                                                                                            dec eax
                                                                                                                                                                                                            sub esp, 28h
                                                                                                                                                                                                            call 00007FA0B07EFC4Ch
                                                                                                                                                                                                            dec eax
                                                                                                                                                                                                            add esp, 28h
                                                                                                                                                                                                            jmp 00007FA0B07EF85Fh
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            dec eax
                                                                                                                                                                                                            sub esp, 28h
                                                                                                                                                                                                            call 00007FA0B07EFFD8h
                                                                                                                                                                                                            test eax, eax
                                                                                                                                                                                                            je 00007FA0B07EFA13h
                                                                                                                                                                                                            dec eax
                                                                                                                                                                                                            mov eax, dword ptr [00000030h]
                                                                                                                                                                                                            dec eax
                                                                                                                                                                                                            mov ecx, dword ptr [eax+08h]
                                                                                                                                                                                                            jmp 00007FA0B07EF9F7h
                                                                                                                                                                                                            dec eax
                                                                                                                                                                                                            cmp ecx, eax
                                                                                                                                                                                                            je 00007FA0B07EFA06h
                                                                                                                                                                                                            xor eax, eax
                                                                                                                                                                                                            dec eax
                                                                                                                                                                                                            cmpxchg dword ptr [0003820Ch], ecx
                                                                                                                                                                                                            jne 00007FA0B07EF9E0h
                                                                                                                                                                                                            xor al, al
                                                                                                                                                                                                            dec eax
                                                                                                                                                                                                            add esp, 28h
                                                                                                                                                                                                            ret
                                                                                                                                                                                                            mov al, 01h
                                                                                                                                                                                                            jmp 00007FA0B07EF9E9h
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            dec eax
                                                                                                                                                                                                            sub esp, 28h
                                                                                                                                                                                                            test ecx, ecx
                                                                                                                                                                                                            jne 00007FA0B07EF9F9h
                                                                                                                                                                                                            mov byte ptr [000381F5h], 00000001h
                                                                                                                                                                                                            call 00007FA0B07EF135h
                                                                                                                                                                                                            call 00007FA0B07F03F0h
                                                                                                                                                                                                            test al, al
                                                                                                                                                                                                            jne 00007FA0B07EF9F6h
                                                                                                                                                                                                            xor al, al
                                                                                                                                                                                                            jmp 00007FA0B07EFA06h
                                                                                                                                                                                                            call 00007FA0B07FE8FFh
                                                                                                                                                                                                            test al, al
                                                                                                                                                                                                            jne 00007FA0B07EF9FBh
                                                                                                                                                                                                            xor ecx, ecx
                                                                                                                                                                                                            call 00007FA0B07F0400h
                                                                                                                                                                                                            jmp 00007FA0B07EF9DCh
                                                                                                                                                                                                            mov al, 01h
                                                                                                                                                                                                            dec eax
                                                                                                                                                                                                            add esp, 28h
                                                                                                                                                                                                            ret
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            int3
                                                                                                                                                                                                            inc eax
                                                                                                                                                                                                            push ebx
                                                                                                                                                                                                            dec eax
                                                                                                                                                                                                            sub esp, 20h
                                                                                                                                                                                                            cmp byte ptr [000381BCh], 00000000h
                                                                                                                                                                                                            mov ebx, ecx
                                                                                                                                                                                                            jne 00007FA0B07EFA59h
                                                                                                                                                                                                            cmp ecx, 01h
                                                                                                                                                                                                            jnbe 00007FA0B07EFA5Ch
                                                                                                                                                                                                            call 00007FA0B07EFF4Eh
                                                                                                                                                                                                            test eax, eax
                                                                                                                                                                                                            je 00007FA0B07EFA1Ah
                                                                                                                                                                                                            test ebx, ebx
                                                                                                                                                                                                            jne 00007FA0B07EFA16h
                                                                                                                                                                                                            dec eax
                                                                                                                                                                                                            lea ecx, dword ptr [000381A6h]
                                                                                                                                                                                                            call 00007FA0B07FE6F2h
                                                                                                                                                                                                            NameVirtual AddressVirtual Size Is in Section
                                                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_EXPORT0x00x0
                                                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_IMPORT0x3ea2c0x50.rdata
                                                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_RESOURCE0x490000xef8c.rsrc
                                                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_EXCEPTION0x460000x22f8.pdata
                                                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_SECURITY0x00x0
                                                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_BASERELOC0x580000x768.reloc
                                                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_DEBUG0x3bfb00x1c.rdata
                                                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_COPYRIGHT0x00x0
                                                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_GLOBALPTR0x00x0
                                                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_TLS0x00x0
                                                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_LOAD_CONFIG0x3be700x140.rdata
                                                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_BOUND_IMPORT0x00x0
                                                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_IAT0x2d0000x400.rdata
                                                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_DELAY_IMPORT0x00x0
                                                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_COM_DESCRIPTOR0x00x0
                                                                                                                                                                                                            IMAGE_DIRECTORY_ENTRY_RESERVED0x00x0
                                                                                                                                                                                                            NameVirtual AddressVirtual SizeRaw SizeMD5Xored PEZLIB ComplexityFile TypeEntropyCharacteristics
                                                                                                                                                                                                            .text0x10000x2b1100x2b20055ff5ed922edfe0b0c10734c674f4ee4False0.5453521286231884data6.496893972670116IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                            .rdata0x2d0000x128420x12a00d684d42f3191a2c7d48d816ba1482670False0.5235816904362416data5.767553361289191IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                            .data0x400000x54080xe00aff56347f897785154c53727472c548dFalse0.13504464285714285data1.8315705466577277IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
                                                                                                                                                                                                            .pdata0x460000x22f80x240057f77a295f3be6e2a8e90035dde19ce2False0.4784071180555556data5.3594808562266065IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                            .rsrc0x490000xef8c0xf0005d72e0338b034862f777c781ab7d2219False0.8010091145833333data7.3501462320035476IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                            .reloc0x580000x7680x80042d6242177dbae8e11ed5d64b87d0d48False0.5576171875data5.268722219019965IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
                                                                                                                                                                                                            NameRVASizeTypeLanguageCountryZLIB Complexity
                                                                                                                                                                                                            RT_ICON0x492080xea8Device independent bitmap graphic, 48 x 96 x 8, image size 00.56636460554371
                                                                                                                                                                                                            RT_ICON0x4a0b00x8a8Device independent bitmap graphic, 32 x 64 x 8, image size 00.7287906137184116
                                                                                                                                                                                                            RT_ICON0x4a9580x568Device independent bitmap graphic, 16 x 32 x 8, image size 00.7471098265895953
                                                                                                                                                                                                            RT_ICON0x4aec00x909bPNG image data, 256 x 256, 8-bit/color RGBA, non-interlaced0.9971636186822983
                                                                                                                                                                                                            RT_ICON0x53f5c0x25a8Device independent bitmap graphic, 48 x 96 x 32, image size 00.38309128630705397
                                                                                                                                                                                                            RT_ICON0x565040x10a8Device independent bitmap graphic, 32 x 64 x 32, image size 00.4826454033771107
                                                                                                                                                                                                            RT_ICON0x575ac0x468Device independent bitmap graphic, 16 x 32 x 32, image size 00.699468085106383
                                                                                                                                                                                                            RT_GROUP_ICON0x57a140x68data0.7019230769230769
                                                                                                                                                                                                            RT_MANIFEST0x57a7c0x50dXML 1.0 document, ASCII text0.4694508894044857
                                                                                                                                                                                                            DLLImport
                                                                                                                                                                                                            USER32.dllTranslateMessage, ShutdownBlockReasonCreate, GetWindowThreadProcessId, SetWindowLongPtrW, GetWindowLongPtrW, MsgWaitForMultipleObjects, ShowWindow, DestroyWindow, CreateWindowExW, RegisterClassW, DefWindowProcW, PeekMessageW, DispatchMessageW, GetMessageW
                                                                                                                                                                                                            KERNEL32.dllGetTimeZoneInformation, GetProcessHeap, FreeEnvironmentStringsW, GetEnvironmentStringsW, GetCPInfo, GetOEMCP, GetACP, IsValidCodePage, GetStringTypeW, FormatMessageW, GetLastError, GetModuleFileNameW, LoadLibraryExW, SetDllDirectoryW, CreateSymbolicLinkW, GetProcAddress, CreateDirectoryW, GetCommandLineW, GetEnvironmentVariableW, ExpandEnvironmentStringsW, DeleteFileW, FindClose, FindFirstFileW, FindNextFileW, HeapSize, RemoveDirectoryW, GetTempPathW, CloseHandle, QueryPerformanceCounter, QueryPerformanceFrequency, WaitForSingleObject, Sleep, GetCurrentProcess, GetCurrentProcessId, TerminateProcess, GetExitCodeProcess, CreateProcessW, GetStartupInfoW, FreeLibrary, LocalFree, SetConsoleCtrlHandler, GetConsoleWindow, K32EnumProcessModules, K32GetModuleFileNameExW, CreateFileW, FindFirstFileExW, GetFinalPathNameByHandleW, MultiByteToWideChar, WideCharToMultiByte, GetFileAttributesExW, HeapReAlloc, WriteConsoleW, SetEndOfFile, GetDriveTypeW, IsDebuggerPresent, RtlCaptureContext, RtlLookupFunctionEntry, RtlVirtualUnwind, UnhandledExceptionFilter, SetUnhandledExceptionFilter, IsProcessorFeaturePresent, GetCurrentThreadId, GetSystemTimeAsFileTime, InitializeSListHead, GetModuleHandleW, RtlUnwindEx, SetLastError, EnterCriticalSection, LeaveCriticalSection, DeleteCriticalSection, InitializeCriticalSectionAndSpinCount, TlsAlloc, TlsGetValue, TlsSetValue, TlsFree, EncodePointer, RaiseException, RtlPcToFileHeader, GetFileInformationByHandle, GetFileType, PeekNamedPipe, SystemTimeToTzSpecificLocalTime, FileTimeToSystemTime, ReadFile, GetFullPathNameW, SetStdHandle, GetStdHandle, WriteFile, ExitProcess, GetModuleHandleExW, GetCommandLineA, HeapFree, GetConsoleMode, ReadConsoleW, SetFilePointerEx, GetConsoleOutputCP, GetFileSizeEx, HeapAlloc, FlsAlloc, FlsGetValue, FlsSetValue, FlsFree, CompareStringW, LCMapStringW, GetCurrentDirectoryW, FlushFileBuffers, SetEnvironmentVariableW
                                                                                                                                                                                                            ADVAPI32.dllConvertSidToStringSidW, GetTokenInformation, OpenProcessToken, ConvertStringSecurityDescriptorToSecurityDescriptorW
                                                                                                                                                                                                            TimestampSIDSignatureSeveritySource IPSource PortDest IPDest PortProtocol
                                                                                                                                                                                                            2024-11-03T06:52:20.012210+01002022930ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow120.109.210.53443192.168.2.449735TCP
                                                                                                                                                                                                            2024-11-03T06:52:58.885422+01002022930ET EXPLOIT Possible CVE-2016-2211 Symantec Cab Parsing Buffer Overflow120.109.210.53443192.168.2.449739TCP
                                                                                                                                                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                            Nov 3, 2024 06:52:11.591404915 CET49731443192.168.2.4169.197.85.95
                                                                                                                                                                                                            Nov 3, 2024 06:52:11.591444969 CET44349731169.197.85.95192.168.2.4
                                                                                                                                                                                                            Nov 3, 2024 06:52:11.591516972 CET49731443192.168.2.4169.197.85.95
                                                                                                                                                                                                            Nov 3, 2024 06:52:11.592808962 CET49731443192.168.2.4169.197.85.95
                                                                                                                                                                                                            Nov 3, 2024 06:52:11.592823029 CET44349731169.197.85.95192.168.2.4
                                                                                                                                                                                                            Nov 3, 2024 06:52:12.466790915 CET44349731169.197.85.95192.168.2.4
                                                                                                                                                                                                            Nov 3, 2024 06:52:12.467375040 CET49731443192.168.2.4169.197.85.95
                                                                                                                                                                                                            Nov 3, 2024 06:52:12.467401028 CET44349731169.197.85.95192.168.2.4
                                                                                                                                                                                                            Nov 3, 2024 06:52:12.468693018 CET44349731169.197.85.95192.168.2.4
                                                                                                                                                                                                            Nov 3, 2024 06:52:12.468755007 CET49731443192.168.2.4169.197.85.95
                                                                                                                                                                                                            Nov 3, 2024 06:52:12.470346928 CET49731443192.168.2.4169.197.85.95
                                                                                                                                                                                                            Nov 3, 2024 06:52:12.470489979 CET49731443192.168.2.4169.197.85.95
                                                                                                                                                                                                            TimestampSource PortDest PortSource IPDest IP
                                                                                                                                                                                                            Nov 3, 2024 06:52:11.580723047 CET5545253192.168.2.41.1.1.1
                                                                                                                                                                                                            Nov 3, 2024 06:52:11.587682962 CET53554521.1.1.1192.168.2.4
                                                                                                                                                                                                            TimestampSource IPDest IPTrans IDOP CodeNameTypeClassDNS over HTTPS
                                                                                                                                                                                                            Nov 3, 2024 06:52:11.580723047 CET192.168.2.41.1.1.10x994cStandard query (0)i.ibb.coA (IP address)IN (0x0001)false
                                                                                                                                                                                                            TimestampSource IPDest IPTrans IDReply CodeNameCNameAddressTypeClassDNS over HTTPS
                                                                                                                                                                                                            Nov 3, 2024 06:52:11.587682962 CET1.1.1.1192.168.2.40x994cNo error (0)i.ibb.co169.197.85.95A (IP address)IN (0x0001)false

                                                                                                                                                                                                            Click to jump to process

                                                                                                                                                                                                            Click to jump to process

                                                                                                                                                                                                            Click to dive into process behavior distribution

                                                                                                                                                                                                            Click to jump to process

                                                                                                                                                                                                            Target ID:0
                                                                                                                                                                                                            Start time:01:51:58
                                                                                                                                                                                                            Start date:03/11/2024
                                                                                                                                                                                                            Path:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            Wow64 process (32bit):false
                                                                                                                                                                                                            Commandline:"C:\Users\user\Desktop\main.exe"
                                                                                                                                                                                                            Imagebase:0x7ff7b35c0000
                                                                                                                                                                                                            File size:20'202'747 bytes
                                                                                                                                                                                                            MD5 hash:91D6288DA150030F5BB3520D313B4C3B
                                                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                                                            Reputation:low
                                                                                                                                                                                                            Has exited:true

                                                                                                                                                                                                            Target ID:1
                                                                                                                                                                                                            Start time:01:51:58
                                                                                                                                                                                                            Start date:03/11/2024
                                                                                                                                                                                                            Path:C:\Windows\System32\conhost.exe
                                                                                                                                                                                                            Wow64 process (32bit):false
                                                                                                                                                                                                            Commandline:C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                                                                                                                                                                                                            Imagebase:0x7ff7699e0000
                                                                                                                                                                                                            File size:862'208 bytes
                                                                                                                                                                                                            MD5 hash:0D698AF330FD17BEE3BF90011D49251D
                                                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                                                            Reputation:high
                                                                                                                                                                                                            Has exited:true

                                                                                                                                                                                                            Target ID:2
                                                                                                                                                                                                            Start time:01:52:06
                                                                                                                                                                                                            Start date:03/11/2024
                                                                                                                                                                                                            Path:C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                            Wow64 process (32bit):false
                                                                                                                                                                                                            Commandline:"C:\Users\user\Desktop\main.exe"
                                                                                                                                                                                                            Imagebase:0x7ff7b35c0000
                                                                                                                                                                                                            File size:20'202'747 bytes
                                                                                                                                                                                                            MD5 hash:91D6288DA150030F5BB3520D313B4C3B
                                                                                                                                                                                                            Has elevated privileges:true
                                                                                                                                                                                                            Has administrator privileges:true
                                                                                                                                                                                                            Programmed in:C, C++ or other language
                                                                                                                                                                                                            Reputation:low
                                                                                                                                                                                                            Has exited:true

                                                                                                                                                                                                            Reset < >

                                                                                                                                                                                                              Execution Graph

                                                                                                                                                                                                              Execution Coverage:9.3%
                                                                                                                                                                                                              Dynamic/Decrypted Code Coverage:0%
                                                                                                                                                                                                              Signature Coverage:10%
                                                                                                                                                                                                              Total number of Nodes:2000
                                                                                                                                                                                                              Total number of Limit Nodes:48
                                                                                                                                                                                                              execution_graph 16887 7ff7b35d6584 16888 7ff7b35d65bb 16887->16888 16889 7ff7b35d659e 16887->16889 16888->16889 16891 7ff7b35d65ce CreateFileW 16888->16891 16938 7ff7b35d5dc8 16889->16938 16893 7ff7b35d6602 16891->16893 16894 7ff7b35d6638 16891->16894 16912 7ff7b35d66d8 GetFileType 16893->16912 16947 7ff7b35d6b60 16894->16947 16901 7ff7b35d6641 16968 7ff7b35d5d5c 16901->16968 16902 7ff7b35d666c 16973 7ff7b35d6920 16902->16973 16904 7ff7b35d662d CloseHandle 16907 7ff7b35d65b6 16904->16907 16905 7ff7b35d6617 CloseHandle 16905->16907 16911 7ff7b35d664b 16911->16907 16913 7ff7b35d67e3 16912->16913 16914 7ff7b35d6726 16912->16914 16916 7ff7b35d67eb 16913->16916 16917 7ff7b35d680d 16913->16917 16915 7ff7b35d6752 GetFileInformationByHandle 16914->16915 16919 7ff7b35d6a5c 21 API calls 16914->16919 16920 7ff7b35d677b 16915->16920 16921 7ff7b35d67fe GetLastError 16915->16921 16916->16921 16922 7ff7b35d67ef 16916->16922 16918 7ff7b35d6830 PeekNamedPipe 16917->16918 16928 7ff7b35d67ce 16917->16928 16918->16928 16923 7ff7b35d6740 16919->16923 16924 7ff7b35d6920 51 API calls 16920->16924 16926 7ff7b35d5d5c _fread_nolock 11 API calls 16921->16926 16925 7ff7b35d5de8 _get_daylight 11 API calls 16922->16925 16923->16915 16923->16928 16929 7ff7b35d6786 16924->16929 16925->16928 16926->16928 16997 7ff7b35cbab0 16928->16997 16990 7ff7b35d6880 16929->16990 16933 7ff7b35d6880 10 API calls 16934 7ff7b35d67a5 16933->16934 16935 7ff7b35d6880 10 API calls 16934->16935 16936 7ff7b35d67b6 16935->16936 16936->16928 16937 7ff7b35d5de8 _get_daylight 11 API calls 16936->16937 16937->16928 17011 7ff7b35dc168 GetLastError 16938->17011 16940 7ff7b35d5dd1 16941 7ff7b35d5de8 16940->16941 16942 7ff7b35dc168 _get_daylight 11 API calls 16941->16942 16943 7ff7b35d5df1 16942->16943 16944 7ff7b35db7c4 16943->16944 17069 7ff7b35db65c 16944->17069 16946 7ff7b35db7dd 16946->16907 16948 7ff7b35d6b96 16947->16948 16949 7ff7b35d6c2e __vcrt_freefls 16948->16949 16950 7ff7b35d5de8 _get_daylight 11 API calls 16948->16950 16951 7ff7b35cbab0 _log10_special 8 API calls 16949->16951 16952 7ff7b35d6ba8 16950->16952 16953 7ff7b35d663d 16951->16953 16954 7ff7b35d5de8 _get_daylight 11 API calls 16952->16954 16953->16901 16953->16902 16955 7ff7b35d6bb0 16954->16955 17121 7ff7b35d8ce4 16955->17121 16957 7ff7b35d6bc5 16958 7ff7b35d6bcd 16957->16958 16959 7ff7b35d6bd7 16957->16959 16960 7ff7b35d5de8 _get_daylight 11 API calls 16958->16960 16961 7ff7b35d5de8 _get_daylight 11 API calls 16959->16961 16966 7ff7b35d6bd2 16960->16966 16962 7ff7b35d6bdc 16961->16962 16962->16949 16963 7ff7b35d5de8 _get_daylight 11 API calls 16962->16963 16964 7ff7b35d6be6 16963->16964 16965 7ff7b35d8ce4 45 API calls 16964->16965 16965->16966 16966->16949 16967 7ff7b35d6c20 GetDriveTypeW 16966->16967 16967->16949 16969 7ff7b35dc168 _get_daylight 11 API calls 16968->16969 16970 7ff7b35d5d69 __free_lconv_num 16969->16970 16971 7ff7b35dc168 _get_daylight 11 API calls 16970->16971 16972 7ff7b35d5d8b 16971->16972 16972->16911 16974 7ff7b35d6948 16973->16974 16982 7ff7b35d6679 16974->16982 17215 7ff7b35e0934 16974->17215 16976 7ff7b35d69dc 16977 7ff7b35e0934 51 API calls 16976->16977 16976->16982 16978 7ff7b35d69ef 16977->16978 16979 7ff7b35e0934 51 API calls 16978->16979 16978->16982 16980 7ff7b35d6a02 16979->16980 16981 7ff7b35e0934 51 API calls 16980->16981 16980->16982 16981->16982 16983 7ff7b35d6a5c 16982->16983 16984 7ff7b35d6a76 16983->16984 16985 7ff7b35d6aad 16984->16985 16986 7ff7b35d6a86 16984->16986 16987 7ff7b35e07c8 21 API calls 16985->16987 16988 7ff7b35d5d5c _fread_nolock 11 API calls 16986->16988 16989 7ff7b35d6a96 16986->16989 16987->16989 16988->16989 16989->16911 16991 7ff7b35d689c 16990->16991 16992 7ff7b35d68a9 FileTimeToSystemTime 16990->16992 16991->16992 16994 7ff7b35d68a4 16991->16994 16993 7ff7b35d68bd SystemTimeToTzSpecificLocalTime 16992->16993 16992->16994 16993->16994 16995 7ff7b35cbab0 _log10_special 8 API calls 16994->16995 16996 7ff7b35d6795 16995->16996 16996->16933 16998 7ff7b35cbab9 16997->16998 16999 7ff7b35cbac4 16998->16999 17000 7ff7b35cbe40 IsProcessorFeaturePresent 16998->17000 16999->16904 16999->16905 17001 7ff7b35cbe58 17000->17001 17006 7ff7b35cc038 RtlCaptureContext 17001->17006 17007 7ff7b35cc052 RtlLookupFunctionEntry 17006->17007 17008 7ff7b35cbe6b 17007->17008 17009 7ff7b35cc068 RtlVirtualUnwind 17007->17009 17010 7ff7b35cbe00 SetUnhandledExceptionFilter UnhandledExceptionFilter GetCurrentProcess TerminateProcess 17008->17010 17009->17007 17009->17008 17012 7ff7b35dc1a9 FlsSetValue 17011->17012 17017 7ff7b35dc18c 17011->17017 17013 7ff7b35dc199 SetLastError 17012->17013 17014 7ff7b35dc1bb 17012->17014 17013->16940 17028 7ff7b35dfda4 17014->17028 17017->17012 17017->17013 17019 7ff7b35dc1e8 FlsSetValue 17021 7ff7b35dc1f4 FlsSetValue 17019->17021 17022 7ff7b35dc206 17019->17022 17020 7ff7b35dc1d8 FlsSetValue 17023 7ff7b35dc1e1 17020->17023 17021->17023 17041 7ff7b35dbd9c 17022->17041 17035 7ff7b35db404 17023->17035 17033 7ff7b35dfdb5 _get_daylight 17028->17033 17029 7ff7b35dfe06 17031 7ff7b35d5de8 _get_daylight 10 API calls 17029->17031 17030 7ff7b35dfdea HeapAlloc 17032 7ff7b35dc1ca 17030->17032 17030->17033 17031->17032 17032->17019 17032->17020 17033->17029 17033->17030 17046 7ff7b35e47a0 17033->17046 17036 7ff7b35db438 17035->17036 17037 7ff7b35db409 RtlFreeHeap 17035->17037 17036->17013 17037->17036 17038 7ff7b35db424 GetLastError 17037->17038 17039 7ff7b35db431 __free_lconv_num 17038->17039 17040 7ff7b35d5de8 _get_daylight 9 API calls 17039->17040 17040->17036 17055 7ff7b35dbc74 17041->17055 17049 7ff7b35e47e0 17046->17049 17054 7ff7b35e14e8 EnterCriticalSection 17049->17054 17067 7ff7b35e14e8 EnterCriticalSection 17055->17067 17070 7ff7b35db687 17069->17070 17073 7ff7b35db6f8 17070->17073 17072 7ff7b35db6ae 17072->16946 17083 7ff7b35db440 17073->17083 17078 7ff7b35db733 17078->17072 17084 7ff7b35db45c GetLastError 17083->17084 17085 7ff7b35db497 17083->17085 17086 7ff7b35db46c 17084->17086 17085->17078 17089 7ff7b35db4ac 17085->17089 17096 7ff7b35dc230 17086->17096 17090 7ff7b35db4e0 17089->17090 17091 7ff7b35db4c8 GetLastError SetLastError 17089->17091 17090->17078 17092 7ff7b35db7e4 IsProcessorFeaturePresent 17090->17092 17091->17090 17093 7ff7b35db7f7 17092->17093 17113 7ff7b35db4f8 17093->17113 17097 7ff7b35dc24f FlsGetValue 17096->17097 17098 7ff7b35dc26a FlsSetValue 17096->17098 17099 7ff7b35dc264 17097->17099 17103 7ff7b35db487 SetLastError 17097->17103 17100 7ff7b35dc277 17098->17100 17098->17103 17099->17098 17101 7ff7b35dfda4 _get_daylight 11 API calls 17100->17101 17102 7ff7b35dc286 17101->17102 17104 7ff7b35dc2a4 FlsSetValue 17102->17104 17105 7ff7b35dc294 FlsSetValue 17102->17105 17103->17085 17107 7ff7b35dc2b0 FlsSetValue 17104->17107 17108 7ff7b35dc2c2 17104->17108 17106 7ff7b35dc29d 17105->17106 17109 7ff7b35db404 __free_lconv_num 11 API calls 17106->17109 17107->17106 17110 7ff7b35dbd9c _get_daylight 11 API calls 17108->17110 17109->17103 17111 7ff7b35dc2ca 17110->17111 17112 7ff7b35db404 __free_lconv_num 11 API calls 17111->17112 17112->17103 17114 7ff7b35db532 _isindst memcpy_s 17113->17114 17115 7ff7b35db55a RtlCaptureContext RtlLookupFunctionEntry 17114->17115 17116 7ff7b35db594 RtlVirtualUnwind 17115->17116 17117 7ff7b35db5ca IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 17115->17117 17116->17117 17118 7ff7b35db61c _isindst 17117->17118 17119 7ff7b35cbab0 _log10_special 8 API calls 17118->17119 17120 7ff7b35db63b GetCurrentProcess TerminateProcess 17119->17120 17122 7ff7b35d8d00 17121->17122 17123 7ff7b35d8d6e 17121->17123 17122->17123 17125 7ff7b35d8d05 17122->17125 17158 7ff7b35e19d0 17123->17158 17126 7ff7b35d8d1d 17125->17126 17127 7ff7b35d8d3a 17125->17127 17133 7ff7b35d8ab4 GetFullPathNameW 17126->17133 17141 7ff7b35d8b28 GetFullPathNameW 17127->17141 17132 7ff7b35d8d32 __vcrt_freefls 17132->16957 17134 7ff7b35d8af0 17133->17134 17135 7ff7b35d8ada GetLastError 17133->17135 17137 7ff7b35d8aec 17134->17137 17139 7ff7b35d5de8 _get_daylight 11 API calls 17134->17139 17136 7ff7b35d5d5c _fread_nolock 11 API calls 17135->17136 17138 7ff7b35d8ae7 17136->17138 17137->17132 17140 7ff7b35d5de8 _get_daylight 11 API calls 17138->17140 17139->17137 17140->17137 17142 7ff7b35d8b5b GetLastError 17141->17142 17147 7ff7b35d8b71 __vcrt_freefls 17141->17147 17143 7ff7b35d5d5c _fread_nolock 11 API calls 17142->17143 17144 7ff7b35d8b68 17143->17144 17146 7ff7b35d5de8 _get_daylight 11 API calls 17144->17146 17145 7ff7b35d8b6d 17149 7ff7b35d8c00 17145->17149 17146->17145 17147->17145 17148 7ff7b35d8bcb GetFullPathNameW 17147->17148 17148->17142 17148->17145 17153 7ff7b35d8c74 memcpy_s 17149->17153 17154 7ff7b35d8c29 memcpy_s 17149->17154 17150 7ff7b35d8c5d 17151 7ff7b35d5de8 _get_daylight 11 API calls 17150->17151 17152 7ff7b35d8c62 17151->17152 17155 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 17152->17155 17153->17132 17154->17150 17154->17153 17156 7ff7b35d8c96 17154->17156 17155->17153 17156->17153 17157 7ff7b35d5de8 _get_daylight 11 API calls 17156->17157 17157->17152 17161 7ff7b35e17e0 17158->17161 17162 7ff7b35e1822 17161->17162 17163 7ff7b35e180b 17161->17163 17165 7ff7b35e1826 17162->17165 17166 7ff7b35e1847 17162->17166 17164 7ff7b35d5de8 _get_daylight 11 API calls 17163->17164 17168 7ff7b35e1810 17164->17168 17187 7ff7b35e194c 17165->17187 17199 7ff7b35e07c8 17166->17199 17173 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 17168->17173 17171 7ff7b35e184c 17176 7ff7b35e1873 17171->17176 17177 7ff7b35e18f1 17171->17177 17172 7ff7b35e182f 17174 7ff7b35d5dc8 _fread_nolock 11 API calls 17172->17174 17183 7ff7b35e181b __vcrt_freefls 17173->17183 17175 7ff7b35e1834 17174->17175 17179 7ff7b35d5de8 _get_daylight 11 API calls 17175->17179 17184 7ff7b35d8b28 14 API calls 17176->17184 17177->17163 17180 7ff7b35e18f9 17177->17180 17178 7ff7b35cbab0 _log10_special 8 API calls 17182 7ff7b35e1941 17178->17182 17179->17168 17181 7ff7b35d8ab4 13 API calls 17180->17181 17181->17183 17182->17132 17183->17178 17185 7ff7b35e18b7 17184->17185 17185->17183 17186 7ff7b35d8c00 37 API calls 17185->17186 17186->17183 17188 7ff7b35e1996 17187->17188 17189 7ff7b35e1966 17187->17189 17191 7ff7b35e19a1 GetDriveTypeW 17188->17191 17192 7ff7b35e1981 17188->17192 17190 7ff7b35d5dc8 _fread_nolock 11 API calls 17189->17190 17193 7ff7b35e196b 17190->17193 17191->17192 17195 7ff7b35cbab0 _log10_special 8 API calls 17192->17195 17194 7ff7b35d5de8 _get_daylight 11 API calls 17193->17194 17196 7ff7b35e1976 17194->17196 17197 7ff7b35e182b 17195->17197 17198 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 17196->17198 17197->17171 17197->17172 17198->17192 17213 7ff7b35eb6e0 17199->17213 17202 7ff7b35e0815 17205 7ff7b35cbab0 _log10_special 8 API calls 17202->17205 17203 7ff7b35e083c 17204 7ff7b35dfda4 _get_daylight 11 API calls 17203->17204 17206 7ff7b35e084b 17204->17206 17207 7ff7b35e08a9 17205->17207 17208 7ff7b35e0864 17206->17208 17209 7ff7b35e0855 GetCurrentDirectoryW 17206->17209 17207->17171 17210 7ff7b35d5de8 _get_daylight 11 API calls 17208->17210 17209->17208 17211 7ff7b35e0869 17209->17211 17210->17211 17212 7ff7b35db404 __free_lconv_num 11 API calls 17211->17212 17212->17202 17214 7ff7b35e07fe GetCurrentDirectoryW 17213->17214 17214->17202 17214->17203 17216 7ff7b35e0941 17215->17216 17217 7ff7b35e0965 17215->17217 17216->17217 17218 7ff7b35e0946 17216->17218 17219 7ff7b35e099f 17217->17219 17222 7ff7b35e09be 17217->17222 17220 7ff7b35d5de8 _get_daylight 11 API calls 17218->17220 17221 7ff7b35d5de8 _get_daylight 11 API calls 17219->17221 17223 7ff7b35e094b 17220->17223 17224 7ff7b35e09a4 17221->17224 17232 7ff7b35d5e2c 17222->17232 17226 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 17223->17226 17227 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 17224->17227 17228 7ff7b35e0956 17226->17228 17229 7ff7b35e09af 17227->17229 17228->16976 17229->16976 17230 7ff7b35e16ec 51 API calls 17231 7ff7b35e09cb 17230->17231 17231->17229 17231->17230 17233 7ff7b35d5e4b 17232->17233 17234 7ff7b35d5e50 17232->17234 17233->17231 17234->17233 17240 7ff7b35dbff0 GetLastError 17234->17240 17241 7ff7b35dc014 FlsGetValue 17240->17241 17242 7ff7b35dc031 FlsSetValue 17240->17242 17243 7ff7b35dc02b 17241->17243 17259 7ff7b35dc021 17241->17259 17244 7ff7b35dc043 17242->17244 17242->17259 17243->17242 17246 7ff7b35dfda4 _get_daylight 11 API calls 17244->17246 17245 7ff7b35dc09d SetLastError 17248 7ff7b35dc0bd 17245->17248 17249 7ff7b35d5e6b 17245->17249 17247 7ff7b35dc052 17246->17247 17251 7ff7b35dc070 FlsSetValue 17247->17251 17252 7ff7b35dc060 FlsSetValue 17247->17252 17270 7ff7b35db3ac 17248->17270 17262 7ff7b35de9ec 17249->17262 17255 7ff7b35dc07c FlsSetValue 17251->17255 17256 7ff7b35dc08e 17251->17256 17254 7ff7b35dc069 17252->17254 17257 7ff7b35db404 __free_lconv_num 11 API calls 17254->17257 17255->17254 17258 7ff7b35dbd9c _get_daylight 11 API calls 17256->17258 17257->17259 17260 7ff7b35dc096 17258->17260 17259->17245 17261 7ff7b35db404 __free_lconv_num 11 API calls 17260->17261 17261->17245 17263 7ff7b35dea01 17262->17263 17265 7ff7b35d5e8e 17262->17265 17263->17265 17314 7ff7b35e4514 17263->17314 17266 7ff7b35dea58 17265->17266 17267 7ff7b35dea80 17266->17267 17268 7ff7b35dea6d 17266->17268 17267->17233 17268->17267 17327 7ff7b35e3860 17268->17327 17279 7ff7b35e4860 17270->17279 17305 7ff7b35e4818 17279->17305 17310 7ff7b35e14e8 EnterCriticalSection 17305->17310 17315 7ff7b35dbff0 _CreateFrameInfo 45 API calls 17314->17315 17316 7ff7b35e4523 17315->17316 17317 7ff7b35e456e 17316->17317 17326 7ff7b35e14e8 EnterCriticalSection 17316->17326 17317->17265 17328 7ff7b35dbff0 _CreateFrameInfo 45 API calls 17327->17328 17329 7ff7b35e3869 17328->17329 20230 7ff7b35ebf79 20233 7ff7b35d6288 LeaveCriticalSection 20230->20233 20727 7ff7b35ec00e 20728 7ff7b35ec01d 20727->20728 20729 7ff7b35ec027 20727->20729 20731 7ff7b35e1548 LeaveCriticalSection 20728->20731 21191 7ff7b35ebdf3 21193 7ff7b35ebe03 21191->21193 21195 7ff7b35d6288 LeaveCriticalSection 21193->21195 20280 7ff7b35dac70 20283 7ff7b35dabe8 20280->20283 20290 7ff7b35e14e8 EnterCriticalSection 20283->20290 20291 7ff7b35dbe70 20292 7ff7b35dbe75 20291->20292 20293 7ff7b35dbe8a 20291->20293 20297 7ff7b35dbe90 20292->20297 20298 7ff7b35dbed2 20297->20298 20299 7ff7b35dbeda 20297->20299 20301 7ff7b35db404 __free_lconv_num 11 API calls 20298->20301 20300 7ff7b35db404 __free_lconv_num 11 API calls 20299->20300 20302 7ff7b35dbee7 20300->20302 20301->20299 20303 7ff7b35db404 __free_lconv_num 11 API calls 20302->20303 20304 7ff7b35dbef4 20303->20304 20305 7ff7b35db404 __free_lconv_num 11 API calls 20304->20305 20306 7ff7b35dbf01 20305->20306 20307 7ff7b35db404 __free_lconv_num 11 API calls 20306->20307 20308 7ff7b35dbf0e 20307->20308 20309 7ff7b35db404 __free_lconv_num 11 API calls 20308->20309 20310 7ff7b35dbf1b 20309->20310 20311 7ff7b35db404 __free_lconv_num 11 API calls 20310->20311 20312 7ff7b35dbf28 20311->20312 20313 7ff7b35db404 __free_lconv_num 11 API calls 20312->20313 20314 7ff7b35dbf35 20313->20314 20315 7ff7b35db404 __free_lconv_num 11 API calls 20314->20315 20316 7ff7b35dbf45 20315->20316 20317 7ff7b35db404 __free_lconv_num 11 API calls 20316->20317 20318 7ff7b35dbf55 20317->20318 20323 7ff7b35dbd3c 20318->20323 20337 7ff7b35e14e8 EnterCriticalSection 20323->20337 20339 7ff7b35e2670 20357 7ff7b35e14e8 EnterCriticalSection 20339->20357 21273 7ff7b35e28c0 21284 7ff7b35e85f4 21273->21284 21285 7ff7b35e8601 21284->21285 21286 7ff7b35db404 __free_lconv_num 11 API calls 21285->21286 21287 7ff7b35e861d 21285->21287 21286->21285 21288 7ff7b35db404 __free_lconv_num 11 API calls 21287->21288 21289 7ff7b35e28c9 21287->21289 21288->21287 21290 7ff7b35e14e8 EnterCriticalSection 21289->21290 17330 7ff7b35cb040 17331 7ff7b35cb06e 17330->17331 17332 7ff7b35cb055 17330->17332 17332->17331 17335 7ff7b35de664 17332->17335 17336 7ff7b35de6af 17335->17336 17340 7ff7b35de673 _get_daylight 17335->17340 17337 7ff7b35d5de8 _get_daylight 11 API calls 17336->17337 17339 7ff7b35cb0ce 17337->17339 17338 7ff7b35de696 HeapAlloc 17338->17339 17338->17340 17340->17336 17340->17338 17341 7ff7b35e47a0 _get_daylight 2 API calls 17340->17341 17341->17340 20038 7ff7b35da839 20039 7ff7b35db2f8 45 API calls 20038->20039 20040 7ff7b35da83e 20039->20040 20041 7ff7b35da865 GetModuleHandleW 20040->20041 20042 7ff7b35da8af 20040->20042 20041->20042 20048 7ff7b35da872 20041->20048 20050 7ff7b35da73c 20042->20050 20048->20042 20064 7ff7b35da960 GetModuleHandleExW 20048->20064 20070 7ff7b35e14e8 EnterCriticalSection 20050->20070 20065 7ff7b35da994 GetProcAddress 20064->20065 20066 7ff7b35da9bd 20064->20066 20069 7ff7b35da9a6 20065->20069 20067 7ff7b35da9c2 FreeLibrary 20066->20067 20068 7ff7b35da9c9 20066->20068 20067->20068 20068->20042 20069->20066 20428 7ff7b35d6220 20429 7ff7b35d622b 20428->20429 20437 7ff7b35e04b4 20429->20437 20450 7ff7b35e14e8 EnterCriticalSection 20437->20450 17342 7ff7b35e0b9c 17343 7ff7b35e0d8e 17342->17343 17345 7ff7b35e0bde _isindst 17342->17345 17344 7ff7b35d5de8 _get_daylight 11 API calls 17343->17344 17362 7ff7b35e0d7e 17344->17362 17345->17343 17348 7ff7b35e0c5e _isindst 17345->17348 17346 7ff7b35cbab0 _log10_special 8 API calls 17347 7ff7b35e0da9 17346->17347 17363 7ff7b35e73a4 17348->17363 17353 7ff7b35e0dba 17355 7ff7b35db7e4 _isindst 17 API calls 17353->17355 17356 7ff7b35e0dce 17355->17356 17360 7ff7b35e0cbb 17360->17362 17388 7ff7b35e73e8 17360->17388 17362->17346 17364 7ff7b35e73b3 17363->17364 17365 7ff7b35e0c7c 17363->17365 17395 7ff7b35e14e8 EnterCriticalSection 17364->17395 17370 7ff7b35e67a8 17365->17370 17371 7ff7b35e67b1 17370->17371 17372 7ff7b35e0c91 17370->17372 17373 7ff7b35d5de8 _get_daylight 11 API calls 17371->17373 17372->17353 17376 7ff7b35e67d8 17372->17376 17374 7ff7b35e67b6 17373->17374 17375 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 17374->17375 17375->17372 17377 7ff7b35e67e1 17376->17377 17378 7ff7b35e0ca2 17376->17378 17379 7ff7b35d5de8 _get_daylight 11 API calls 17377->17379 17378->17353 17382 7ff7b35e6808 17378->17382 17380 7ff7b35e67e6 17379->17380 17381 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 17380->17381 17381->17378 17383 7ff7b35e6811 17382->17383 17384 7ff7b35e0cb3 17382->17384 17385 7ff7b35d5de8 _get_daylight 11 API calls 17383->17385 17384->17353 17384->17360 17386 7ff7b35e6816 17385->17386 17387 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 17386->17387 17387->17384 17396 7ff7b35e14e8 EnterCriticalSection 17388->17396 17397 7ff7b35cc19c 17418 7ff7b35cc37c 17397->17418 17400 7ff7b35cc2f3 17594 7ff7b35cc69c IsProcessorFeaturePresent 17400->17594 17401 7ff7b35cc1bd __scrt_acquire_startup_lock 17403 7ff7b35cc2fd 17401->17403 17409 7ff7b35cc1db __scrt_release_startup_lock 17401->17409 17404 7ff7b35cc69c 7 API calls 17403->17404 17406 7ff7b35cc308 _CreateFrameInfo 17404->17406 17405 7ff7b35cc200 17407 7ff7b35cc286 17426 7ff7b35da658 17407->17426 17409->17405 17409->17407 17583 7ff7b35daa04 17409->17583 17411 7ff7b35cc28b 17432 7ff7b35c1000 17411->17432 17416 7ff7b35cc2af 17416->17406 17590 7ff7b35cc500 17416->17590 17419 7ff7b35cc384 17418->17419 17420 7ff7b35cc390 __scrt_dllmain_crt_thread_attach 17419->17420 17421 7ff7b35cc39d 17420->17421 17422 7ff7b35cc1b5 17420->17422 17601 7ff7b35db2ac 17421->17601 17422->17400 17422->17401 17427 7ff7b35da67d 17426->17427 17428 7ff7b35da668 17426->17428 17427->17411 17428->17427 17644 7ff7b35da0e8 17428->17644 17433 7ff7b35c2b80 17432->17433 17706 7ff7b35d6360 17433->17706 17435 7ff7b35c2bbc 17713 7ff7b35c2a70 17435->17713 17438 7ff7b35c2bc9 __vcrt_freefls 17441 7ff7b35cbab0 _log10_special 8 API calls 17438->17441 17442 7ff7b35c30ec 17441->17442 17588 7ff7b35cc7ec GetModuleHandleW 17442->17588 17443 7ff7b35c2bfd 17873 7ff7b35c1c60 17443->17873 17444 7ff7b35c2cdb 17882 7ff7b35c39e0 17444->17882 17447 7ff7b35c2c1c 17785 7ff7b35c7c80 17447->17785 17450 7ff7b35c2d2a 17905 7ff7b35c1e50 17450->17905 17452 7ff7b35c2c4f 17461 7ff7b35c2c7b __vcrt_freefls 17452->17461 17877 7ff7b35c7df0 17452->17877 17454 7ff7b35c2d1d 17455 7ff7b35c2d22 17454->17455 17456 7ff7b35c2d45 17454->17456 17901 7ff7b35cf544 17455->17901 17457 7ff7b35c1c60 49 API calls 17456->17457 17460 7ff7b35c2d64 17457->17460 17466 7ff7b35c1930 115 API calls 17460->17466 17463 7ff7b35c7c80 14 API calls 17461->17463 17469 7ff7b35c2c9e __vcrt_freefls 17461->17469 17463->17469 17464 7ff7b35c2dcc 17465 7ff7b35c7df0 40 API calls 17464->17465 17467 7ff7b35c2dd8 17465->17467 17468 7ff7b35c2d8e 17466->17468 17470 7ff7b35c7df0 40 API calls 17467->17470 17468->17447 17471 7ff7b35c2d9e 17468->17471 17475 7ff7b35c2cce __vcrt_freefls 17469->17475 17916 7ff7b35c7d90 17469->17916 17472 7ff7b35c2de4 17470->17472 17473 7ff7b35c1e50 81 API calls 17471->17473 17474 7ff7b35c7df0 40 API calls 17472->17474 17473->17438 17474->17475 17476 7ff7b35c7c80 14 API calls 17475->17476 17477 7ff7b35c2e04 17476->17477 17478 7ff7b35c2e29 __vcrt_freefls 17477->17478 17479 7ff7b35c2ef9 17477->17479 17481 7ff7b35c7d90 40 API calls 17478->17481 17499 7ff7b35c2e6c 17478->17499 17480 7ff7b35c1e50 81 API calls 17479->17480 17480->17438 17481->17499 17482 7ff7b35c3033 17923 7ff7b35c8530 GetConsoleWindow 17482->17923 17483 7ff7b35c303a 17485 7ff7b35c3043 17483->17485 17486 7ff7b35c303e 17483->17486 17489 7ff7b35c7c80 14 API calls 17485->17489 17928 7ff7b35c86a0 GetConsoleWindow 17486->17928 17490 7ff7b35c304f __vcrt_freefls 17489->17490 17491 7ff7b35c308a 17490->17491 17492 7ff7b35c3187 17490->17492 17493 7ff7b35c3094 17491->17493 17494 7ff7b35c311a 17491->17494 17933 7ff7b35c3900 17492->17933 17798 7ff7b35c8580 17493->17798 17497 7ff7b35c7c80 14 API calls 17494->17497 17501 7ff7b35c3126 17497->17501 17498 7ff7b35c3195 17502 7ff7b35c31b7 17498->17502 17503 7ff7b35c31ab 17498->17503 17499->17482 17499->17483 17504 7ff7b35c30a5 17501->17504 17508 7ff7b35c3133 17501->17508 17506 7ff7b35c1c60 49 API calls 17502->17506 17936 7ff7b35c3a50 17503->17936 17510 7ff7b35c1e50 81 API calls 17504->17510 17517 7ff7b35c310e __vcrt_freefls 17506->17517 17511 7ff7b35c1c60 49 API calls 17508->17511 17510->17438 17514 7ff7b35c3151 17511->17514 17512 7ff7b35c3202 17848 7ff7b35c88f0 17512->17848 17514->17517 17518 7ff7b35c3158 17514->17518 17515 7ff7b35c31ed LoadLibraryExW 17515->17512 17516 7ff7b35c3215 SetDllDirectoryW 17521 7ff7b35c3248 17516->17521 17573 7ff7b35c3299 17516->17573 17517->17512 17517->17515 17520 7ff7b35c1e50 81 API calls 17518->17520 17520->17438 17523 7ff7b35c7c80 14 API calls 17521->17523 17522 7ff7b35c3437 17525 7ff7b35c3442 17522->17525 17526 7ff7b35c3449 17522->17526 17534 7ff7b35c3254 __vcrt_freefls 17523->17534 17524 7ff7b35c335a 17853 7ff7b35c2780 17524->17853 17530 7ff7b35c8530 4 API calls 17525->17530 17527 7ff7b35c3452 17526->17527 17528 7ff7b35c344d 17526->17528 18013 7ff7b35c2720 17527->18013 17531 7ff7b35c86a0 4 API calls 17528->17531 17533 7ff7b35c3447 17530->17533 17531->17527 17533->17527 17535 7ff7b35c3331 17534->17535 17539 7ff7b35c328d 17534->17539 17538 7ff7b35c7d90 40 API calls 17535->17538 17538->17573 17539->17573 17939 7ff7b35c6210 17539->17939 17551 7ff7b35c6410 FreeLibrary 17556 7ff7b35c3478 17551->17556 17560 7ff7b35c32c0 17563 7ff7b35c32e1 17560->17563 17574 7ff7b35c32c4 17560->17574 17960 7ff7b35c6250 17560->17960 17563->17574 17979 7ff7b35c6600 17563->17979 17573->17522 17573->17524 17574->17573 17995 7ff7b35c2140 17574->17995 17584 7ff7b35daa3c 17583->17584 17585 7ff7b35daa1b 17583->17585 20033 7ff7b35db2f8 17584->20033 17585->17407 17589 7ff7b35cc7fd 17588->17589 17589->17416 17591 7ff7b35cc511 17590->17591 17592 7ff7b35cc2c6 17591->17592 17593 7ff7b35ccdb8 7 API calls 17591->17593 17592->17405 17593->17592 17595 7ff7b35cc6c2 _isindst memcpy_s 17594->17595 17596 7ff7b35cc6e1 RtlCaptureContext RtlLookupFunctionEntry 17595->17596 17597 7ff7b35cc746 memcpy_s 17596->17597 17598 7ff7b35cc70a RtlVirtualUnwind 17596->17598 17599 7ff7b35cc778 IsDebuggerPresent SetUnhandledExceptionFilter UnhandledExceptionFilter 17597->17599 17598->17597 17600 7ff7b35cc7c6 _isindst 17599->17600 17600->17403 17602 7ff7b35e46bc 17601->17602 17603 7ff7b35cc3a2 17602->17603 17611 7ff7b35dd3c0 17602->17611 17603->17422 17605 7ff7b35ccdb8 17603->17605 17606 7ff7b35ccdc0 17605->17606 17607 7ff7b35ccdca 17605->17607 17623 7ff7b35cd154 17606->17623 17607->17422 17622 7ff7b35e14e8 EnterCriticalSection 17611->17622 17624 7ff7b35cd163 17623->17624 17625 7ff7b35ccdc5 17623->17625 17631 7ff7b35cd390 17624->17631 17627 7ff7b35cd1c0 17625->17627 17628 7ff7b35cd1eb 17627->17628 17629 7ff7b35cd1ef 17628->17629 17630 7ff7b35cd1ce DeleteCriticalSection 17628->17630 17629->17607 17630->17628 17635 7ff7b35cd1f8 17631->17635 17636 7ff7b35cd2e2 TlsFree 17635->17636 17642 7ff7b35cd23c __vcrt_InitializeCriticalSectionEx 17635->17642 17637 7ff7b35cd26a LoadLibraryExW 17639 7ff7b35cd28b GetLastError 17637->17639 17640 7ff7b35cd309 17637->17640 17638 7ff7b35cd329 GetProcAddress 17638->17636 17639->17642 17640->17638 17641 7ff7b35cd320 FreeLibrary 17640->17641 17641->17638 17642->17636 17642->17637 17642->17638 17643 7ff7b35cd2ad LoadLibraryExW 17642->17643 17643->17640 17643->17642 17645 7ff7b35da101 17644->17645 17652 7ff7b35da0fd 17644->17652 17665 7ff7b35e3c4c GetEnvironmentStringsW 17645->17665 17648 7ff7b35da10e 17650 7ff7b35db404 __free_lconv_num 11 API calls 17648->17650 17649 7ff7b35da11a 17672 7ff7b35da268 17649->17672 17650->17652 17652->17427 17657 7ff7b35da4a8 17652->17657 17654 7ff7b35db404 __free_lconv_num 11 API calls 17655 7ff7b35da141 17654->17655 17656 7ff7b35db404 __free_lconv_num 11 API calls 17655->17656 17656->17652 17658 7ff7b35da4e2 17657->17658 17659 7ff7b35da4cb 17657->17659 17658->17659 17660 7ff7b35dfda4 _get_daylight 11 API calls 17658->17660 17661 7ff7b35da556 17658->17661 17662 7ff7b35e0ab0 MultiByteToWideChar _fread_nolock 17658->17662 17664 7ff7b35db404 __free_lconv_num 11 API calls 17658->17664 17659->17427 17660->17658 17663 7ff7b35db404 __free_lconv_num 11 API calls 17661->17663 17662->17658 17663->17659 17664->17658 17666 7ff7b35da106 17665->17666 17667 7ff7b35e3c70 17665->17667 17666->17648 17666->17649 17668 7ff7b35de664 _fread_nolock 12 API calls 17667->17668 17669 7ff7b35e3ca7 memcpy_s 17668->17669 17670 7ff7b35db404 __free_lconv_num 11 API calls 17669->17670 17671 7ff7b35e3cc7 FreeEnvironmentStringsW 17670->17671 17671->17666 17673 7ff7b35da290 17672->17673 17674 7ff7b35dfda4 _get_daylight 11 API calls 17673->17674 17687 7ff7b35da2cb 17674->17687 17675 7ff7b35da2d3 17676 7ff7b35db404 __free_lconv_num 11 API calls 17675->17676 17677 7ff7b35da122 17676->17677 17677->17654 17678 7ff7b35da34d 17679 7ff7b35db404 __free_lconv_num 11 API calls 17678->17679 17679->17677 17680 7ff7b35dfda4 _get_daylight 11 API calls 17680->17687 17681 7ff7b35da33c 17700 7ff7b35da384 17681->17700 17685 7ff7b35db404 __free_lconv_num 11 API calls 17685->17675 17686 7ff7b35da370 17688 7ff7b35db7e4 _isindst 17 API calls 17686->17688 17687->17675 17687->17678 17687->17680 17687->17681 17687->17686 17689 7ff7b35db404 __free_lconv_num 11 API calls 17687->17689 17691 7ff7b35e1684 17687->17691 17690 7ff7b35da382 17688->17690 17689->17687 17692 7ff7b35e1691 17691->17692 17693 7ff7b35e169b 17691->17693 17692->17693 17698 7ff7b35e16b7 17692->17698 17694 7ff7b35d5de8 _get_daylight 11 API calls 17693->17694 17695 7ff7b35e16a3 17694->17695 17696 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 17695->17696 17697 7ff7b35e16af 17696->17697 17697->17687 17698->17697 17699 7ff7b35d5de8 _get_daylight 11 API calls 17698->17699 17699->17695 17704 7ff7b35da389 17700->17704 17705 7ff7b35da344 17700->17705 17701 7ff7b35da3b2 17703 7ff7b35db404 __free_lconv_num 11 API calls 17701->17703 17702 7ff7b35db404 __free_lconv_num 11 API calls 17702->17704 17703->17705 17704->17701 17704->17702 17705->17685 17708 7ff7b35e0690 17706->17708 17707 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 17712 7ff7b35e070c 17707->17712 17709 7ff7b35e0736 17708->17709 17711 7ff7b35e06e3 17708->17711 18026 7ff7b35e0568 17709->18026 17711->17707 17712->17435 18034 7ff7b35cbdb0 17713->18034 17716 7ff7b35c2ad0 18036 7ff7b35c87e0 FindFirstFileExW 17716->18036 17717 7ff7b35c2aab GetLastError 18041 7ff7b35c2310 17717->18041 17720 7ff7b35c2ac6 17725 7ff7b35cbab0 _log10_special 8 API calls 17720->17725 17722 7ff7b35c2ae3 18058 7ff7b35c8860 CreateFileW 17722->18058 17723 7ff7b35c2b3d 18071 7ff7b35c89a0 17723->18071 17728 7ff7b35c2b75 17725->17728 17727 7ff7b35c2b4b 17727->17720 17731 7ff7b35c1f30 78 API calls 17727->17731 17728->17438 17735 7ff7b35c1930 17728->17735 17730 7ff7b35c2af4 18061 7ff7b35c1f30 17730->18061 17731->17720 17734 7ff7b35c2b0c __vcrt_InitializeCriticalSectionEx 17734->17723 17736 7ff7b35c39e0 108 API calls 17735->17736 17737 7ff7b35c1965 17736->17737 17738 7ff7b35c1c23 17737->17738 17740 7ff7b35c73e0 83 API calls 17737->17740 17739 7ff7b35cbab0 _log10_special 8 API calls 17738->17739 17741 7ff7b35c1c3e 17739->17741 17742 7ff7b35c19ab 17740->17742 17741->17443 17741->17444 17784 7ff7b35c19e3 17742->17784 18447 7ff7b35cfbcc 17742->18447 17744 7ff7b35cf544 74 API calls 17744->17738 17745 7ff7b35c19c5 17746 7ff7b35c19c9 17745->17746 17747 7ff7b35c19e8 17745->17747 17749 7ff7b35d5de8 _get_daylight 11 API calls 17746->17749 18451 7ff7b35cf894 17747->18451 17750 7ff7b35c19ce 17749->17750 18454 7ff7b35c2020 17750->18454 17753 7ff7b35c1a06 17755 7ff7b35d5de8 _get_daylight 11 API calls 17753->17755 17754 7ff7b35c1a25 17758 7ff7b35c1a3c 17754->17758 17759 7ff7b35c1a5b 17754->17759 17756 7ff7b35c1a0b 17755->17756 17757 7ff7b35c2020 87 API calls 17756->17757 17757->17784 17761 7ff7b35d5de8 _get_daylight 11 API calls 17758->17761 17760 7ff7b35c1c60 49 API calls 17759->17760 17763 7ff7b35c1a72 17760->17763 17762 7ff7b35c1a41 17761->17762 17764 7ff7b35c2020 87 API calls 17762->17764 17765 7ff7b35c1c60 49 API calls 17763->17765 17764->17784 17766 7ff7b35c1abd 17765->17766 17767 7ff7b35cfbcc 73 API calls 17766->17767 17768 7ff7b35c1ae1 17767->17768 17769 7ff7b35c1af6 17768->17769 17770 7ff7b35c1b15 17768->17770 17772 7ff7b35d5de8 _get_daylight 11 API calls 17769->17772 17771 7ff7b35cf894 _fread_nolock 53 API calls 17770->17771 17773 7ff7b35c1b2a 17771->17773 17774 7ff7b35c1afb 17772->17774 17775 7ff7b35c1b30 17773->17775 17776 7ff7b35c1b4f 17773->17776 17777 7ff7b35c2020 87 API calls 17774->17777 17778 7ff7b35d5de8 _get_daylight 11 API calls 17775->17778 18469 7ff7b35cf608 17776->18469 17777->17784 17780 7ff7b35c1b35 17778->17780 17782 7ff7b35c2020 87 API calls 17780->17782 17782->17784 17783 7ff7b35c1e50 81 API calls 17783->17784 17784->17744 17786 7ff7b35c7c8a 17785->17786 17787 7ff7b35c88f0 2 API calls 17786->17787 17788 7ff7b35c7ca9 GetEnvironmentVariableW 17787->17788 17789 7ff7b35c7d12 17788->17789 17790 7ff7b35c7cc6 ExpandEnvironmentStringsW 17788->17790 17792 7ff7b35cbab0 _log10_special 8 API calls 17789->17792 17790->17789 17791 7ff7b35c7ce8 17790->17791 17793 7ff7b35c89a0 2 API calls 17791->17793 17794 7ff7b35c7d24 17792->17794 17795 7ff7b35c7cfa 17793->17795 17794->17452 17796 7ff7b35cbab0 _log10_special 8 API calls 17795->17796 17797 7ff7b35c7d0a 17796->17797 17797->17452 17799 7ff7b35c8595 17798->17799 18733 7ff7b35c79c0 GetCurrentProcess OpenProcessToken 17799->18733 17802 7ff7b35c79c0 7 API calls 17803 7ff7b35c85c1 17802->17803 17804 7ff7b35c85f4 17803->17804 17805 7ff7b35c85da 17803->17805 17806 7ff7b35c1d50 48 API calls 17804->17806 17807 7ff7b35c1d50 48 API calls 17805->17807 17808 7ff7b35c8607 LocalFree LocalFree 17806->17808 17809 7ff7b35c85f2 17807->17809 17810 7ff7b35c8623 17808->17810 17812 7ff7b35c862f 17808->17812 17809->17808 18743 7ff7b35c2220 17810->18743 17813 7ff7b35cbab0 _log10_special 8 API calls 17812->17813 17814 7ff7b35c3099 17813->17814 17814->17504 17815 7ff7b35c7ab0 17814->17815 17816 7ff7b35c7ac8 17815->17816 17817 7ff7b35c7b4a GetTempPathW GetCurrentProcessId 17816->17817 17818 7ff7b35c7aec 17816->17818 18754 7ff7b35c8700 17817->18754 17820 7ff7b35c7c80 14 API calls 17818->17820 17822 7ff7b35c7af8 17820->17822 17821 7ff7b35c7b78 __vcrt_freefls 17833 7ff7b35c7bb5 __vcrt_freefls 17821->17833 18758 7ff7b35d9a44 17821->18758 18761 7ff7b35c7620 17822->18761 17827 7ff7b35c7b38 __vcrt_freefls 17847 7ff7b35c7c24 __vcrt_freefls 17827->17847 17839 7ff7b35c88f0 2 API calls 17833->17839 17833->17847 17834 7ff7b35cbab0 _log10_special 8 API calls 17835 7ff7b35c3101 17834->17835 17835->17504 17835->17517 17840 7ff7b35c7c01 17839->17840 17841 7ff7b35c7c06 17840->17841 17842 7ff7b35c7c39 17840->17842 17843 7ff7b35c88f0 2 API calls 17841->17843 17844 7ff7b35d9114 38 API calls 17842->17844 17845 7ff7b35c7c16 17843->17845 17844->17847 17846 7ff7b35d9114 38 API calls 17845->17846 17846->17847 17847->17834 17849 7ff7b35c8912 MultiByteToWideChar 17848->17849 17850 7ff7b35c8936 17848->17850 17849->17850 17852 7ff7b35c894c __vcrt_freefls 17849->17852 17851 7ff7b35c8953 MultiByteToWideChar 17850->17851 17850->17852 17851->17852 17852->17516 17864 7ff7b35c278e memcpy_s 17853->17864 17854 7ff7b35cbab0 _log10_special 8 API calls 17855 7ff7b35c2a24 17854->17855 17855->17438 17872 7ff7b35c8510 LocalFree 17855->17872 17856 7ff7b35c2987 17856->17854 17858 7ff7b35c1c60 49 API calls 17858->17864 17859 7ff7b35c29a2 17861 7ff7b35c1e50 81 API calls 17859->17861 17861->17856 17864->17856 17864->17858 17864->17859 17865 7ff7b35c2989 17864->17865 17867 7ff7b35c2140 81 API calls 17864->17867 17870 7ff7b35c2990 17864->17870 18941 7ff7b35c3980 17864->18941 18947 7ff7b35c7270 17864->18947 18958 7ff7b35c15e0 17864->18958 19006 7ff7b35c6570 17864->19006 19010 7ff7b35c35b0 17864->19010 19054 7ff7b35c3870 17864->19054 17866 7ff7b35c1e50 81 API calls 17865->17866 17866->17856 17867->17864 17871 7ff7b35c1e50 81 API calls 17870->17871 17871->17856 17874 7ff7b35c1c85 17873->17874 17875 7ff7b35d5864 49 API calls 17874->17875 17876 7ff7b35c1ca8 17875->17876 17876->17447 17878 7ff7b35c88f0 2 API calls 17877->17878 17879 7ff7b35c7e04 17878->17879 17880 7ff7b35d9114 38 API calls 17879->17880 17881 7ff7b35c7e16 __vcrt_freefls 17880->17881 17881->17461 17883 7ff7b35c39ec 17882->17883 17884 7ff7b35c88f0 2 API calls 17883->17884 17885 7ff7b35c3a14 17884->17885 17886 7ff7b35c88f0 2 API calls 17885->17886 17887 7ff7b35c3a27 17886->17887 19221 7ff7b35d6ef4 17887->19221 17890 7ff7b35cbab0 _log10_special 8 API calls 17891 7ff7b35c2ceb 17890->17891 17891->17450 17892 7ff7b35c73e0 17891->17892 17893 7ff7b35c7404 17892->17893 17894 7ff7b35c74db __vcrt_freefls 17893->17894 17895 7ff7b35cfbcc 73 API calls 17893->17895 17894->17454 17896 7ff7b35c7420 17895->17896 17896->17894 19612 7ff7b35d87a4 17896->19612 17898 7ff7b35cfbcc 73 API calls 17900 7ff7b35c7435 17898->17900 17899 7ff7b35cf894 _fread_nolock 53 API calls 17899->17900 17900->17894 17900->17898 17900->17899 17902 7ff7b35cf574 17901->17902 19627 7ff7b35cf320 17902->19627 17904 7ff7b35cf58d 17904->17450 17906 7ff7b35cbdb0 17905->17906 17907 7ff7b35c1e74 GetCurrentProcessId 17906->17907 17908 7ff7b35c1c60 49 API calls 17907->17908 17909 7ff7b35c1ec5 17908->17909 17910 7ff7b35d5864 49 API calls 17909->17910 17911 7ff7b35c1f02 17910->17911 17912 7ff7b35c1cc0 80 API calls 17911->17912 17913 7ff7b35c1f0c 17912->17913 17914 7ff7b35cbab0 _log10_special 8 API calls 17913->17914 17915 7ff7b35c1f1c 17914->17915 17915->17438 17917 7ff7b35c88f0 2 API calls 17916->17917 17918 7ff7b35c7dac 17917->17918 17919 7ff7b35c88f0 2 API calls 17918->17919 17920 7ff7b35c7dbc 17919->17920 17921 7ff7b35d9114 38 API calls 17920->17921 17922 7ff7b35c7dca __vcrt_freefls 17921->17922 17922->17464 17924 7ff7b35c8544 GetCurrentProcessId GetWindowThreadProcessId 17923->17924 17925 7ff7b35c3038 17923->17925 17924->17925 17926 7ff7b35c8563 17924->17926 17925->17485 17926->17925 17927 7ff7b35c8569 ShowWindow 17926->17927 17927->17925 17929 7ff7b35c86b4 GetCurrentProcessId GetWindowThreadProcessId 17928->17929 17930 7ff7b35c86e7 17928->17930 17929->17930 17931 7ff7b35c86d3 17929->17931 17930->17485 17931->17930 17932 7ff7b35c86d9 ShowWindow 17931->17932 17932->17930 17934 7ff7b35c1c60 49 API calls 17933->17934 17935 7ff7b35c391d 17934->17935 17935->17498 17937 7ff7b35c1c60 49 API calls 17936->17937 17938 7ff7b35c3a80 17937->17938 17938->17517 17940 7ff7b35c6225 17939->17940 17941 7ff7b35d5de8 _get_daylight 11 API calls 17940->17941 17944 7ff7b35c32ab 17940->17944 17942 7ff7b35c6232 17941->17942 17943 7ff7b35c2020 87 API calls 17942->17943 17943->17944 17945 7ff7b35c6790 17944->17945 19638 7ff7b35c1450 17945->19638 17947 7ff7b35c67b8 17948 7ff7b35c3a50 49 API calls 17947->17948 17958 7ff7b35c6909 __vcrt_freefls 17947->17958 17949 7ff7b35c67da 17948->17949 17950 7ff7b35c67df 17949->17950 17951 7ff7b35c3a50 49 API calls 17949->17951 17953 7ff7b35c2140 81 API calls 17950->17953 17952 7ff7b35c67fe 17951->17952 17952->17950 17954 7ff7b35c3a50 49 API calls 17952->17954 17953->17958 17955 7ff7b35c681a 17954->17955 17955->17950 17956 7ff7b35c6823 17955->17956 17958->17560 17961 7ff7b35c626c 17960->17961 17963 7ff7b35c1820 45 API calls 17961->17963 17965 7ff7b35c63fa 17961->17965 17966 7ff7b35c1c60 49 API calls 17961->17966 17968 7ff7b35c638f 17961->17968 17969 7ff7b35c63e7 17961->17969 17971 7ff7b35c3980 10 API calls 17961->17971 17972 7ff7b35c7270 52 API calls 17961->17972 17973 7ff7b35c2140 81 API calls 17961->17973 17974 7ff7b35c63d4 17961->17974 17976 7ff7b35c15e0 116 API calls 17961->17976 17977 7ff7b35c63bd 17961->17977 17962 7ff7b35cbab0 _log10_special 8 API calls 17964 7ff7b35c63a1 17962->17964 17963->17961 17964->17563 17967 7ff7b35c1e50 81 API calls 17965->17967 17966->17961 17967->17968 17968->17962 17970 7ff7b35c1e50 81 API calls 17969->17970 17970->17968 17971->17961 17972->17961 17973->17961 17975 7ff7b35c1e50 81 API calls 17974->17975 17975->17968 17976->17961 17978 7ff7b35c1e50 81 API calls 17977->17978 17978->17968 19668 7ff7b35c82d0 17979->19668 17996 7ff7b35cbdb0 17995->17996 17997 7ff7b35c2164 GetCurrentProcessId 17996->17997 17998 7ff7b35c1c60 49 API calls 17997->17998 19744 7ff7b35c57b0 18013->19744 18016 7ff7b35c2759 18022 7ff7b35c2a30 18016->18022 18023 7ff7b35c2a3e 18022->18023 18024 7ff7b35c2a4f 18023->18024 20032 7ff7b35c82b0 FreeLibrary 18023->20032 18024->17551 18033 7ff7b35d627c EnterCriticalSection 18026->18033 18035 7ff7b35c2a7c GetModuleFileNameW 18034->18035 18035->17716 18035->17717 18037 7ff7b35c881f FindClose 18036->18037 18038 7ff7b35c8832 18036->18038 18037->18038 18039 7ff7b35cbab0 _log10_special 8 API calls 18038->18039 18040 7ff7b35c2ada 18039->18040 18040->17722 18040->17723 18042 7ff7b35cbdb0 18041->18042 18043 7ff7b35c2330 GetCurrentProcessId 18042->18043 18076 7ff7b35c1d50 18043->18076 18045 7ff7b35c237b 18080 7ff7b35d5ab8 18045->18080 18048 7ff7b35c1d50 48 API calls 18049 7ff7b35c23eb FormatMessageW 18048->18049 18051 7ff7b35c2436 18049->18051 18052 7ff7b35c2424 18049->18052 18098 7ff7b35c1e00 18051->18098 18053 7ff7b35c1d50 48 API calls 18052->18053 18053->18051 18056 7ff7b35cbab0 _log10_special 8 API calls 18057 7ff7b35c2464 18056->18057 18057->17720 18059 7ff7b35c88a0 GetFinalPathNameByHandleW CloseHandle 18058->18059 18060 7ff7b35c2af0 18058->18060 18059->18060 18060->17730 18060->17734 18062 7ff7b35c1f54 18061->18062 18063 7ff7b35c1d50 48 API calls 18062->18063 18064 7ff7b35c1fa5 18063->18064 18065 7ff7b35d5ab8 48 API calls 18064->18065 18066 7ff7b35c1fe3 18065->18066 18067 7ff7b35c1e00 78 API calls 18066->18067 18068 7ff7b35c2001 18067->18068 18069 7ff7b35cbab0 _log10_special 8 API calls 18068->18069 18070 7ff7b35c2011 18069->18070 18070->17720 18072 7ff7b35c89ca WideCharToMultiByte 18071->18072 18073 7ff7b35c89f5 18071->18073 18072->18073 18075 7ff7b35c8a0b __vcrt_freefls 18072->18075 18074 7ff7b35c8a12 WideCharToMultiByte 18073->18074 18073->18075 18074->18075 18075->17727 18077 7ff7b35c1d75 18076->18077 18078 7ff7b35d5ab8 48 API calls 18077->18078 18079 7ff7b35c1d98 18078->18079 18079->18045 18082 7ff7b35d5b12 18080->18082 18081 7ff7b35d5b37 18083 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18081->18083 18082->18081 18084 7ff7b35d5b73 18082->18084 18097 7ff7b35d5b61 18083->18097 18102 7ff7b35d2da8 18084->18102 18086 7ff7b35d5c54 18089 7ff7b35db404 __free_lconv_num 11 API calls 18086->18089 18088 7ff7b35cbab0 _log10_special 8 API calls 18090 7ff7b35c23bb 18088->18090 18089->18097 18090->18048 18091 7ff7b35d5c29 18094 7ff7b35db404 __free_lconv_num 11 API calls 18091->18094 18092 7ff7b35d5c7a 18092->18086 18093 7ff7b35d5c84 18092->18093 18096 7ff7b35db404 __free_lconv_num 11 API calls 18093->18096 18094->18097 18095 7ff7b35d5c20 18095->18086 18095->18091 18096->18097 18097->18088 18099 7ff7b35c1e26 18098->18099 18432 7ff7b35d5740 18099->18432 18101 7ff7b35c1e3c 18101->18056 18103 7ff7b35d2de6 18102->18103 18104 7ff7b35d2dd6 18102->18104 18105 7ff7b35d2def 18103->18105 18111 7ff7b35d2e1d 18103->18111 18106 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18104->18106 18107 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18105->18107 18108 7ff7b35d2e15 18106->18108 18107->18108 18108->18086 18108->18091 18108->18092 18108->18095 18111->18104 18111->18108 18113 7ff7b35d43f0 18111->18113 18146 7ff7b35d3540 18111->18146 18183 7ff7b35d2330 18111->18183 18114 7ff7b35d44a3 18113->18114 18115 7ff7b35d4432 18113->18115 18116 7ff7b35d44fc 18114->18116 18117 7ff7b35d44a8 18114->18117 18118 7ff7b35d44cd 18115->18118 18119 7ff7b35d4438 18115->18119 18125 7ff7b35d4513 18116->18125 18126 7ff7b35d4506 18116->18126 18131 7ff7b35d450b 18116->18131 18120 7ff7b35d44dd 18117->18120 18121 7ff7b35d44aa 18117->18121 18206 7ff7b35d12cc 18118->18206 18122 7ff7b35d446c 18119->18122 18123 7ff7b35d443d 18119->18123 18213 7ff7b35d0ebc 18120->18213 18124 7ff7b35d444c 18121->18124 18134 7ff7b35d44b9 18121->18134 18128 7ff7b35d4443 18122->18128 18122->18131 18123->18125 18123->18128 18144 7ff7b35d453c 18124->18144 18186 7ff7b35d4ba4 18124->18186 18220 7ff7b35d50f8 18125->18220 18126->18118 18126->18131 18128->18124 18133 7ff7b35d447e 18128->18133 18141 7ff7b35d4467 18128->18141 18131->18144 18224 7ff7b35d16dc 18131->18224 18133->18144 18196 7ff7b35d4ee0 18133->18196 18134->18118 18136 7ff7b35d44be 18134->18136 18136->18144 18202 7ff7b35d4fa4 18136->18202 18138 7ff7b35cbab0 _log10_special 8 API calls 18140 7ff7b35d4836 18138->18140 18140->18111 18141->18144 18145 7ff7b35d4728 18141->18145 18231 7ff7b35d5210 18141->18231 18144->18138 18145->18144 18237 7ff7b35dfa70 18145->18237 18147 7ff7b35d3564 18146->18147 18148 7ff7b35d354e 18146->18148 18149 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18147->18149 18150 7ff7b35d35a4 18147->18150 18148->18150 18151 7ff7b35d44a3 18148->18151 18152 7ff7b35d4432 18148->18152 18149->18150 18150->18111 18153 7ff7b35d44fc 18151->18153 18154 7ff7b35d44a8 18151->18154 18155 7ff7b35d44cd 18152->18155 18156 7ff7b35d4438 18152->18156 18162 7ff7b35d4513 18153->18162 18163 7ff7b35d4506 18153->18163 18168 7ff7b35d450b 18153->18168 18157 7ff7b35d44dd 18154->18157 18158 7ff7b35d44aa 18154->18158 18164 7ff7b35d12cc 38 API calls 18155->18164 18159 7ff7b35d446c 18156->18159 18160 7ff7b35d443d 18156->18160 18166 7ff7b35d0ebc 38 API calls 18157->18166 18161 7ff7b35d444c 18158->18161 18170 7ff7b35d44b9 18158->18170 18165 7ff7b35d4443 18159->18165 18159->18168 18160->18162 18160->18165 18167 7ff7b35d4ba4 47 API calls 18161->18167 18181 7ff7b35d453c 18161->18181 18169 7ff7b35d50f8 45 API calls 18162->18169 18163->18155 18163->18168 18178 7ff7b35d4467 18164->18178 18165->18161 18171 7ff7b35d447e 18165->18171 18165->18178 18166->18178 18167->18178 18172 7ff7b35d16dc 38 API calls 18168->18172 18168->18181 18169->18178 18170->18155 18173 7ff7b35d44be 18170->18173 18174 7ff7b35d4ee0 46 API calls 18171->18174 18171->18181 18172->18178 18176 7ff7b35d4fa4 37 API calls 18173->18176 18173->18181 18174->18178 18175 7ff7b35cbab0 _log10_special 8 API calls 18177 7ff7b35d4836 18175->18177 18176->18178 18177->18111 18179 7ff7b35d5210 45 API calls 18178->18179 18178->18181 18182 7ff7b35d4728 18178->18182 18179->18182 18180 7ff7b35dfa70 46 API calls 18180->18182 18181->18175 18182->18180 18182->18181 18415 7ff7b35d0540 18183->18415 18187 7ff7b35d4bca 18186->18187 18249 7ff7b35d00f8 18187->18249 18191 7ff7b35d4d0f 18194 7ff7b35d5210 45 API calls 18191->18194 18195 7ff7b35d4d9d 18191->18195 18193 7ff7b35d5210 45 API calls 18193->18191 18194->18195 18195->18141 18197 7ff7b35d4f15 18196->18197 18198 7ff7b35d4f33 18197->18198 18199 7ff7b35d5210 45 API calls 18197->18199 18201 7ff7b35d4f5a 18197->18201 18200 7ff7b35dfa70 46 API calls 18198->18200 18199->18198 18200->18201 18201->18141 18203 7ff7b35d4fc5 18202->18203 18204 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18203->18204 18205 7ff7b35d4ff6 18203->18205 18204->18205 18205->18141 18207 7ff7b35d12ff 18206->18207 18208 7ff7b35d132e 18207->18208 18210 7ff7b35d13eb 18207->18210 18212 7ff7b35d136b 18208->18212 18385 7ff7b35d01a0 18208->18385 18211 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18210->18211 18211->18212 18212->18141 18214 7ff7b35d0eef 18213->18214 18215 7ff7b35d0f1e 18214->18215 18217 7ff7b35d0fdb 18214->18217 18216 7ff7b35d01a0 12 API calls 18215->18216 18219 7ff7b35d0f5b 18215->18219 18216->18219 18218 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18217->18218 18218->18219 18219->18141 18221 7ff7b35d513b 18220->18221 18223 7ff7b35d513f __crtLCMapStringW 18221->18223 18393 7ff7b35d5194 18221->18393 18223->18141 18225 7ff7b35d170f 18224->18225 18226 7ff7b35d173e 18225->18226 18228 7ff7b35d17fb 18225->18228 18227 7ff7b35d01a0 12 API calls 18226->18227 18230 7ff7b35d177b 18226->18230 18227->18230 18229 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18228->18229 18229->18230 18230->18141 18232 7ff7b35d5227 18231->18232 18397 7ff7b35dea20 18232->18397 18239 7ff7b35dfaa1 18237->18239 18247 7ff7b35dfaaf 18237->18247 18238 7ff7b35dfacf 18241 7ff7b35dfae0 18238->18241 18242 7ff7b35dfb07 18238->18242 18239->18238 18240 7ff7b35d5210 45 API calls 18239->18240 18239->18247 18240->18238 18405 7ff7b35e12b0 18241->18405 18244 7ff7b35dfb92 18242->18244 18245 7ff7b35dfb31 18242->18245 18242->18247 18246 7ff7b35e0ab0 _fread_nolock MultiByteToWideChar 18244->18246 18245->18247 18408 7ff7b35e0ab0 18245->18408 18246->18247 18247->18145 18250 7ff7b35d012f 18249->18250 18256 7ff7b35d011e 18249->18256 18251 7ff7b35de664 _fread_nolock 12 API calls 18250->18251 18250->18256 18252 7ff7b35d015c 18251->18252 18253 7ff7b35d0170 18252->18253 18255 7ff7b35db404 __free_lconv_num 11 API calls 18252->18255 18254 7ff7b35db404 __free_lconv_num 11 API calls 18253->18254 18254->18256 18255->18253 18257 7ff7b35df5d8 18256->18257 18258 7ff7b35df5f5 18257->18258 18259 7ff7b35df628 18257->18259 18260 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18258->18260 18259->18258 18262 7ff7b35df65a 18259->18262 18261 7ff7b35d4ced 18260->18261 18261->18191 18261->18193 18267 7ff7b35df76d 18262->18267 18274 7ff7b35df6a2 18262->18274 18263 7ff7b35df85f 18312 7ff7b35deac4 18263->18312 18264 7ff7b35df825 18305 7ff7b35dee5c 18264->18305 18266 7ff7b35df7f4 18298 7ff7b35df13c 18266->18298 18267->18263 18267->18264 18267->18266 18269 7ff7b35df7b7 18267->18269 18271 7ff7b35df7ad 18267->18271 18288 7ff7b35df36c 18269->18288 18271->18264 18273 7ff7b35df7b2 18271->18273 18273->18266 18273->18269 18274->18261 18279 7ff7b35db34c 18274->18279 18277 7ff7b35db7e4 _isindst 17 API calls 18278 7ff7b35df8bc 18277->18278 18280 7ff7b35db363 18279->18280 18281 7ff7b35db359 18279->18281 18282 7ff7b35d5de8 _get_daylight 11 API calls 18280->18282 18281->18280 18286 7ff7b35db37e 18281->18286 18283 7ff7b35db36a 18282->18283 18284 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 18283->18284 18285 7ff7b35db376 18284->18285 18285->18261 18285->18277 18286->18285 18287 7ff7b35d5de8 _get_daylight 11 API calls 18286->18287 18287->18283 18321 7ff7b35e52bc 18288->18321 18292 7ff7b35df414 18293 7ff7b35df418 18292->18293 18294 7ff7b35df469 18292->18294 18295 7ff7b35df434 18292->18295 18293->18261 18374 7ff7b35def58 18294->18374 18370 7ff7b35df214 18295->18370 18299 7ff7b35e52bc 38 API calls 18298->18299 18300 7ff7b35df186 18299->18300 18301 7ff7b35e4d04 37 API calls 18300->18301 18302 7ff7b35df1d6 18301->18302 18303 7ff7b35df1da 18302->18303 18304 7ff7b35df214 45 API calls 18302->18304 18303->18261 18304->18303 18306 7ff7b35e52bc 38 API calls 18305->18306 18307 7ff7b35deea7 18306->18307 18308 7ff7b35e4d04 37 API calls 18307->18308 18309 7ff7b35deeff 18308->18309 18310 7ff7b35def03 18309->18310 18311 7ff7b35def58 45 API calls 18309->18311 18310->18261 18311->18310 18313 7ff7b35deb3c 18312->18313 18314 7ff7b35deb09 18312->18314 18315 7ff7b35deb54 18313->18315 18319 7ff7b35debd5 18313->18319 18316 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18314->18316 18317 7ff7b35dee5c 46 API calls 18315->18317 18318 7ff7b35deb35 memcpy_s 18316->18318 18317->18318 18318->18261 18319->18318 18320 7ff7b35d5210 45 API calls 18319->18320 18320->18318 18322 7ff7b35e530f fegetenv 18321->18322 18323 7ff7b35e903c 37 API calls 18322->18323 18326 7ff7b35e5362 18323->18326 18324 7ff7b35e538f 18328 7ff7b35db34c __std_exception_copy 37 API calls 18324->18328 18325 7ff7b35e5452 18327 7ff7b35e903c 37 API calls 18325->18327 18326->18325 18331 7ff7b35e542c 18326->18331 18332 7ff7b35e537d 18326->18332 18329 7ff7b35e547c 18327->18329 18330 7ff7b35e540d 18328->18330 18333 7ff7b35e903c 37 API calls 18329->18333 18334 7ff7b35e6534 18330->18334 18340 7ff7b35e5415 18330->18340 18335 7ff7b35db34c __std_exception_copy 37 API calls 18331->18335 18332->18324 18332->18325 18336 7ff7b35e548d 18333->18336 18337 7ff7b35db7e4 _isindst 17 API calls 18334->18337 18335->18330 18338 7ff7b35e9230 20 API calls 18336->18338 18339 7ff7b35e6549 18337->18339 18343 7ff7b35e54f6 memcpy_s 18338->18343 18341 7ff7b35cbab0 _log10_special 8 API calls 18340->18341 18342 7ff7b35df3b9 18341->18342 18366 7ff7b35e4d04 18342->18366 18344 7ff7b35e589f memcpy_s 18343->18344 18345 7ff7b35e5537 memcpy_s 18343->18345 18350 7ff7b35d5de8 _get_daylight 11 API calls 18343->18350 18345->18345 18360 7ff7b35e5e7b memcpy_s 18345->18360 18362 7ff7b35e5993 memcpy_s 18345->18362 18346 7ff7b35e5bdf 18347 7ff7b35e4e20 37 API calls 18346->18347 18352 7ff7b35e62f7 18347->18352 18348 7ff7b35e5b8b 18348->18346 18349 7ff7b35e654c memcpy_s 37 API calls 18348->18349 18349->18346 18351 7ff7b35e5970 18350->18351 18353 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 18351->18353 18355 7ff7b35e654c memcpy_s 37 API calls 18352->18355 18359 7ff7b35e6352 18352->18359 18353->18345 18354 7ff7b35e64d8 18357 7ff7b35e903c 37 API calls 18354->18357 18355->18359 18356 7ff7b35d5de8 11 API calls _get_daylight 18356->18360 18357->18340 18358 7ff7b35d5de8 11 API calls _get_daylight 18358->18362 18359->18354 18361 7ff7b35e4e20 37 API calls 18359->18361 18364 7ff7b35e654c memcpy_s 37 API calls 18359->18364 18360->18346 18360->18348 18360->18356 18365 7ff7b35db7c4 37 API calls _invalid_parameter_noinfo 18360->18365 18361->18359 18362->18348 18362->18358 18363 7ff7b35db7c4 37 API calls _invalid_parameter_noinfo 18362->18363 18363->18362 18364->18359 18365->18360 18367 7ff7b35e4d23 18366->18367 18368 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18367->18368 18369 7ff7b35e4d4e memcpy_s 18367->18369 18368->18369 18369->18292 18371 7ff7b35df240 memcpy_s 18370->18371 18372 7ff7b35d5210 45 API calls 18371->18372 18373 7ff7b35df2fa memcpy_s 18371->18373 18372->18373 18373->18293 18375 7ff7b35def93 18374->18375 18376 7ff7b35defe0 memcpy_s 18374->18376 18377 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18375->18377 18379 7ff7b35df04b 18376->18379 18381 7ff7b35d5210 45 API calls 18376->18381 18378 7ff7b35defbf 18377->18378 18378->18293 18380 7ff7b35db34c __std_exception_copy 37 API calls 18379->18380 18384 7ff7b35df08d memcpy_s 18380->18384 18381->18379 18382 7ff7b35db7e4 _isindst 17 API calls 18383 7ff7b35df138 18382->18383 18384->18382 18386 7ff7b35d01d7 18385->18386 18392 7ff7b35d01c6 18385->18392 18387 7ff7b35de664 _fread_nolock 12 API calls 18386->18387 18386->18392 18388 7ff7b35d0208 18387->18388 18389 7ff7b35d021c 18388->18389 18391 7ff7b35db404 __free_lconv_num 11 API calls 18388->18391 18390 7ff7b35db404 __free_lconv_num 11 API calls 18389->18390 18390->18392 18391->18389 18392->18212 18394 7ff7b35d51b2 18393->18394 18395 7ff7b35d51ba 18393->18395 18396 7ff7b35d5210 45 API calls 18394->18396 18395->18223 18396->18395 18398 7ff7b35dea39 18397->18398 18400 7ff7b35d524f 18397->18400 18399 7ff7b35e4514 45 API calls 18398->18399 18398->18400 18399->18400 18401 7ff7b35dea8c 18400->18401 18402 7ff7b35deaa5 18401->18402 18403 7ff7b35d525f 18401->18403 18402->18403 18404 7ff7b35e3860 45 API calls 18402->18404 18403->18145 18404->18403 18411 7ff7b35e7f98 18405->18411 18410 7ff7b35e0ab9 MultiByteToWideChar 18408->18410 18414 7ff7b35e7ffc 18411->18414 18412 7ff7b35cbab0 _log10_special 8 API calls 18413 7ff7b35e12cd 18412->18413 18413->18247 18414->18412 18416 7ff7b35d0575 18415->18416 18417 7ff7b35d0587 18415->18417 18418 7ff7b35d5de8 _get_daylight 11 API calls 18416->18418 18419 7ff7b35d0595 18417->18419 18423 7ff7b35d05d1 18417->18423 18420 7ff7b35d057a 18418->18420 18421 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18419->18421 18422 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 18420->18422 18429 7ff7b35d0585 18421->18429 18422->18429 18424 7ff7b35d094d 18423->18424 18426 7ff7b35d5de8 _get_daylight 11 API calls 18423->18426 18425 7ff7b35d5de8 _get_daylight 11 API calls 18424->18425 18424->18429 18427 7ff7b35d0be1 18425->18427 18428 7ff7b35d0942 18426->18428 18430 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 18427->18430 18431 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 18428->18431 18429->18111 18430->18429 18431->18424 18433 7ff7b35d576a 18432->18433 18434 7ff7b35d57a2 18433->18434 18436 7ff7b35d57d5 18433->18436 18435 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18434->18435 18438 7ff7b35d57cb 18435->18438 18439 7ff7b35d0078 18436->18439 18438->18101 18446 7ff7b35d627c EnterCriticalSection 18439->18446 18448 7ff7b35cfbfc 18447->18448 18475 7ff7b35cf95c 18448->18475 18450 7ff7b35cfc15 18450->17745 18487 7ff7b35cf8b4 18451->18487 18455 7ff7b35cbdb0 18454->18455 18456 7ff7b35c2040 GetCurrentProcessId 18455->18456 18457 7ff7b35c1c60 49 API calls 18456->18457 18458 7ff7b35c208b 18457->18458 18501 7ff7b35d5864 18458->18501 18462 7ff7b35c20ec 18463 7ff7b35c1c60 49 API calls 18462->18463 18464 7ff7b35c2106 18463->18464 18541 7ff7b35c1cc0 18464->18541 18467 7ff7b35cbab0 _log10_special 8 API calls 18468 7ff7b35c2120 18467->18468 18468->17784 18470 7ff7b35c1b69 18469->18470 18471 7ff7b35cf611 18469->18471 18470->17783 18470->17784 18472 7ff7b35d5de8 _get_daylight 11 API calls 18471->18472 18473 7ff7b35cf616 18472->18473 18474 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 18473->18474 18474->18470 18476 7ff7b35cf9c6 18475->18476 18477 7ff7b35cf986 18475->18477 18476->18477 18479 7ff7b35cf9d2 18476->18479 18478 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18477->18478 18481 7ff7b35cf9ad 18478->18481 18486 7ff7b35d627c EnterCriticalSection 18479->18486 18481->18450 18488 7ff7b35c1a00 18487->18488 18489 7ff7b35cf8de 18487->18489 18488->17753 18488->17754 18489->18488 18490 7ff7b35cf8ed memcpy_s 18489->18490 18491 7ff7b35cf92a 18489->18491 18494 7ff7b35d5de8 _get_daylight 11 API calls 18490->18494 18500 7ff7b35d627c EnterCriticalSection 18491->18500 18496 7ff7b35cf902 18494->18496 18497 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 18496->18497 18497->18488 18505 7ff7b35d58be 18501->18505 18502 7ff7b35d58e3 18503 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18502->18503 18507 7ff7b35d590d 18503->18507 18504 7ff7b35d591f 18552 7ff7b35d2758 18504->18552 18505->18502 18505->18504 18509 7ff7b35cbab0 _log10_special 8 API calls 18507->18509 18508 7ff7b35d59fc 18510 7ff7b35db404 __free_lconv_num 11 API calls 18508->18510 18511 7ff7b35c20ca 18509->18511 18510->18507 18519 7ff7b35d6040 18511->18519 18513 7ff7b35d5a20 18513->18508 18515 7ff7b35d5a2a 18513->18515 18514 7ff7b35d59d1 18516 7ff7b35db404 __free_lconv_num 11 API calls 18514->18516 18518 7ff7b35db404 __free_lconv_num 11 API calls 18515->18518 18516->18507 18517 7ff7b35d59c8 18517->18508 18517->18514 18518->18507 18520 7ff7b35dc168 _get_daylight 11 API calls 18519->18520 18521 7ff7b35d6057 18520->18521 18522 7ff7b35d605f 18521->18522 18523 7ff7b35dfda4 _get_daylight 11 API calls 18521->18523 18526 7ff7b35d6097 18521->18526 18522->18462 18524 7ff7b35d608c 18523->18524 18525 7ff7b35db404 __free_lconv_num 11 API calls 18524->18525 18525->18526 18526->18522 18690 7ff7b35dfe2c 18526->18690 18529 7ff7b35db7e4 _isindst 17 API calls 18530 7ff7b35d60dc 18529->18530 18531 7ff7b35dfda4 _get_daylight 11 API calls 18530->18531 18532 7ff7b35d6129 18531->18532 18533 7ff7b35db404 __free_lconv_num 11 API calls 18532->18533 18534 7ff7b35d6137 18533->18534 18535 7ff7b35dfda4 _get_daylight 11 API calls 18534->18535 18539 7ff7b35d6161 18534->18539 18536 7ff7b35d6153 18535->18536 18538 7ff7b35db404 __free_lconv_num 11 API calls 18536->18538 18538->18539 18540 7ff7b35d616a 18539->18540 18699 7ff7b35e0280 18539->18699 18540->18462 18542 7ff7b35c1ccc 18541->18542 18543 7ff7b35c88f0 2 API calls 18542->18543 18544 7ff7b35c1cf4 18543->18544 18545 7ff7b35c1d19 18544->18545 18546 7ff7b35c1cfe 18544->18546 18714 7ff7b35c1db0 18545->18714 18548 7ff7b35c1e00 78 API calls 18546->18548 18549 7ff7b35c1d17 18548->18549 18550 7ff7b35cbab0 _log10_special 8 API calls 18549->18550 18551 7ff7b35c1d40 18550->18551 18551->18467 18553 7ff7b35d2796 18552->18553 18554 7ff7b35d2786 18552->18554 18555 7ff7b35d279f 18553->18555 18564 7ff7b35d27cd 18553->18564 18556 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18554->18556 18557 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18555->18557 18558 7ff7b35d27c5 18556->18558 18557->18558 18558->18508 18558->18513 18558->18514 18558->18517 18559 7ff7b35d5210 45 API calls 18559->18564 18561 7ff7b35d2a7c 18563 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18561->18563 18563->18554 18564->18554 18564->18558 18564->18559 18564->18561 18566 7ff7b35d3b28 18564->18566 18592 7ff7b35d3208 18564->18592 18622 7ff7b35d22a0 18564->18622 18567 7ff7b35d3bdd 18566->18567 18568 7ff7b35d3b6a 18566->18568 18569 7ff7b35d3be2 18567->18569 18570 7ff7b35d3c37 18567->18570 18571 7ff7b35d3b70 18568->18571 18572 7ff7b35d3c07 18568->18572 18573 7ff7b35d3be4 18569->18573 18574 7ff7b35d3c17 18569->18574 18570->18572 18581 7ff7b35d3c46 18570->18581 18590 7ff7b35d3ba0 18570->18590 18579 7ff7b35d3b75 18571->18579 18571->18581 18639 7ff7b35d10c8 18572->18639 18575 7ff7b35d3b85 18573->18575 18580 7ff7b35d3bf3 18573->18580 18646 7ff7b35d0cb8 18574->18646 18591 7ff7b35d3c75 18575->18591 18625 7ff7b35d4950 18575->18625 18579->18575 18582 7ff7b35d3bb8 18579->18582 18579->18590 18580->18572 18584 7ff7b35d3bf8 18580->18584 18581->18591 18653 7ff7b35d14d8 18581->18653 18582->18591 18635 7ff7b35d4e0c 18582->18635 18587 7ff7b35d4fa4 37 API calls 18584->18587 18584->18591 18586 7ff7b35cbab0 _log10_special 8 API calls 18588 7ff7b35d3f0b 18586->18588 18587->18590 18588->18564 18590->18591 18660 7ff7b35df8c0 18590->18660 18591->18586 18593 7ff7b35d3213 18592->18593 18594 7ff7b35d3229 18592->18594 18595 7ff7b35d3267 18593->18595 18596 7ff7b35d3bdd 18593->18596 18597 7ff7b35d3b6a 18593->18597 18594->18595 18598 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18594->18598 18595->18564 18599 7ff7b35d3be2 18596->18599 18602 7ff7b35d3c37 18596->18602 18600 7ff7b35d3b70 18597->18600 18601 7ff7b35d3c07 18597->18601 18598->18595 18605 7ff7b35d3c17 18599->18605 18606 7ff7b35d3be4 18599->18606 18604 7ff7b35d3b75 18600->18604 18609 7ff7b35d3c46 18600->18609 18603 7ff7b35d10c8 38 API calls 18601->18603 18602->18601 18602->18609 18620 7ff7b35d3ba0 18602->18620 18603->18620 18611 7ff7b35d3b85 18604->18611 18612 7ff7b35d3bb8 18604->18612 18604->18620 18607 7ff7b35d0cb8 38 API calls 18605->18607 18610 7ff7b35d3bf3 18606->18610 18606->18611 18607->18620 18608 7ff7b35d4950 47 API calls 18608->18620 18613 7ff7b35d14d8 38 API calls 18609->18613 18621 7ff7b35d3c75 18609->18621 18610->18601 18614 7ff7b35d3bf8 18610->18614 18611->18608 18611->18621 18615 7ff7b35d4e0c 47 API calls 18612->18615 18612->18621 18613->18620 18617 7ff7b35d4fa4 37 API calls 18614->18617 18614->18621 18615->18620 18616 7ff7b35cbab0 _log10_special 8 API calls 18618 7ff7b35d3f0b 18616->18618 18617->18620 18618->18564 18619 7ff7b35df8c0 47 API calls 18619->18620 18620->18619 18620->18621 18621->18616 18673 7ff7b35d028c 18622->18673 18626 7ff7b35d4972 18625->18626 18627 7ff7b35d00f8 12 API calls 18626->18627 18628 7ff7b35d49ba 18627->18628 18629 7ff7b35df5d8 46 API calls 18628->18629 18630 7ff7b35d4a8d 18629->18630 18631 7ff7b35d5210 45 API calls 18630->18631 18632 7ff7b35d4aaf 18630->18632 18631->18632 18632->18632 18633 7ff7b35d5210 45 API calls 18632->18633 18634 7ff7b35d4b38 18632->18634 18633->18634 18634->18590 18636 7ff7b35d4e24 18635->18636 18638 7ff7b35d4e8c 18635->18638 18637 7ff7b35df8c0 47 API calls 18636->18637 18636->18638 18637->18638 18638->18590 18640 7ff7b35d10fb 18639->18640 18641 7ff7b35d112a 18640->18641 18643 7ff7b35d11e7 18640->18643 18642 7ff7b35d00f8 12 API calls 18641->18642 18645 7ff7b35d1167 18641->18645 18642->18645 18644 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18643->18644 18644->18645 18645->18590 18648 7ff7b35d0ceb 18646->18648 18647 7ff7b35d0d1a 18649 7ff7b35d00f8 12 API calls 18647->18649 18652 7ff7b35d0d57 18647->18652 18648->18647 18650 7ff7b35d0dd7 18648->18650 18649->18652 18651 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18650->18651 18651->18652 18652->18590 18654 7ff7b35d150b 18653->18654 18655 7ff7b35d153a 18654->18655 18657 7ff7b35d15f7 18654->18657 18656 7ff7b35d00f8 12 API calls 18655->18656 18659 7ff7b35d1577 18655->18659 18656->18659 18658 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18657->18658 18658->18659 18659->18590 18662 7ff7b35df8e8 18660->18662 18661 7ff7b35df92d 18665 7ff7b35df8ed memcpy_s 18661->18665 18669 7ff7b35df916 memcpy_s 18661->18669 18670 7ff7b35e19f8 18661->18670 18662->18661 18663 7ff7b35d5210 45 API calls 18662->18663 18662->18665 18662->18669 18663->18661 18664 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18664->18665 18665->18590 18669->18664 18669->18665 18671 7ff7b35e1a1c WideCharToMultiByte 18670->18671 18674 7ff7b35d02cb 18673->18674 18675 7ff7b35d02b9 18673->18675 18677 7ff7b35d0315 18674->18677 18679 7ff7b35d02d8 18674->18679 18676 7ff7b35d5de8 _get_daylight 11 API calls 18675->18676 18678 7ff7b35d02be 18676->18678 18682 7ff7b35d03be 18677->18682 18684 7ff7b35d5de8 _get_daylight 11 API calls 18677->18684 18680 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 18678->18680 18681 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18679->18681 18686 7ff7b35d02c9 18680->18686 18681->18686 18683 7ff7b35d5de8 _get_daylight 11 API calls 18682->18683 18682->18686 18685 7ff7b35d0468 18683->18685 18687 7ff7b35d03b3 18684->18687 18689 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 18685->18689 18686->18564 18688 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 18687->18688 18688->18682 18689->18686 18694 7ff7b35dfe49 18690->18694 18691 7ff7b35dfe4e 18692 7ff7b35d60bd 18691->18692 18693 7ff7b35d5de8 _get_daylight 11 API calls 18691->18693 18692->18522 18692->18529 18695 7ff7b35dfe58 18693->18695 18694->18691 18694->18692 18697 7ff7b35dfe98 18694->18697 18696 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 18695->18696 18696->18692 18697->18692 18698 7ff7b35d5de8 _get_daylight 11 API calls 18697->18698 18698->18695 18704 7ff7b35dff1c 18699->18704 18702 7ff7b35e02d5 InitializeCriticalSectionAndSpinCount 18703 7ff7b35e02bb 18702->18703 18703->18539 18705 7ff7b35dff79 18704->18705 18712 7ff7b35dff74 __vcrt_InitializeCriticalSectionEx 18704->18712 18705->18702 18705->18703 18706 7ff7b35dffa9 LoadLibraryExW 18708 7ff7b35e007e 18706->18708 18709 7ff7b35dffce GetLastError 18706->18709 18707 7ff7b35e009e GetProcAddress 18707->18705 18711 7ff7b35e00af 18707->18711 18708->18707 18710 7ff7b35e0095 FreeLibrary 18708->18710 18709->18712 18710->18707 18711->18705 18712->18705 18712->18706 18712->18707 18713 7ff7b35e0008 LoadLibraryExW 18712->18713 18713->18708 18713->18712 18715 7ff7b35c1dd6 18714->18715 18718 7ff7b35d561c 18715->18718 18717 7ff7b35c1dec 18717->18549 18719 7ff7b35d5646 18718->18719 18720 7ff7b35d567e 18719->18720 18722 7ff7b35d56b1 18719->18722 18721 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 18720->18721 18724 7ff7b35d56a7 18721->18724 18725 7ff7b35d00b8 18722->18725 18724->18717 18732 7ff7b35d627c EnterCriticalSection 18725->18732 18734 7ff7b35c7a01 GetTokenInformation 18733->18734 18735 7ff7b35c7a83 __vcrt_freefls 18733->18735 18736 7ff7b35c7a22 GetLastError 18734->18736 18739 7ff7b35c7a2d 18734->18739 18737 7ff7b35c7a96 CloseHandle 18735->18737 18738 7ff7b35c7a9c 18735->18738 18736->18735 18736->18739 18737->18738 18738->17802 18739->18735 18740 7ff7b35c7a49 GetTokenInformation 18739->18740 18740->18735 18741 7ff7b35c7a6c 18740->18741 18741->18735 18742 7ff7b35c7a76 ConvertSidToStringSidW 18741->18742 18742->18735 18744 7ff7b35cbdb0 18743->18744 18745 7ff7b35c2244 GetCurrentProcessId 18744->18745 18746 7ff7b35c1d50 48 API calls 18745->18746 18747 7ff7b35c2295 18746->18747 18748 7ff7b35d5ab8 48 API calls 18747->18748 18749 7ff7b35c22d3 18748->18749 18750 7ff7b35c1e00 78 API calls 18749->18750 18751 7ff7b35c22f1 18750->18751 18752 7ff7b35cbab0 _log10_special 8 API calls 18751->18752 18753 7ff7b35c2301 18752->18753 18753->17812 18755 7ff7b35c8725 18754->18755 18756 7ff7b35d5ab8 48 API calls 18755->18756 18757 7ff7b35c8744 18756->18757 18757->17821 18803 7ff7b35d9670 18758->18803 18762 7ff7b35c762c 18761->18762 18763 7ff7b35c88f0 2 API calls 18762->18763 18764 7ff7b35c764b 18763->18764 18765 7ff7b35c7666 ExpandEnvironmentStringsW 18764->18765 18766 7ff7b35c7653 18764->18766 18768 7ff7b35c768c __vcrt_freefls 18765->18768 18767 7ff7b35c1f30 78 API calls 18766->18767 18792 7ff7b35c765f __vcrt_freefls 18767->18792 18769 7ff7b35c7690 18768->18769 18770 7ff7b35c76a3 18768->18770 18772 7ff7b35c1f30 78 API calls 18769->18772 18774 7ff7b35c76b1 GetDriveTypeW 18770->18774 18775 7ff7b35c770f 18770->18775 18771 7ff7b35cbab0 _log10_special 8 API calls 18773 7ff7b35c77ff 18771->18773 18772->18792 18773->17827 18793 7ff7b35d9114 18773->18793 18778 7ff7b35c7700 18774->18778 18779 7ff7b35c76e5 18774->18779 18777 7ff7b35d8ce4 45 API calls 18775->18777 18780 7ff7b35c7721 18777->18780 18926 7ff7b35d8848 18778->18926 18782 7ff7b35c1f30 78 API calls 18779->18782 18781 7ff7b35c7729 18780->18781 18785 7ff7b35c773c 18780->18785 18784 7ff7b35c1f30 78 API calls 18781->18784 18782->18792 18784->18792 18786 7ff7b35c779e CreateDirectoryW 18785->18786 18787 7ff7b35c1d50 48 API calls 18785->18787 18788 7ff7b35c77ad GetLastError 18786->18788 18786->18792 18789 7ff7b35c7778 CreateDirectoryW 18787->18789 18790 7ff7b35c77ba GetLastError 18788->18790 18788->18792 18789->18785 18791 7ff7b35c2310 80 API calls 18790->18791 18791->18792 18792->18771 18794 7ff7b35d9134 18793->18794 18795 7ff7b35d9121 18793->18795 18933 7ff7b35d8d98 18794->18933 18796 7ff7b35d5de8 _get_daylight 11 API calls 18795->18796 18798 7ff7b35d9126 18796->18798 18799 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 18798->18799 18800 7ff7b35d9132 18799->18800 18844 7ff7b35e2768 18803->18844 18903 7ff7b35e24e0 18844->18903 18924 7ff7b35e14e8 EnterCriticalSection 18903->18924 18927 7ff7b35d8866 18926->18927 18930 7ff7b35d8899 18926->18930 18928 7ff7b35e1684 37 API calls 18927->18928 18927->18930 18929 7ff7b35d8895 18928->18929 18929->18930 18931 7ff7b35db7e4 _isindst 17 API calls 18929->18931 18930->18792 18932 7ff7b35d88c9 18931->18932 18940 7ff7b35e14e8 EnterCriticalSection 18933->18940 18942 7ff7b35c398a 18941->18942 18943 7ff7b35c88f0 2 API calls 18942->18943 18944 7ff7b35c39af 18943->18944 18945 7ff7b35cbab0 _log10_special 8 API calls 18944->18945 18946 7ff7b35c39d7 18945->18946 18946->17864 18949 7ff7b35c727e 18947->18949 18948 7ff7b35c73a2 18951 7ff7b35cbab0 _log10_special 8 API calls 18948->18951 18949->18948 18950 7ff7b35c1c60 49 API calls 18949->18950 18955 7ff7b35c7305 18950->18955 18952 7ff7b35c73d3 18951->18952 18952->17864 18953 7ff7b35c1c60 49 API calls 18953->18955 18954 7ff7b35c3980 10 API calls 18954->18955 18955->18948 18955->18953 18955->18954 18956 7ff7b35c88f0 2 API calls 18955->18956 18957 7ff7b35c7373 CreateDirectoryW 18956->18957 18957->18948 18957->18955 18959 7ff7b35c15f3 18958->18959 18960 7ff7b35c1617 18958->18960 19079 7ff7b35c1030 18959->19079 18961 7ff7b35c39e0 108 API calls 18960->18961 18963 7ff7b35c162b 18961->18963 18965 7ff7b35c1662 18963->18965 18966 7ff7b35c1633 18963->18966 18964 7ff7b35c15f8 18967 7ff7b35c160e 18964->18967 18970 7ff7b35c1e50 81 API calls 18964->18970 18969 7ff7b35c39e0 108 API calls 18965->18969 18968 7ff7b35d5de8 _get_daylight 11 API calls 18966->18968 18967->17864 18971 7ff7b35c1638 18968->18971 18972 7ff7b35c1676 18969->18972 18970->18967 18973 7ff7b35c2020 87 API calls 18971->18973 18974 7ff7b35c1698 18972->18974 18975 7ff7b35c167e 18972->18975 18977 7ff7b35c1651 18973->18977 18976 7ff7b35cfbcc 73 API calls 18974->18976 18978 7ff7b35c1e50 81 API calls 18975->18978 18979 7ff7b35c16ad 18976->18979 18977->17864 18980 7ff7b35c168e 18978->18980 18981 7ff7b35c16b1 18979->18981 18982 7ff7b35c16d9 18979->18982 18986 7ff7b35cf544 74 API calls 18980->18986 18983 7ff7b35d5de8 _get_daylight 11 API calls 18981->18983 18984 7ff7b35c16df 18982->18984 18985 7ff7b35c16f7 18982->18985 18987 7ff7b35c16b6 18983->18987 19057 7ff7b35c11f0 18984->19057 18991 7ff7b35c1719 18985->18991 19002 7ff7b35c1741 18985->19002 18989 7ff7b35c1809 18986->18989 18990 7ff7b35c2020 87 API calls 18987->18990 18989->17864 18997 7ff7b35c16cf __vcrt_freefls 18990->18997 18993 7ff7b35d5de8 _get_daylight 11 API calls 18991->18993 18992 7ff7b35cf544 74 API calls 18992->18980 18994 7ff7b35c171e 18993->18994 18995 7ff7b35c2020 87 API calls 18994->18995 18995->18997 18996 7ff7b35cf894 _fread_nolock 53 API calls 18996->19002 18997->18992 18998 7ff7b35c17ba 18999 7ff7b35d5de8 _get_daylight 11 API calls 18998->18999 19001 7ff7b35c17aa 18999->19001 19004 7ff7b35c2020 87 API calls 19001->19004 19002->18996 19002->18997 19002->18998 19003 7ff7b35c17a5 19002->19003 19110 7ff7b35cffd4 19002->19110 19005 7ff7b35d5de8 _get_daylight 11 API calls 19003->19005 19004->18997 19005->19001 19007 7ff7b35c65db 19006->19007 19009 7ff7b35c6594 19006->19009 19007->17864 19009->19007 19143 7ff7b35d5f04 19009->19143 19011 7ff7b35c35c1 19010->19011 19012 7ff7b35c3900 49 API calls 19011->19012 19013 7ff7b35c35fb 19012->19013 19014 7ff7b35c3900 49 API calls 19013->19014 19015 7ff7b35c360b 19014->19015 19016 7ff7b35c362d 19015->19016 19017 7ff7b35c365c 19015->19017 19158 7ff7b35c3530 19016->19158 19019 7ff7b35c3530 51 API calls 19017->19019 19020 7ff7b35c365a 19019->19020 19021 7ff7b35c3687 19020->19021 19022 7ff7b35c36bc 19020->19022 19165 7ff7b35c7140 19021->19165 19024 7ff7b35c3530 51 API calls 19022->19024 19026 7ff7b35c36e0 19024->19026 19028 7ff7b35c3530 51 API calls 19026->19028 19040 7ff7b35c3732 19026->19040 19027 7ff7b35c36b7 19033 7ff7b35cbab0 _log10_special 8 API calls 19027->19033 19031 7ff7b35c3709 19028->19031 19029 7ff7b35c37b3 19032 7ff7b35c1930 115 API calls 19029->19032 19030 7ff7b35c1e50 81 API calls 19030->19027 19036 7ff7b35c3530 51 API calls 19031->19036 19031->19040 19034 7ff7b35c37bd 19032->19034 19035 7ff7b35c3855 19033->19035 19037 7ff7b35c381e 19034->19037 19039 7ff7b35c37c5 19034->19039 19035->17864 19036->19040 19038 7ff7b35c1e50 81 API calls 19037->19038 19042 7ff7b35c3737 19038->19042 19191 7ff7b35c1820 19039->19191 19040->19029 19041 7ff7b35c37ac 19040->19041 19040->19042 19045 7ff7b35c379b 19040->19045 19041->19039 19041->19042 19046 7ff7b35c1e50 81 API calls 19042->19046 19049 7ff7b35c1e50 81 API calls 19045->19049 19046->19027 19049->19042 19055 7ff7b35c1c60 49 API calls 19054->19055 19056 7ff7b35c3894 19055->19056 19056->17864 19058 7ff7b35c1248 19057->19058 19059 7ff7b35c124f 19058->19059 19060 7ff7b35c1277 19058->19060 19061 7ff7b35c1e50 81 API calls 19059->19061 19063 7ff7b35c1291 19060->19063 19064 7ff7b35c12b4 19060->19064 19062 7ff7b35c1262 19061->19062 19062->18997 19065 7ff7b35d5de8 _get_daylight 11 API calls 19063->19065 19067 7ff7b35c12c6 19064->19067 19068 7ff7b35c12e9 memcpy_s 19064->19068 19080 7ff7b35c39e0 108 API calls 19079->19080 19081 7ff7b35c106c 19080->19081 19082 7ff7b35c1074 19081->19082 19083 7ff7b35c1089 19081->19083 19084 7ff7b35c1e50 81 API calls 19082->19084 19085 7ff7b35cfbcc 73 API calls 19083->19085 19091 7ff7b35c1084 __vcrt_freefls 19084->19091 19086 7ff7b35c109f 19085->19086 19087 7ff7b35c10c6 19086->19087 19088 7ff7b35c10a3 19086->19088 19092 7ff7b35c1102 19087->19092 19093 7ff7b35c10d7 19087->19093 19089 7ff7b35d5de8 _get_daylight 11 API calls 19088->19089 19090 7ff7b35c10a8 19089->19090 19094 7ff7b35c2020 87 API calls 19090->19094 19091->18964 19096 7ff7b35c1109 19092->19096 19104 7ff7b35c111c 19092->19104 19095 7ff7b35d5de8 _get_daylight 11 API calls 19093->19095 19101 7ff7b35c10c1 __vcrt_freefls 19094->19101 19097 7ff7b35c10e0 19095->19097 19098 7ff7b35c11f0 96 API calls 19096->19098 19099 7ff7b35c2020 87 API calls 19097->19099 19098->19101 19099->19101 19100 7ff7b35cf544 74 API calls 19102 7ff7b35c1194 19100->19102 19101->19100 19102->19091 19114 7ff7b35c3b10 19102->19114 19103 7ff7b35cf894 _fread_nolock 53 API calls 19103->19104 19104->19101 19104->19103 19106 7ff7b35c11cd 19104->19106 19107 7ff7b35d5de8 _get_daylight 11 API calls 19106->19107 19108 7ff7b35c11d2 19107->19108 19109 7ff7b35c2020 87 API calls 19108->19109 19109->19101 19111 7ff7b35d0004 19110->19111 19128 7ff7b35cfd24 19111->19128 19115 7ff7b35c3b20 19114->19115 19116 7ff7b35c88f0 2 API calls 19115->19116 19117 7ff7b35c3b4b 19116->19117 19129 7ff7b35cfd44 19128->19129 19134 7ff7b35cfd71 19128->19134 19129->19134 19144 7ff7b35d5f11 19143->19144 19145 7ff7b35d5f3e 19143->19145 19146 7ff7b35d5de8 _get_daylight 11 API calls 19144->19146 19152 7ff7b35d5ec8 19144->19152 19147 7ff7b35d5f61 19145->19147 19150 7ff7b35d5f7d 19145->19150 19148 7ff7b35d5f1b 19146->19148 19149 7ff7b35d5de8 _get_daylight 11 API calls 19147->19149 19151 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 19148->19151 19153 7ff7b35d5f66 19149->19153 19154 7ff7b35d5e2c 45 API calls 19150->19154 19155 7ff7b35d5f26 19151->19155 19152->19009 19156 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 19153->19156 19157 7ff7b35d5f71 19154->19157 19155->19009 19156->19157 19157->19009 19159 7ff7b35c3556 19158->19159 19160 7ff7b35d5864 49 API calls 19159->19160 19161 7ff7b35c357c 19160->19161 19162 7ff7b35c358d 19161->19162 19163 7ff7b35c3980 10 API calls 19161->19163 19162->19020 19164 7ff7b35c359f 19163->19164 19164->19020 19166 7ff7b35c7155 19165->19166 19167 7ff7b35c39e0 108 API calls 19166->19167 19168 7ff7b35c717b 19167->19168 19169 7ff7b35c71a2 19168->19169 19170 7ff7b35c39e0 108 API calls 19168->19170 19172 7ff7b35cbab0 _log10_special 8 API calls 19169->19172 19171 7ff7b35c7192 19170->19171 19173 7ff7b35c719d 19171->19173 19174 7ff7b35c71ac 19171->19174 19175 7ff7b35c3697 19172->19175 19176 7ff7b35cf544 74 API calls 19173->19176 19195 7ff7b35cf5dc 19174->19195 19175->19027 19175->19030 19176->19169 19193 7ff7b35c18b5 19191->19193 19194 7ff7b35c1845 19191->19194 19194->19193 19222 7ff7b35d6e28 19221->19222 19223 7ff7b35d6e4e 19222->19223 19225 7ff7b35d6e81 19222->19225 19224 7ff7b35d5de8 _get_daylight 11 API calls 19223->19224 19226 7ff7b35d6e53 19224->19226 19227 7ff7b35d6e94 19225->19227 19228 7ff7b35d6e87 19225->19228 19229 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 19226->19229 19240 7ff7b35dbad0 19227->19240 19230 7ff7b35d5de8 _get_daylight 11 API calls 19228->19230 19232 7ff7b35c3a36 19229->19232 19230->19232 19232->17890 19253 7ff7b35e14e8 EnterCriticalSection 19240->19253 19613 7ff7b35d87d4 19612->19613 19616 7ff7b35d82b0 19613->19616 19615 7ff7b35d87ed 19615->17900 19617 7ff7b35d82cb 19616->19617 19618 7ff7b35d82fa 19616->19618 19619 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 19617->19619 19626 7ff7b35d627c EnterCriticalSection 19618->19626 19621 7ff7b35d82eb 19619->19621 19621->19615 19628 7ff7b35cf33b 19627->19628 19629 7ff7b35cf369 19627->19629 19630 7ff7b35db6f8 _invalid_parameter_noinfo 37 API calls 19628->19630 19636 7ff7b35cf35b 19629->19636 19637 7ff7b35d627c EnterCriticalSection 19629->19637 19630->19636 19636->17904 19639 7ff7b35c39e0 108 API calls 19638->19639 19640 7ff7b35c1473 19639->19640 19641 7ff7b35c149c 19640->19641 19642 7ff7b35c147b 19640->19642 19644 7ff7b35cfbcc 73 API calls 19641->19644 19643 7ff7b35c1e50 81 API calls 19642->19643 19645 7ff7b35c148b 19643->19645 19646 7ff7b35c14b1 19644->19646 19645->17947 19647 7ff7b35c14b5 19646->19647 19648 7ff7b35c14d8 19646->19648 19649 7ff7b35d5de8 _get_daylight 11 API calls 19647->19649 19651 7ff7b35c1512 19648->19651 19652 7ff7b35c14e8 19648->19652 19650 7ff7b35c14ba 19649->19650 19653 7ff7b35c2020 87 API calls 19650->19653 19655 7ff7b35c1518 19651->19655 19663 7ff7b35c152b 19651->19663 19654 7ff7b35d5de8 _get_daylight 11 API calls 19652->19654 19660 7ff7b35c14d3 __vcrt_freefls 19653->19660 19656 7ff7b35c14f0 19654->19656 19657 7ff7b35c11f0 96 API calls 19655->19657 19658 7ff7b35c2020 87 API calls 19656->19658 19657->19660 19658->19660 19659 7ff7b35cf544 74 API calls 19661 7ff7b35c15a4 19659->19661 19660->19659 19661->17947 19662 7ff7b35cf894 _fread_nolock 53 API calls 19662->19663 19663->19660 19663->19662 19664 7ff7b35c15b6 19663->19664 19665 7ff7b35d5de8 _get_daylight 11 API calls 19664->19665 19666 7ff7b35c15bb 19665->19666 19667 7ff7b35c2020 87 API calls 19666->19667 19667->19660 19669 7ff7b35c88f0 2 API calls 19668->19669 19670 7ff7b35c82e4 LoadLibraryExW 19669->19670 19745 7ff7b35c57c5 19744->19745 19746 7ff7b35c1c60 49 API calls 19745->19746 19747 7ff7b35c5801 19746->19747 19748 7ff7b35c580a 19747->19748 19749 7ff7b35c582d 19747->19749 19750 7ff7b35c1e50 81 API calls 19748->19750 19751 7ff7b35c3a50 49 API calls 19749->19751 19774 7ff7b35c5823 19750->19774 19752 7ff7b35c5845 19751->19752 19753 7ff7b35c5863 19752->19753 19755 7ff7b35c1e50 81 API calls 19752->19755 19756 7ff7b35c3980 10 API calls 19753->19756 19754 7ff7b35cbab0 _log10_special 8 API calls 19757 7ff7b35c272e 19754->19757 19755->19753 19758 7ff7b35c586d 19756->19758 19757->18016 19775 7ff7b35c5950 19757->19775 19759 7ff7b35c587b 19758->19759 19760 7ff7b35c82d0 3 API calls 19758->19760 19761 7ff7b35c3a50 49 API calls 19759->19761 19760->19759 19762 7ff7b35c5894 19761->19762 19763 7ff7b35c58b9 19762->19763 19764 7ff7b35c5899 19762->19764 19766 7ff7b35c82d0 3 API calls 19763->19766 19765 7ff7b35c1e50 81 API calls 19764->19765 19765->19774 19767 7ff7b35c58c6 19766->19767 19774->19754 19924 7ff7b35c4820 19775->19924 19777 7ff7b35c5976 19778 7ff7b35c598f 19777->19778 19779 7ff7b35c597e 19777->19779 19931 7ff7b35c40b0 19778->19931 19781 7ff7b35c1e50 81 API calls 19779->19781 19786 7ff7b35c598a 19781->19786 19925 7ff7b35c484c 19924->19925 19926 7ff7b35c4854 19925->19926 19929 7ff7b35c49f4 19925->19929 19955 7ff7b35d7a04 19925->19955 19926->19777 19927 7ff7b35c4bb7 __vcrt_freefls 19927->19777 19928 7ff7b35c3bf0 47 API calls 19928->19929 19929->19927 19929->19928 19932 7ff7b35c40e0 19931->19932 19956 7ff7b35d7a34 19955->19956 19959 7ff7b35d6f00 19956->19959 19960 7ff7b35d6f43 19959->19960 19961 7ff7b35d6f31 19959->19961 20032->18024 20034 7ff7b35dbff0 _CreateFrameInfo 45 API calls 20033->20034 20035 7ff7b35db301 20034->20035 20036 7ff7b35db3ac _CreateFrameInfo 45 API calls 20035->20036 20037 7ff7b35db321 20036->20037 21578 7ff7b35cc0b0 21579 7ff7b35cc0c0 21578->21579 21595 7ff7b35daa80 21579->21595 21581 7ff7b35cc0cc 21601 7ff7b35cc3b8 21581->21601 21583 7ff7b35cc69c 7 API calls 21585 7ff7b35cc165 21583->21585 21584 7ff7b35cc0e4 _RTC_Initialize 21593 7ff7b35cc139 21584->21593 21606 7ff7b35cc568 21584->21606 21587 7ff7b35cc0f9 21609 7ff7b35d9ef0 21587->21609 21593->21583 21594 7ff7b35cc155 21593->21594 21596 7ff7b35daa91 21595->21596 21597 7ff7b35daa99 21596->21597 21598 7ff7b35d5de8 _get_daylight 11 API calls 21596->21598 21597->21581 21599 7ff7b35daaa8 21598->21599 21600 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 21599->21600 21600->21597 21602 7ff7b35cc3c9 21601->21602 21605 7ff7b35cc3ce __scrt_release_startup_lock 21601->21605 21603 7ff7b35cc69c 7 API calls 21602->21603 21602->21605 21604 7ff7b35cc442 21603->21604 21605->21584 21634 7ff7b35cc52c 21606->21634 21608 7ff7b35cc571 21608->21587 21610 7ff7b35d9f10 21609->21610 21611 7ff7b35cc105 21609->21611 21612 7ff7b35d9f2e GetModuleFileNameW 21610->21612 21613 7ff7b35d9f18 21610->21613 21611->21593 21633 7ff7b35cc63c InitializeSListHead 21611->21633 21617 7ff7b35d9f59 21612->21617 21614 7ff7b35d5de8 _get_daylight 11 API calls 21613->21614 21615 7ff7b35d9f1d 21614->21615 21616 7ff7b35db7c4 _invalid_parameter_noinfo 37 API calls 21615->21616 21616->21611 21618 7ff7b35d9e90 11 API calls 21617->21618 21619 7ff7b35d9f99 21618->21619 21620 7ff7b35d9fa1 21619->21620 21624 7ff7b35d9fb9 21619->21624 21621 7ff7b35d5de8 _get_daylight 11 API calls 21620->21621 21622 7ff7b35d9fa6 21621->21622 21623 7ff7b35db404 __free_lconv_num 11 API calls 21622->21623 21623->21611 21625 7ff7b35d9fdb 21624->21625 21627 7ff7b35da020 21624->21627 21628 7ff7b35da007 21624->21628 21626 7ff7b35db404 __free_lconv_num 11 API calls 21625->21626 21626->21611 21631 7ff7b35db404 __free_lconv_num 11 API calls 21627->21631 21629 7ff7b35db404 __free_lconv_num 11 API calls 21628->21629 21630 7ff7b35da010 21629->21630 21632 7ff7b35db404 __free_lconv_num 11 API calls 21630->21632 21631->21625 21632->21611 21635 7ff7b35cc546 21634->21635 21637 7ff7b35cc53f 21634->21637 21638 7ff7b35db10c 21635->21638 21637->21608 21641 7ff7b35dad48 21638->21641 21648 7ff7b35e14e8 EnterCriticalSection 21641->21648 20473 7ff7b35e8e30 20476 7ff7b35e3800 20473->20476 20477 7ff7b35e380d 20476->20477 20478 7ff7b35e3852 20476->20478 20482 7ff7b35dc0c4 20477->20482 20483 7ff7b35dc0d5 FlsGetValue 20482->20483 20484 7ff7b35dc0f0 FlsSetValue 20482->20484 20485 7ff7b35dc0e2 20483->20485 20486 7ff7b35dc0ea 20483->20486 20484->20485 20487 7ff7b35dc0fd 20484->20487 20488 7ff7b35db3ac _CreateFrameInfo 45 API calls 20485->20488 20490 7ff7b35dc0e8 20485->20490 20486->20484 20489 7ff7b35dfda4 _get_daylight 11 API calls 20487->20489 20491 7ff7b35dc165 20488->20491 20492 7ff7b35dc10c 20489->20492 20502 7ff7b35e34d4 20490->20502 20493 7ff7b35dc12a FlsSetValue 20492->20493 20494 7ff7b35dc11a FlsSetValue 20492->20494 20495 7ff7b35dc136 FlsSetValue 20493->20495 20496 7ff7b35dc148 20493->20496 20497 7ff7b35dc123 20494->20497 20495->20497 20499 7ff7b35dbd9c _get_daylight 11 API calls 20496->20499 20498 7ff7b35db404 __free_lconv_num 11 API calls 20497->20498 20498->20485 20500 7ff7b35dc150 20499->20500 20501 7ff7b35db404 __free_lconv_num 11 API calls 20500->20501 20501->20490 20525 7ff7b35e3744 20502->20525 20504 7ff7b35e3509 20540 7ff7b35e31d4 20504->20540 20507 7ff7b35de664 _fread_nolock 12 API calls 20508 7ff7b35e3537 20507->20508 20509 7ff7b35e353f 20508->20509 20511 7ff7b35e354e 20508->20511 20510 7ff7b35db404 __free_lconv_num 11 API calls 20509->20510 20524 7ff7b35e3526 20510->20524 20511->20511 20547 7ff7b35e387c 20511->20547 20514 7ff7b35e364a 20515 7ff7b35d5de8 _get_daylight 11 API calls 20514->20515 20516 7ff7b35e364f 20515->20516 20520 7ff7b35db404 __free_lconv_num 11 API calls 20516->20520 20517 7ff7b35e3664 20519 7ff7b35e36a5 20517->20519 20521 7ff7b35db404 __free_lconv_num 11 API calls 20517->20521 20518 7ff7b35e370c 20523 7ff7b35db404 __free_lconv_num 11 API calls 20518->20523 20519->20518 20558 7ff7b35e3004 20519->20558 20520->20524 20521->20519 20523->20524 20524->20478 20526 7ff7b35e3767 20525->20526 20527 7ff7b35e3771 20526->20527 20573 7ff7b35e14e8 EnterCriticalSection 20526->20573 20529 7ff7b35e37e3 20527->20529 20531 7ff7b35db3ac _CreateFrameInfo 45 API calls 20527->20531 20529->20504 20534 7ff7b35e37fb 20531->20534 20535 7ff7b35e3852 20534->20535 20537 7ff7b35dc0c4 50 API calls 20534->20537 20535->20504 20538 7ff7b35e383c 20537->20538 20539 7ff7b35e34d4 65 API calls 20538->20539 20539->20535 20541 7ff7b35d5e2c 45 API calls 20540->20541 20542 7ff7b35e31e8 20541->20542 20543 7ff7b35e31f4 GetOEMCP 20542->20543 20544 7ff7b35e3206 20542->20544 20545 7ff7b35e321b 20543->20545 20544->20545 20546 7ff7b35e320b GetACP 20544->20546 20545->20507 20545->20524 20546->20545 20548 7ff7b35e31d4 47 API calls 20547->20548 20549 7ff7b35e38a9 20548->20549 20550 7ff7b35e39ff 20549->20550 20552 7ff7b35e38e6 IsValidCodePage 20549->20552 20557 7ff7b35e3900 memcpy_s 20549->20557 20551 7ff7b35cbab0 _log10_special 8 API calls 20550->20551 20553 7ff7b35e3641 20551->20553 20552->20550 20554 7ff7b35e38f7 20552->20554 20553->20514 20553->20517 20555 7ff7b35e3926 GetCPInfo 20554->20555 20554->20557 20555->20550 20555->20557 20574 7ff7b35e32ec 20557->20574 20630 7ff7b35e14e8 EnterCriticalSection 20558->20630 20575 7ff7b35e3329 GetCPInfo 20574->20575 20584 7ff7b35e341f 20574->20584 20581 7ff7b35e333c 20575->20581 20575->20584 20576 7ff7b35cbab0 _log10_special 8 API calls 20578 7ff7b35e34be 20576->20578 20577 7ff7b35e4050 48 API calls 20579 7ff7b35e33b3 20577->20579 20578->20550 20585 7ff7b35e8d94 20579->20585 20581->20577 20583 7ff7b35e8d94 54 API calls 20583->20584 20584->20576 20586 7ff7b35d5e2c 45 API calls 20585->20586 20587 7ff7b35e8db9 20586->20587 20590 7ff7b35e8a60 20587->20590 20591 7ff7b35e8aa1 20590->20591 20592 7ff7b35e0ab0 _fread_nolock MultiByteToWideChar 20591->20592 20595 7ff7b35e8aeb 20592->20595 20593 7ff7b35e8d69 20594 7ff7b35cbab0 _log10_special 8 API calls 20593->20594 20596 7ff7b35e33e6 20594->20596 20595->20593 20597 7ff7b35de664 _fread_nolock 12 API calls 20595->20597 20599 7ff7b35e8b23 20595->20599 20610 7ff7b35e8c21 20595->20610 20596->20583 20597->20599 20598 7ff7b35db404 __free_lconv_num 11 API calls 20598->20593 20600 7ff7b35e0ab0 _fread_nolock MultiByteToWideChar 20599->20600 20599->20610 20601 7ff7b35e8b96 20600->20601 20601->20610 20621 7ff7b35e02f0 20601->20621 20604 7ff7b35e8be1 20607 7ff7b35e02f0 __crtLCMapStringW 6 API calls 20604->20607 20604->20610 20605 7ff7b35e8c32 20606 7ff7b35de664 _fread_nolock 12 API calls 20605->20606 20608 7ff7b35e8d04 20605->20608 20609 7ff7b35e8c50 20605->20609 20606->20609 20607->20610 20608->20610 20611 7ff7b35db404 __free_lconv_num 11 API calls 20608->20611 20609->20610 20612 7ff7b35e02f0 __crtLCMapStringW 6 API calls 20609->20612 20610->20593 20610->20598 20611->20610 20613 7ff7b35e8cd0 20612->20613 20613->20608 20614 7ff7b35e8d06 20613->20614 20615 7ff7b35e8cf0 20613->20615 20617 7ff7b35e19f8 WideCharToMultiByte 20614->20617 20616 7ff7b35e19f8 WideCharToMultiByte 20615->20616 20618 7ff7b35e8cfe 20616->20618 20617->20618 20618->20608 20619 7ff7b35e8d1e 20618->20619 20619->20610 20620 7ff7b35db404 __free_lconv_num 11 API calls 20619->20620 20620->20610 20622 7ff7b35dff1c __crtLCMapStringW 5 API calls 20621->20622 20623 7ff7b35e032e 20622->20623 20624 7ff7b35e0336 20623->20624 20627 7ff7b35e03dc 20623->20627 20624->20604 20624->20605 20624->20610 20626 7ff7b35e039f LCMapStringW 20626->20624 20628 7ff7b35dff1c __crtLCMapStringW 5 API calls 20627->20628 20629 7ff7b35e040a __crtLCMapStringW 20628->20629 20629->20626

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              • Executed
                                                                                                                                                                                                              • Not Executed
                                                                                                                                                                                                              control_flow_graph 0 7ff7b35c7e30-7ff7b35c7f76 call 7ff7b35cbdb0 call 7ff7b35c88f0 SetConsoleCtrlHandler GetStartupInfoW call 7ff7b35d6200 call 7ff7b35db324 call 7ff7b35d95f8 call 7ff7b35d6200 call 7ff7b35db324 call 7ff7b35d95f8 call 7ff7b35d6200 call 7ff7b35db324 call 7ff7b35d95f8 GetCommandLineW CreateProcessW 23 7ff7b35c7f78-7ff7b35c7f98 GetLastError call 7ff7b35c2310 0->23 24 7ff7b35c7f9d-7ff7b35c7fd9 RegisterClassW 0->24 31 7ff7b35c8289-7ff7b35c82af call 7ff7b35cbab0 23->31 26 7ff7b35c7fe1-7ff7b35c8035 CreateWindowExW 24->26 27 7ff7b35c7fdb GetLastError 24->27 29 7ff7b35c803f-7ff7b35c8044 ShowWindow 26->29 30 7ff7b35c8037-7ff7b35c803d GetLastError 26->30 27->26 32 7ff7b35c804a-7ff7b35c805a WaitForSingleObject 29->32 30->32 34 7ff7b35c80d8-7ff7b35c80df 32->34 35 7ff7b35c805c 32->35 36 7ff7b35c80e1-7ff7b35c80f1 WaitForSingleObject 34->36 37 7ff7b35c8122-7ff7b35c8129 34->37 39 7ff7b35c8060-7ff7b35c8063 35->39 40 7ff7b35c80f7-7ff7b35c8107 TerminateProcess 36->40 41 7ff7b35c8248-7ff7b35c8252 36->41 42 7ff7b35c812f-7ff7b35c8145 QueryPerformanceFrequency QueryPerformanceCounter 37->42 43 7ff7b35c8210-7ff7b35c8229 GetMessageW 37->43 44 7ff7b35c8065 GetLastError 39->44 45 7ff7b35c806b-7ff7b35c8072 39->45 50 7ff7b35c810f-7ff7b35c811d WaitForSingleObject 40->50 51 7ff7b35c8109 GetLastError 40->51 48 7ff7b35c8254-7ff7b35c825a DestroyWindow 41->48 49 7ff7b35c8261-7ff7b35c8285 GetExitCodeProcess CloseHandle * 2 41->49 52 7ff7b35c8150-7ff7b35c8188 MsgWaitForMultipleObjects PeekMessageW 42->52 46 7ff7b35c823f-7ff7b35c8246 43->46 47 7ff7b35c822b-7ff7b35c8239 TranslateMessage DispatchMessageW 43->47 44->45 45->36 53 7ff7b35c8074-7ff7b35c8091 PeekMessageW 45->53 46->41 46->43 47->46 48->49 49->31 50->41 51->50 56 7ff7b35c81c3-7ff7b35c81ca 52->56 57 7ff7b35c818a 52->57 54 7ff7b35c80c6-7ff7b35c80d6 WaitForSingleObject 53->54 55 7ff7b35c8093-7ff7b35c80c4 TranslateMessage DispatchMessageW PeekMessageW 53->55 54->34 54->39 55->54 55->55 56->43 59 7ff7b35c81cc-7ff7b35c81f5 QueryPerformanceCounter 56->59 58 7ff7b35c8190-7ff7b35c81c1 TranslateMessage DispatchMessageW PeekMessageW 57->58 58->56 58->58 59->52 60 7ff7b35c81fb-7ff7b35c8202 59->60 60->41 61 7ff7b35c8204-7ff7b35c8208 60->61 61->43
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ErrorLastMessage$ObjectProcessSingleWait$CloseCreateHandlePeekWindow_invalid_parameter_noinfo$ByteCharClassCodeCommandConsoleCtrlCurrentDestroyDispatchExitFormatHandlerInfoLineMultiRegisterStartupTerminateTranslateWide
                                                                                                                                                                                                              • String ID: CreateProcessW$Failed to create child process!$PyInstaller Onefile Hidden Window$PyInstallerOnefileHiddenWindow
                                                                                                                                                                                                              • API String ID: 4208240515-3165540532
                                                                                                                                                                                                              • Opcode ID: 6cf3c8642f53b43b1e9fef10f104943b82e9411ccff8eb65c880d58da3f350d3
                                                                                                                                                                                                              • Instruction ID: a8f797e64596bb3aad519b08308c9fdf61d8613350d412f5b48aa8d65c233033
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 6cf3c8642f53b43b1e9fef10f104943b82e9411ccff8eb65c880d58da3f350d3
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 3CD18871A0CB9295E790AF38E8542ADB7A0FF56758FC00235DB5D66A98DF3CD188C720

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              • Executed
                                                                                                                                                                                                              • Not Executed
                                                                                                                                                                                                              control_flow_graph 507 7ff7b35e6e10-7ff7b35e6e4b call 7ff7b35e6798 call 7ff7b35e67a0 call 7ff7b35e6808 514 7ff7b35e7075-7ff7b35e70c1 call 7ff7b35db7e4 call 7ff7b35e6798 call 7ff7b35e67a0 call 7ff7b35e6808 507->514 515 7ff7b35e6e51-7ff7b35e6e5c call 7ff7b35e67a8 507->515 542 7ff7b35e71ff-7ff7b35e726d call 7ff7b35db7e4 call 7ff7b35e2788 514->542 543 7ff7b35e70c7-7ff7b35e70d2 call 7ff7b35e67a8 514->543 515->514 520 7ff7b35e6e62-7ff7b35e6e6c 515->520 522 7ff7b35e6e8e-7ff7b35e6e92 520->522 523 7ff7b35e6e6e-7ff7b35e6e71 520->523 526 7ff7b35e6e95-7ff7b35e6e9d 522->526 525 7ff7b35e6e74-7ff7b35e6e7f 523->525 528 7ff7b35e6e81-7ff7b35e6e88 525->528 529 7ff7b35e6e8a-7ff7b35e6e8c 525->529 526->526 530 7ff7b35e6e9f-7ff7b35e6eb2 call 7ff7b35de664 526->530 528->525 528->529 529->522 532 7ff7b35e6ebb-7ff7b35e6ec9 529->532 537 7ff7b35e6eb4-7ff7b35e6eb6 call 7ff7b35db404 530->537 538 7ff7b35e6eca-7ff7b35e6ed6 call 7ff7b35db404 530->538 537->532 548 7ff7b35e6edd-7ff7b35e6ee5 538->548 560 7ff7b35e726f-7ff7b35e7276 542->560 561 7ff7b35e727b-7ff7b35e727e 542->561 543->542 552 7ff7b35e70d8-7ff7b35e70e3 call 7ff7b35e67d8 543->552 548->548 551 7ff7b35e6ee7-7ff7b35e6ef8 call 7ff7b35e1684 548->551 551->514 562 7ff7b35e6efe-7ff7b35e6f54 call 7ff7b35eb6e0 * 4 call 7ff7b35e6d2c 551->562 552->542 559 7ff7b35e70e9-7ff7b35e710c call 7ff7b35db404 GetTimeZoneInformation 552->559 576 7ff7b35e71d4-7ff7b35e71fe call 7ff7b35e6790 call 7ff7b35e6780 call 7ff7b35e6788 559->576 577 7ff7b35e7112-7ff7b35e7133 559->577 564 7ff7b35e730b-7ff7b35e730e 560->564 565 7ff7b35e72b5-7ff7b35e72c8 call 7ff7b35de664 561->565 566 7ff7b35e7280 561->566 619 7ff7b35e6f56-7ff7b35e6f5a 562->619 571 7ff7b35e7283 call 7ff7b35e708c 564->571 572 7ff7b35e7314-7ff7b35e731c call 7ff7b35e6e10 564->572 581 7ff7b35e72d3-7ff7b35e72ee call 7ff7b35e2788 565->581 582 7ff7b35e72ca 565->582 566->571 586 7ff7b35e7288-7ff7b35e72b4 call 7ff7b35db404 call 7ff7b35cbab0 571->586 572->586 583 7ff7b35e7135-7ff7b35e713b 577->583 584 7ff7b35e713e-7ff7b35e7145 577->584 603 7ff7b35e72f5-7ff7b35e7307 call 7ff7b35db404 581->603 604 7ff7b35e72f0-7ff7b35e72f3 581->604 588 7ff7b35e72cc-7ff7b35e72d1 call 7ff7b35db404 582->588 583->584 590 7ff7b35e7147-7ff7b35e714f 584->590 591 7ff7b35e7159 584->591 588->566 590->591 598 7ff7b35e7151-7ff7b35e7157 590->598 596 7ff7b35e715b-7ff7b35e71cf call 7ff7b35eb6e0 * 4 call 7ff7b35e3d6c call 7ff7b35e7324 * 2 591->596 596->576 598->596 603->564 604->588 622 7ff7b35e6f60-7ff7b35e6f64 619->622 623 7ff7b35e6f5c 619->623 622->619 625 7ff7b35e6f66-7ff7b35e6f8b call 7ff7b35d7ab8 622->625 623->622 631 7ff7b35e6f8e-7ff7b35e6f92 625->631 632 7ff7b35e6f94-7ff7b35e6f9f 631->632 633 7ff7b35e6fa1-7ff7b35e6fa5 631->633 632->633 635 7ff7b35e6fa7-7ff7b35e6fab 632->635 633->631 637 7ff7b35e702c-7ff7b35e7030 635->637 638 7ff7b35e6fad-7ff7b35e6fd5 call 7ff7b35d7ab8 635->638 640 7ff7b35e7032-7ff7b35e7034 637->640 641 7ff7b35e7037-7ff7b35e7044 637->641 647 7ff7b35e6ff3-7ff7b35e6ff7 638->647 648 7ff7b35e6fd7 638->648 640->641 643 7ff7b35e7046-7ff7b35e705c call 7ff7b35e6d2c 641->643 644 7ff7b35e705f-7ff7b35e706e call 7ff7b35e6790 call 7ff7b35e6780 641->644 643->644 644->514 647->637 653 7ff7b35e6ff9-7ff7b35e7017 call 7ff7b35d7ab8 647->653 651 7ff7b35e6fda-7ff7b35e6fe1 648->651 651->647 654 7ff7b35e6fe3-7ff7b35e6ff1 651->654 659 7ff7b35e7023-7ff7b35e702a 653->659 654->647 654->651 659->637 660 7ff7b35e7019-7ff7b35e701d 659->660 660->637 661 7ff7b35e701f 660->661 661->659
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • _get_daylight.LIBCMT ref: 00007FF7B35E6E55
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35E67A8: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7B35E67BC
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35DB404: RtlFreeHeap.NTDLL(?,?,?,00007FF7B35E3F32,?,?,?,00007FF7B35E3F6F,?,?,00000000,00007FF7B35E4435,?,?,?,00007FF7B35E4367), ref: 00007FF7B35DB41A
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35DB404: GetLastError.KERNEL32(?,?,?,00007FF7B35E3F32,?,?,?,00007FF7B35E3F6F,?,?,00000000,00007FF7B35E4435,?,?,?,00007FF7B35E4367), ref: 00007FF7B35DB424
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35DB7E4: IsProcessorFeaturePresent.KERNEL32(?,?,?,?,00007FF7B35DB7C3,?,?,?,?,?,00007FF7B35DB6AE), ref: 00007FF7B35DB7ED
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35DB7E4: GetCurrentProcess.KERNEL32(?,?,?,?,00007FF7B35DB7C3,?,?,?,?,?,00007FF7B35DB6AE), ref: 00007FF7B35DB812
                                                                                                                                                                                                              • _get_daylight.LIBCMT ref: 00007FF7B35E6E44
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35E6808: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7B35E681C
                                                                                                                                                                                                              • _get_daylight.LIBCMT ref: 00007FF7B35E70BA
                                                                                                                                                                                                              • _get_daylight.LIBCMT ref: 00007FF7B35E70CB
                                                                                                                                                                                                              • _get_daylight.LIBCMT ref: 00007FF7B35E70DC
                                                                                                                                                                                                              • GetTimeZoneInformation.KERNELBASE(?,?,?,?,?,?,?,?,?,00000000,?,00007FF7B35E731C), ref: 00007FF7B35E7103
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _get_daylight$_invalid_parameter_noinfo$CurrentErrorFeatureFreeHeapInformationLastPresentProcessProcessorTimeZone
                                                                                                                                                                                                              • String ID: Eastern Standard Time$Eastern Summer Time
                                                                                                                                                                                                              • API String ID: 4070488512-239921721
                                                                                                                                                                                                              • Opcode ID: b22cc06a3c60431b14bcf1c8d747afbe170d6a75001cdb9071bf50fc7cf7b518
                                                                                                                                                                                                              • Instruction ID: f88143f891f83cbb2545e980f873507d5b3287f4b666790f101cf12792008540
                                                                                                                                                                                                              • Opcode Fuzzy Hash: b22cc06a3c60431b14bcf1c8d747afbe170d6a75001cdb9071bf50fc7cf7b518
                                                                                                                                                                                                              • Instruction Fuzzy Hash: CCD1D326A0C26285EBA4BF39D4811B9A361EF66794FC04235EB4D6768DDF3CE4C1C760

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              • Executed
                                                                                                                                                                                                              • Not Executed
                                                                                                                                                                                                              control_flow_graph 721 7ff7b35e7b74-7ff7b35e7be7 call 7ff7b35e78a8 724 7ff7b35e7c01-7ff7b35e7c0b call 7ff7b35d93fc 721->724 725 7ff7b35e7be9-7ff7b35e7bf2 call 7ff7b35d5dc8 721->725 731 7ff7b35e7c26-7ff7b35e7c8f CreateFileW 724->731 732 7ff7b35e7c0d-7ff7b35e7c24 call 7ff7b35d5dc8 call 7ff7b35d5de8 724->732 730 7ff7b35e7bf5-7ff7b35e7bfc call 7ff7b35d5de8 725->730 745 7ff7b35e7f42-7ff7b35e7f62 730->745 733 7ff7b35e7c91-7ff7b35e7c97 731->733 734 7ff7b35e7d0c-7ff7b35e7d17 GetFileType 731->734 732->730 737 7ff7b35e7cd9-7ff7b35e7d07 GetLastError call 7ff7b35d5d5c 733->737 738 7ff7b35e7c99-7ff7b35e7c9d 733->738 740 7ff7b35e7d6a-7ff7b35e7d71 734->740 741 7ff7b35e7d19-7ff7b35e7d54 GetLastError call 7ff7b35d5d5c CloseHandle 734->741 737->730 738->737 743 7ff7b35e7c9f-7ff7b35e7cd7 CreateFileW 738->743 748 7ff7b35e7d73-7ff7b35e7d77 740->748 749 7ff7b35e7d79-7ff7b35e7d7c 740->749 741->730 756 7ff7b35e7d5a-7ff7b35e7d65 call 7ff7b35d5de8 741->756 743->734 743->737 750 7ff7b35e7d82-7ff7b35e7dd7 call 7ff7b35d9314 748->750 749->750 751 7ff7b35e7d7e 749->751 759 7ff7b35e7df6-7ff7b35e7e27 call 7ff7b35e7628 750->759 760 7ff7b35e7dd9-7ff7b35e7de5 call 7ff7b35e7ab0 750->760 751->750 756->730 767 7ff7b35e7e2d-7ff7b35e7e6f 759->767 768 7ff7b35e7e29-7ff7b35e7e2b 759->768 760->759 766 7ff7b35e7de7 760->766 771 7ff7b35e7de9-7ff7b35e7df1 call 7ff7b35db968 766->771 769 7ff7b35e7e91-7ff7b35e7e9c 767->769 770 7ff7b35e7e71-7ff7b35e7e75 767->770 768->771 773 7ff7b35e7f40 769->773 774 7ff7b35e7ea2-7ff7b35e7ea6 769->774 770->769 772 7ff7b35e7e77-7ff7b35e7e8c 770->772 771->745 772->769 773->745 774->773 776 7ff7b35e7eac-7ff7b35e7ef1 CloseHandle CreateFileW 774->776 778 7ff7b35e7ef3-7ff7b35e7f21 GetLastError call 7ff7b35d5d5c call 7ff7b35d953c 776->778 779 7ff7b35e7f26-7ff7b35e7f3b 776->779 778->779 779->773
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: File$CreateErrorLast_invalid_parameter_noinfo$CloseHandle$Type
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 1617910340-0
                                                                                                                                                                                                              • Opcode ID: 6900b12a6c6c443aa41c68e268e6275e38d412fb7e8bb922b7a0c5fbdd2459d5
                                                                                                                                                                                                              • Instruction ID: 295bdcbf190dfd96455fd70fa42c69d17e7117482e11012bd840b777fc71c1e6
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 6900b12a6c6c443aa41c68e268e6275e38d412fb7e8bb922b7a0c5fbdd2459d5
                                                                                                                                                                                                              • Instruction Fuzzy Hash: A2C10236B18A5185EB90EFB8C4806AC7765FB5AB98B410335DF2E6B398CF38D091C310

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: FileFind$DirectoryRemove$CloseDeleteFirstNext
                                                                                                                                                                                                              • String ID: %s\*
                                                                                                                                                                                                              • API String ID: 1057558799-766152087
                                                                                                                                                                                                              • Opcode ID: 13d1e5ca616fbee15f7399d2a7e70757b47be021e92437ea9419fac0636d742e
                                                                                                                                                                                                              • Instruction ID: e8f0b767daaec0bd23973d84ae7b17b2d9d9ca27c556adbd6ecdf3c1d991faf4
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 13d1e5ca616fbee15f7399d2a7e70757b47be021e92437ea9419fac0636d742e
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 3C41682590C55285EAA0BB38E4441B9E3A4FF76758FC00232D79D52A9CDF3CD58AC730

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              • Executed
                                                                                                                                                                                                              • Not Executed
                                                                                                                                                                                                              control_flow_graph 1042 7ff7b35e708c-7ff7b35e70c1 call 7ff7b35e6798 call 7ff7b35e67a0 call 7ff7b35e6808 1049 7ff7b35e71ff-7ff7b35e726d call 7ff7b35db7e4 call 7ff7b35e2788 1042->1049 1050 7ff7b35e70c7-7ff7b35e70d2 call 7ff7b35e67a8 1042->1050 1062 7ff7b35e726f-7ff7b35e7276 1049->1062 1063 7ff7b35e727b-7ff7b35e727e 1049->1063 1050->1049 1056 7ff7b35e70d8-7ff7b35e70e3 call 7ff7b35e67d8 1050->1056 1056->1049 1061 7ff7b35e70e9-7ff7b35e710c call 7ff7b35db404 GetTimeZoneInformation 1056->1061 1074 7ff7b35e71d4-7ff7b35e71fe call 7ff7b35e6790 call 7ff7b35e6780 call 7ff7b35e6788 1061->1074 1075 7ff7b35e7112-7ff7b35e7133 1061->1075 1065 7ff7b35e730b-7ff7b35e730e 1062->1065 1066 7ff7b35e72b5-7ff7b35e72c8 call 7ff7b35de664 1063->1066 1067 7ff7b35e7280 1063->1067 1070 7ff7b35e7283 call 7ff7b35e708c 1065->1070 1071 7ff7b35e7314-7ff7b35e731c call 7ff7b35e6e10 1065->1071 1078 7ff7b35e72d3-7ff7b35e72ee call 7ff7b35e2788 1066->1078 1079 7ff7b35e72ca 1066->1079 1067->1070 1083 7ff7b35e7288-7ff7b35e72b4 call 7ff7b35db404 call 7ff7b35cbab0 1070->1083 1071->1083 1080 7ff7b35e7135-7ff7b35e713b 1075->1080 1081 7ff7b35e713e-7ff7b35e7145 1075->1081 1097 7ff7b35e72f5-7ff7b35e7307 call 7ff7b35db404 1078->1097 1098 7ff7b35e72f0-7ff7b35e72f3 1078->1098 1084 7ff7b35e72cc-7ff7b35e72d1 call 7ff7b35db404 1079->1084 1080->1081 1086 7ff7b35e7147-7ff7b35e714f 1081->1086 1087 7ff7b35e7159 1081->1087 1084->1067 1086->1087 1093 7ff7b35e7151-7ff7b35e7157 1086->1093 1091 7ff7b35e715b-7ff7b35e71cf call 7ff7b35eb6e0 * 4 call 7ff7b35e3d6c call 7ff7b35e7324 * 2 1087->1091 1091->1074 1093->1091 1097->1065 1098->1084
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • _get_daylight.LIBCMT ref: 00007FF7B35E70BA
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35E6808: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7B35E681C
                                                                                                                                                                                                              • _get_daylight.LIBCMT ref: 00007FF7B35E70CB
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35E67A8: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7B35E67BC
                                                                                                                                                                                                              • _get_daylight.LIBCMT ref: 00007FF7B35E70DC
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35E67D8: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7B35E67EC
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35DB404: RtlFreeHeap.NTDLL(?,?,?,00007FF7B35E3F32,?,?,?,00007FF7B35E3F6F,?,?,00000000,00007FF7B35E4435,?,?,?,00007FF7B35E4367), ref: 00007FF7B35DB41A
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35DB404: GetLastError.KERNEL32(?,?,?,00007FF7B35E3F32,?,?,?,00007FF7B35E3F6F,?,?,00000000,00007FF7B35E4435,?,?,?,00007FF7B35E4367), ref: 00007FF7B35DB424
                                                                                                                                                                                                              • GetTimeZoneInformation.KERNELBASE(?,?,?,?,?,?,?,?,?,00000000,?,00007FF7B35E731C), ref: 00007FF7B35E7103
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _get_daylight_invalid_parameter_noinfo$ErrorFreeHeapInformationLastTimeZone
                                                                                                                                                                                                              • String ID: Eastern Standard Time$Eastern Summer Time
                                                                                                                                                                                                              • API String ID: 3458911817-239921721
                                                                                                                                                                                                              • Opcode ID: dc6df152e4e0072f1ab9809411110e842ecafcb7cd56bca977f92307902173f2
                                                                                                                                                                                                              • Instruction ID: fbc1bd94d45890fac675896dd110716a01b491022a0d31b4a0a29babe2f01a50
                                                                                                                                                                                                              • Opcode Fuzzy Hash: dc6df152e4e0072f1ab9809411110e842ecafcb7cd56bca977f92307902173f2
                                                                                                                                                                                                              • Instruction Fuzzy Hash: C151C436A0C25286F794FF39D881169E361BF6A784FC04235EB4D57699DF3CE4808760
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Find$CloseFileFirst
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2295610775-0
                                                                                                                                                                                                              • Opcode ID: bf04df12ed89424385b35bc97b9e30209b4e9d30cb3ee9ccc1531a0517fd62e7
                                                                                                                                                                                                              • Instruction ID: 896966a225f0a88dc4aa841ce210392be47c1457a984285d5b3490e37dfa5a29
                                                                                                                                                                                                              • Opcode Fuzzy Hash: bf04df12ed89424385b35bc97b9e30209b4e9d30cb3ee9ccc1531a0517fd62e7
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 4EF0A966A1C64186F7E09B74B455366A390FF95328F800735DB6D12AD8DF3CD0898710
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ErrorFileLastModuleName
                                                                                                                                                                                                              • String ID: Could not create temporary directory!$Could not load PyInstaller's embedded PKG archive from the executable (%s)$Could not side-load PyInstaller's PKG archive from external file (%s)$Failed to convert DLL search path!$Failed to initialize security descriptor for temporary directory!$Failed to load Tcl/Tk shared libraries for splash screen!$Failed to load splash screen resources!$Failed to remove temporary directory: %s$Failed to start splash screen!$Failed to unpack splash screen dependencies from PKG archive!$Invalid value in _PYI_PARENT_PROCESS_LEVEL: %s$MEI$PYINSTALLER_RESET_ENVIRONMENT$PYINSTALLER_STRICT_UNPACK_MODE$PYINSTALLER_SUPPRESS_SPLASH_SCREEN$Path exceeds PYI_PATH_MAX limit.$Py_GIL_DISABLED$VCRUNTIME140.dll$_PYI_APPLICATION_HOME_DIR$_PYI_APPLICATION_HOME_DIR not set for onefile child process!$_PYI_ARCHIVE_FILE$_PYI_PARENT_PROCESS_LEVEL$_PYI_SPLASH_IPC$hide-early$hide-late$minimize-early$minimize-late$pkg$pyi-contents-directory$pyi-hide-console$pyi-python-flag$pyi-runtime-tmpdir
                                                                                                                                                                                                              • API String ID: 2776309574-3325264605
                                                                                                                                                                                                              • Opcode ID: bab758d5dd615f8f942ac918c14ef296acf9dcec52a111ed12c92b7a2b0d960d
                                                                                                                                                                                                              • Instruction ID: 9b98d692e060a842cb4ff0fadcd6aba82ba2354058c2171414e3e6b9d7d1f987
                                                                                                                                                                                                              • Opcode Fuzzy Hash: bab758d5dd615f8f942ac918c14ef296acf9dcec52a111ed12c92b7a2b0d960d
                                                                                                                                                                                                              • Instruction Fuzzy Hash: CD42A161A0C68695FAA5B73C94152F9E691AF72748FC40031DB9E622CEDE2CE5C9C330

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              • Executed
                                                                                                                                                                                                              • Not Executed
                                                                                                                                                                                                              control_flow_graph 359 7ff7b35c1930-7ff7b35c196b call 7ff7b35c39e0 362 7ff7b35c1971-7ff7b35c19b1 call 7ff7b35c73e0 359->362 363 7ff7b35c1c2e-7ff7b35c1c52 call 7ff7b35cbab0 359->363 368 7ff7b35c19b7-7ff7b35c19c7 call 7ff7b35cfbcc 362->368 369 7ff7b35c1c1b-7ff7b35c1c1e call 7ff7b35cf544 362->369 374 7ff7b35c19c9-7ff7b35c19e3 call 7ff7b35d5de8 call 7ff7b35c2020 368->374 375 7ff7b35c19e8-7ff7b35c1a04 call 7ff7b35cf894 368->375 373 7ff7b35c1c23-7ff7b35c1c2b 369->373 373->363 374->369 381 7ff7b35c1a06-7ff7b35c1a20 call 7ff7b35d5de8 call 7ff7b35c2020 375->381 382 7ff7b35c1a25-7ff7b35c1a3a call 7ff7b35d5e08 375->382 381->369 389 7ff7b35c1a3c-7ff7b35c1a56 call 7ff7b35d5de8 call 7ff7b35c2020 382->389 390 7ff7b35c1a5b-7ff7b35c1ae5 call 7ff7b35c1c60 * 2 call 7ff7b35cfbcc call 7ff7b35d5e24 382->390 389->369 403 7ff7b35c1aea-7ff7b35c1af4 390->403 404 7ff7b35c1af6-7ff7b35c1b10 call 7ff7b35d5de8 call 7ff7b35c2020 403->404 405 7ff7b35c1b15-7ff7b35c1b2e call 7ff7b35cf894 403->405 404->369 410 7ff7b35c1b30-7ff7b35c1b4a call 7ff7b35d5de8 call 7ff7b35c2020 405->410 411 7ff7b35c1b4f-7ff7b35c1b6b call 7ff7b35cf608 405->411 410->369 419 7ff7b35c1b7e-7ff7b35c1b8c 411->419 420 7ff7b35c1b6d-7ff7b35c1b79 call 7ff7b35c1e50 411->420 419->369 421 7ff7b35c1b92-7ff7b35c1b99 419->421 420->369 424 7ff7b35c1ba1-7ff7b35c1ba7 421->424 426 7ff7b35c1bc0-7ff7b35c1bcf 424->426 427 7ff7b35c1ba9-7ff7b35c1bb6 424->427 426->426 428 7ff7b35c1bd1-7ff7b35c1bda 426->428 427->428 429 7ff7b35c1bef 428->429 430 7ff7b35c1bdc-7ff7b35c1bdf 428->430 432 7ff7b35c1bf1-7ff7b35c1c04 429->432 430->429 431 7ff7b35c1be1-7ff7b35c1be4 430->431 431->429 433 7ff7b35c1be6-7ff7b35c1be9 431->433 434 7ff7b35c1c06 432->434 435 7ff7b35c1c0d-7ff7b35c1c19 432->435 433->429 436 7ff7b35c1beb-7ff7b35c1bed 433->436 434->435 435->369 435->424 436->432
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C73E0: _fread_nolock.LIBCMT ref: 00007FF7B35C748A
                                                                                                                                                                                                              • _fread_nolock.LIBCMT ref: 00007FF7B35C19FB
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C2020: GetCurrentProcessId.KERNEL32(?,?,?,?,00000000,00000000,?,00000000,00007FF7B35C1B4A), ref: 00007FF7B35C2070
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _fread_nolock$CurrentProcess
                                                                                                                                                                                                              • String ID: Could not allocate buffer for TOC!$Could not allocate memory for archive structure!$Could not read full TOC!$Error on file.$Failed to read cookie!$Failed to seek to cookie position!$MEI$calloc$fread$fseek$malloc
                                                                                                                                                                                                              • API String ID: 2397952137-3497178890
                                                                                                                                                                                                              • Opcode ID: 5f947099be3a53b39a177038c113629b7d0864f625fd406fd4a19cd2ca708d12
                                                                                                                                                                                                              • Instruction ID: 42803647da48ae187e15adf96d406c0948755155947795f1c1a27333e7a1d452
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 5f947099be3a53b39a177038c113629b7d0864f625fd406fd4a19cd2ca708d12
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 9C818371A0C68285E790EB38D4412B9A3A1AF66748FD04131EB8D6765DDE3CE6C58B70

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              • Executed
                                                                                                                                                                                                              • Not Executed
                                                                                                                                                                                                              control_flow_graph 437 7ff7b35c15e0-7ff7b35c15f1 438 7ff7b35c15f3-7ff7b35c15fc call 7ff7b35c1030 437->438 439 7ff7b35c1617-7ff7b35c1631 call 7ff7b35c39e0 437->439 446 7ff7b35c160e-7ff7b35c1616 438->446 447 7ff7b35c15fe-7ff7b35c1609 call 7ff7b35c1e50 438->447 444 7ff7b35c1662-7ff7b35c167c call 7ff7b35c39e0 439->444 445 7ff7b35c1633-7ff7b35c1661 call 7ff7b35d5de8 call 7ff7b35c2020 439->445 454 7ff7b35c1698-7ff7b35c16af call 7ff7b35cfbcc 444->454 455 7ff7b35c167e-7ff7b35c1693 call 7ff7b35c1e50 444->455 447->446 461 7ff7b35c16b1-7ff7b35c16d4 call 7ff7b35d5de8 call 7ff7b35c2020 454->461 462 7ff7b35c16d9-7ff7b35c16dd 454->462 463 7ff7b35c1801-7ff7b35c1804 call 7ff7b35cf544 455->463 476 7ff7b35c17f9-7ff7b35c17fc call 7ff7b35cf544 461->476 465 7ff7b35c16df-7ff7b35c16eb call 7ff7b35c11f0 462->465 466 7ff7b35c16f7-7ff7b35c1717 call 7ff7b35d5e24 462->466 471 7ff7b35c1809-7ff7b35c181b 463->471 473 7ff7b35c16f0-7ff7b35c16f2 465->473 477 7ff7b35c1741-7ff7b35c174c 466->477 478 7ff7b35c1719-7ff7b35c173c call 7ff7b35d5de8 call 7ff7b35c2020 466->478 473->476 476->463 479 7ff7b35c17e2-7ff7b35c17ea call 7ff7b35d5e10 477->479 480 7ff7b35c1752-7ff7b35c1757 477->480 491 7ff7b35c17ef-7ff7b35c17f4 478->491 479->491 484 7ff7b35c1760-7ff7b35c1782 call 7ff7b35cf894 480->484 492 7ff7b35c1784-7ff7b35c179c call 7ff7b35cffd4 484->492 493 7ff7b35c17ba-7ff7b35c17c6 call 7ff7b35d5de8 484->493 491->476 499 7ff7b35c17a5-7ff7b35c17b8 call 7ff7b35d5de8 492->499 500 7ff7b35c179e-7ff7b35c17a1 492->500 498 7ff7b35c17cd-7ff7b35c17d8 call 7ff7b35c2020 493->498 505 7ff7b35c17dd 498->505 499->498 500->484 502 7ff7b35c17a3 500->502 502->505 505->479
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentProcess
                                                                                                                                                                                                              • String ID: Failed to create symbolic link %s!$Failed to extract %s: failed to allocate temporary buffer!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to open target file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$Failed to extract %s: failed to write data chunk!$fopen$fread$fseek$fwrite$malloc
                                                                                                                                                                                                              • API String ID: 2050909247-1550345328
                                                                                                                                                                                                              • Opcode ID: 48408747cb3c2ed73c201aafa5c62b1a50f7074641420da138e9dfa43a697cfe
                                                                                                                                                                                                              • Instruction ID: 05bcb2034371667fa716f3c4cbfa657921b4d3f69d657a06e0e1fe5e5e727945
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 48408747cb3c2ed73c201aafa5c62b1a50f7074641420da138e9dfa43a697cfe
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 7A51A161A0C64746EA90BB3994005A9A390BF66798FC44132EF1C2779EDF3CE6C9C770

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • GetTempPathW.KERNEL32(FFFFFFFF,00000000,?,00007FF7B35C3101), ref: 00007FF7B35C7B54
                                                                                                                                                                                                              • GetCurrentProcessId.KERNEL32(?,00007FF7B35C3101), ref: 00007FF7B35C7B5A
                                                                                                                                                                                                              • CreateDirectoryW.KERNELBASE(?,00007FF7B35C3101), ref: 00007FF7B35C7B9C
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C7C80: GetEnvironmentVariableW.KERNEL32(00007FF7B35C2C4F), ref: 00007FF7B35C7CB7
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C7C80: ExpandEnvironmentStringsW.KERNEL32 ref: 00007FF7B35C7CD9
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35D9114: _invalid_parameter_noinfo.LIBCMT ref: 00007FF7B35D912D
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Environment$CreateCurrentDirectoryExpandPathProcessStringsTempVariable_invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID: LOADER: failed to set the TMP environment variable.$LOADER: length of teporary directory path exceeds maximum path length!$TMP$TMP$_MEI%d
                                                                                                                                                                                                              • API String ID: 365913792-1339014028
                                                                                                                                                                                                              • Opcode ID: f3273f3d93b4370bc37173b7eaaf61b6c15f57638ffcf23e2354b18da0bd52c9
                                                                                                                                                                                                              • Instruction ID: 098dd2da3619b37fc0efb7586cb4b45e7c66458fc8ef53c719560e7d1e760f88
                                                                                                                                                                                                              • Opcode Fuzzy Hash: f3273f3d93b4370bc37173b7eaaf61b6c15f57638ffcf23e2354b18da0bd52c9
                                                                                                                                                                                                              • Instruction Fuzzy Hash: FA41E021A0D69245FA90FB3D98556F99295AFA6788FC00031DF0D27B9EEE3CE5C18230

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              • Executed
                                                                                                                                                                                                              • Not Executed
                                                                                                                                                                                                              control_flow_graph 784 7ff7b35c11f0-7ff7b35c124d call 7ff7b35cb2e0 787 7ff7b35c124f-7ff7b35c1276 call 7ff7b35c1e50 784->787 788 7ff7b35c1277-7ff7b35c128f call 7ff7b35d5e24 784->788 793 7ff7b35c1291-7ff7b35c12af call 7ff7b35d5de8 call 7ff7b35c2020 788->793 794 7ff7b35c12b4-7ff7b35c12c4 call 7ff7b35d5e24 788->794 807 7ff7b35c1419-7ff7b35c142e call 7ff7b35cafc0 call 7ff7b35d5e10 * 2 793->807 799 7ff7b35c12c6-7ff7b35c12e4 call 7ff7b35d5de8 call 7ff7b35c2020 794->799 800 7ff7b35c12e9-7ff7b35c12fb 794->800 799->807 803 7ff7b35c1300-7ff7b35c1325 call 7ff7b35cf894 800->803 813 7ff7b35c1411 803->813 814 7ff7b35c132b-7ff7b35c1335 call 7ff7b35cf608 803->814 821 7ff7b35c1433-7ff7b35c144d 807->821 813->807 814->813 820 7ff7b35c133b-7ff7b35c1347 814->820 822 7ff7b35c1350-7ff7b35c1378 call 7ff7b35c9720 820->822 825 7ff7b35c13f6-7ff7b35c140c call 7ff7b35c1e50 822->825 826 7ff7b35c137a-7ff7b35c137d 822->826 825->813 827 7ff7b35c13f1 826->827 828 7ff7b35c137f-7ff7b35c1389 826->828 827->825 830 7ff7b35c13b4-7ff7b35c13b7 828->830 831 7ff7b35c138b-7ff7b35c1399 call 7ff7b35cffd4 828->831 833 7ff7b35c13ca-7ff7b35c13cf 830->833 834 7ff7b35c13b9-7ff7b35c13c7 call 7ff7b35eb040 830->834 836 7ff7b35c139e-7ff7b35c13a1 831->836 833->822 835 7ff7b35c13d5-7ff7b35c13d8 833->835 834->833 838 7ff7b35c13da-7ff7b35c13dd 835->838 839 7ff7b35c13ec-7ff7b35c13ef 835->839 840 7ff7b35c13af-7ff7b35c13b2 836->840 841 7ff7b35c13a3-7ff7b35c13ad call 7ff7b35cf608 836->841 838->825 843 7ff7b35c13df-7ff7b35c13e7 838->843 839->813 840->825 841->833 841->840 843->803
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentProcess
                                                                                                                                                                                                              • String ID: 1.3.1$Failed to extract %s: decompression resulted in return code %d!$Failed to extract %s: failed to allocate temporary input buffer!$Failed to extract %s: failed to allocate temporary output buffer!$Failed to extract %s: inflateInit() failed with return code %d!$malloc
                                                                                                                                                                                                              • API String ID: 2050909247-2813020118
                                                                                                                                                                                                              • Opcode ID: c767c8624a844fc3a6c994365fe1efa40bde488381a9e214cbf2d7cbba15fe36
                                                                                                                                                                                                              • Instruction ID: bd710fbe172637b109934f62affdd9bbca64bf85f92d1931382b22b63f49aa1a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: c767c8624a844fc3a6c994365fe1efa40bde488381a9e214cbf2d7cbba15fe36
                                                                                                                                                                                                              • Instruction Fuzzy Hash: EF51E662A0C54245EAA0BB39A4403BAA291FF66B98FD44131DF4D6778DDF3CE585C730

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • FreeLibrary.KERNEL32(?,?,?,00007FF7B35E02B6,?,?,-00000018,00007FF7B35DBBFB,?,?,?,00007FF7B35DBAF2,?,?,?,00007FF7B35D6E9E), ref: 00007FF7B35E0098
                                                                                                                                                                                                              • GetProcAddress.KERNEL32(?,?,?,00007FF7B35E02B6,?,?,-00000018,00007FF7B35DBBFB,?,?,?,00007FF7B35DBAF2,?,?,?,00007FF7B35D6E9E), ref: 00007FF7B35E00A4
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: AddressFreeLibraryProc
                                                                                                                                                                                                              • String ID: api-ms-$ext-ms-
                                                                                                                                                                                                              • API String ID: 3013587201-537541572
                                                                                                                                                                                                              • Opcode ID: aadbaee7c76e5d54b6d4897acaf79a0667e5faa90471c45c14db321705774b03
                                                                                                                                                                                                              • Instruction ID: ea8b60c78d0ba9ee661a40ce8a06a81205c7e10b05d6d395aa7518248645f012
                                                                                                                                                                                                              • Opcode Fuzzy Hash: aadbaee7c76e5d54b6d4897acaf79a0667e5faa90471c45c14db321705774b03
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 7541F461B1D61245EA95EB3AA800675A381FF66B90FC94235DF0D6B74CEE3DE4C58330

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • GetModuleFileNameW.KERNEL32(?,00007FF7B35C2BC5), ref: 00007FF7B35C2AA1
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,00007FF7B35C2BC5), ref: 00007FF7B35C2AAB
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C2310: GetCurrentProcessId.KERNEL32(?,?,?,?,?,?,?,?,00007FF7B35C2AC6,?,00007FF7B35C2BC5), ref: 00007FF7B35C2360
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C2310: FormatMessageW.KERNEL32(?,?,?,?,?,?,?,?,00007FF7B35C2AC6,?,00007FF7B35C2BC5), ref: 00007FF7B35C241A
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentErrorFileFormatLastMessageModuleNameProcess
                                                                                                                                                                                                              • String ID: Failed to convert executable path to UTF-8.$Failed to obtain executable path.$Failed to resolve full path to executable %ls.$GetModuleFileNameW$\\?\
                                                                                                                                                                                                              • API String ID: 4002088556-2863816727
                                                                                                                                                                                                              • Opcode ID: aed140f8d8e2637361ba54921802919f4f3b7eb641456186ceb893f60fbbd120
                                                                                                                                                                                                              • Instruction ID: 83e1c0f940390364d6f95c9b4243a29a8cd590a4510b437e074f8937645e1f6e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: aed140f8d8e2637361ba54921802919f4f3b7eb641456186ceb893f60fbbd120
                                                                                                                                                                                                              • Instruction Fuzzy Hash: A2219461B1C64291FAA4BB3DE8043B59250BF6A348FC00232E75DA65DDEE2CE5C48334

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              • Executed
                                                                                                                                                                                                              • Not Executed
                                                                                                                                                                                                              control_flow_graph 929 7ff7b35dc8fc-7ff7b35dc922 930 7ff7b35dc924-7ff7b35dc938 call 7ff7b35d5dc8 call 7ff7b35d5de8 929->930 931 7ff7b35dc93d-7ff7b35dc941 929->931 949 7ff7b35dcd2e 930->949 933 7ff7b35dcd17-7ff7b35dcd23 call 7ff7b35d5dc8 call 7ff7b35d5de8 931->933 934 7ff7b35dc947-7ff7b35dc94e 931->934 951 7ff7b35dcd29 call 7ff7b35db7c4 933->951 934->933 936 7ff7b35dc954-7ff7b35dc982 934->936 936->933 940 7ff7b35dc988-7ff7b35dc98f 936->940 941 7ff7b35dc991-7ff7b35dc9a3 call 7ff7b35d5dc8 call 7ff7b35d5de8 940->941 942 7ff7b35dc9a8-7ff7b35dc9ab 940->942 941->951 947 7ff7b35dcd13-7ff7b35dcd15 942->947 948 7ff7b35dc9b1-7ff7b35dc9b7 942->948 952 7ff7b35dcd31-7ff7b35dcd48 947->952 948->947 953 7ff7b35dc9bd-7ff7b35dc9c0 948->953 949->952 951->949 953->941 956 7ff7b35dc9c2-7ff7b35dc9e7 953->956 958 7ff7b35dca1a-7ff7b35dca21 956->958 959 7ff7b35dc9e9-7ff7b35dc9eb 956->959 960 7ff7b35dca23-7ff7b35dca4b call 7ff7b35de664 call 7ff7b35db404 * 2 958->960 961 7ff7b35dc9f6-7ff7b35dca0d call 7ff7b35d5dc8 call 7ff7b35d5de8 call 7ff7b35db7c4 958->961 962 7ff7b35dca12-7ff7b35dca18 959->962 963 7ff7b35dc9ed-7ff7b35dc9f4 959->963 992 7ff7b35dca4d-7ff7b35dca63 call 7ff7b35d5de8 call 7ff7b35d5dc8 960->992 993 7ff7b35dca68-7ff7b35dca93 call 7ff7b35dd124 960->993 990 7ff7b35dcba0 961->990 964 7ff7b35dca98-7ff7b35dcaaf 962->964 963->961 963->962 967 7ff7b35dcab1-7ff7b35dcab9 964->967 968 7ff7b35dcb2a-7ff7b35dcb34 call 7ff7b35e4b2c 964->968 967->968 971 7ff7b35dcabb-7ff7b35dcabd 967->971 979 7ff7b35dcbbe 968->979 980 7ff7b35dcb3a-7ff7b35dcb4f 968->980 971->968 975 7ff7b35dcabf-7ff7b35dcad5 971->975 975->968 982 7ff7b35dcad7-7ff7b35dcae3 975->982 988 7ff7b35dcbc3-7ff7b35dcbe3 ReadFile 979->988 980->979 984 7ff7b35dcb51-7ff7b35dcb63 GetConsoleMode 980->984 982->968 986 7ff7b35dcae5-7ff7b35dcae7 982->986 984->979 989 7ff7b35dcb65-7ff7b35dcb6d 984->989 986->968 991 7ff7b35dcae9-7ff7b35dcb01 986->991 994 7ff7b35dccdd-7ff7b35dcce6 GetLastError 988->994 995 7ff7b35dcbe9-7ff7b35dcbf1 988->995 989->988 997 7ff7b35dcb6f-7ff7b35dcb91 ReadConsoleW 989->997 1000 7ff7b35dcba3-7ff7b35dcbad call 7ff7b35db404 990->1000 991->968 1001 7ff7b35dcb03-7ff7b35dcb0f 991->1001 992->990 993->964 998 7ff7b35dcd03-7ff7b35dcd06 994->998 999 7ff7b35dcce8-7ff7b35dccfe call 7ff7b35d5de8 call 7ff7b35d5dc8 994->999 995->994 1003 7ff7b35dcbf7 995->1003 1006 7ff7b35dcb93 GetLastError 997->1006 1007 7ff7b35dcbb2-7ff7b35dcbbc 997->1007 1011 7ff7b35dcd0c-7ff7b35dcd0e 998->1011 1012 7ff7b35dcb99-7ff7b35dcb9b call 7ff7b35d5d5c 998->1012 999->990 1000->952 1001->968 1010 7ff7b35dcb11-7ff7b35dcb13 1001->1010 1004 7ff7b35dcbfe-7ff7b35dcc13 1003->1004 1004->1000 1014 7ff7b35dcc15-7ff7b35dcc20 1004->1014 1006->1012 1007->1004 1010->968 1018 7ff7b35dcb15-7ff7b35dcb25 1010->1018 1011->1000 1012->990 1020 7ff7b35dcc22-7ff7b35dcc3b call 7ff7b35dc514 1014->1020 1021 7ff7b35dcc47-7ff7b35dcc4f 1014->1021 1018->968 1029 7ff7b35dcc40-7ff7b35dcc42 1020->1029 1025 7ff7b35dcc51-7ff7b35dcc63 1021->1025 1026 7ff7b35dcccb-7ff7b35dccd8 call 7ff7b35dc354 1021->1026 1030 7ff7b35dcc65 1025->1030 1031 7ff7b35dccbe-7ff7b35dccc6 1025->1031 1026->1029 1029->1000 1033 7ff7b35dcc6a-7ff7b35dcc71 1030->1033 1031->1000 1034 7ff7b35dcc73-7ff7b35dcc77 1033->1034 1035 7ff7b35dccad-7ff7b35dccb8 1033->1035 1036 7ff7b35dcc93 1034->1036 1037 7ff7b35dcc79-7ff7b35dcc80 1034->1037 1035->1031 1039 7ff7b35dcc99-7ff7b35dcca9 1036->1039 1037->1036 1038 7ff7b35dcc82-7ff7b35dcc86 1037->1038 1038->1036 1040 7ff7b35dcc88-7ff7b35dcc91 1038->1040 1039->1033 1041 7ff7b35dccab 1039->1041 1040->1039 1041->1031
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3215553584-0
                                                                                                                                                                                                              • Opcode ID: e93ed7a31f68c532dbd80e14518cadf7dab422dd0c3a13bad048ec9ed5af6547
                                                                                                                                                                                                              • Instruction ID: 208c28849ad4add9b31f92cfe3a50b1e4305ee1d943763ca229224c843b9b315
                                                                                                                                                                                                              • Opcode Fuzzy Hash: e93ed7a31f68c532dbd80e14518cadf7dab422dd0c3a13bad048ec9ed5af6547
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 13C1E52290C68251F7A0BB289444ABDB751EFA2B80FD54131DB6E2779DDF7CE4C58320

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Token$InformationProcess$CloseConvertCurrentErrorHandleLastOpenString
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 995526605-0
                                                                                                                                                                                                              • Opcode ID: 1d53d6d9a09d765e47c497b0d6d615a887cb0773de01ad6b7486372e5d5147f3
                                                                                                                                                                                                              • Instruction ID: c94e5252d26e56e97deb3e8811c2c1b5faa0732006352f19b4b62b6a6412c978
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 1d53d6d9a09d765e47c497b0d6d615a887cb0773de01ad6b7486372e5d5147f3
                                                                                                                                                                                                              • Instruction Fuzzy Hash: A721D735A0C64246EB90AB3DA44022EE3A5EF927A4FD00235DB6C53AECDF7DD5858720

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              APIs
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C79C0: GetCurrentProcess.KERNEL32 ref: 00007FF7B35C79E0
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C79C0: OpenProcessToken.ADVAPI32 ref: 00007FF7B35C79F3
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C79C0: GetTokenInformation.KERNELBASE ref: 00007FF7B35C7A18
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C79C0: GetLastError.KERNEL32 ref: 00007FF7B35C7A22
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C79C0: GetTokenInformation.KERNELBASE ref: 00007FF7B35C7A62
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C79C0: ConvertSidToStringSidW.ADVAPI32 ref: 00007FF7B35C7A7E
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C79C0: CloseHandle.KERNEL32 ref: 00007FF7B35C7A96
                                                                                                                                                                                                              • LocalFree.KERNEL32(00000000,00007FF7B35C3099), ref: 00007FF7B35C860C
                                                                                                                                                                                                              • LocalFree.KERNEL32 ref: 00007FF7B35C8615
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Token$FreeInformationLocalProcess$CloseConvertCurrentErrorHandleLastOpenString
                                                                                                                                                                                                              • String ID: D:(A;;FA;;;%s)$D:(A;;FA;;;%s)(A;;FA;;;%s)$S-1-3-4$Security descriptor string length exceeds PYI_PATH_MAX!
                                                                                                                                                                                                              • API String ID: 6828938-1529539262
                                                                                                                                                                                                              • Opcode ID: adc432e05c3c573e6ed13a0ece6c243bdb52cb2c57461f69188002d76d144bb7
                                                                                                                                                                                                              • Instruction ID: d31a6461c2f9e6bc86001317a564538cd24b55f0d17bb617e28f6cf62e6ae66c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: adc432e05c3c573e6ed13a0ece6c243bdb52cb2c57461f69188002d76d144bb7
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 05217331A0C64691F690BB28E8113EAE264EFA6784FC54035EB4D6379ADF3CE5C48770
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • CreateDirectoryW.KERNELBASE(00000000,?,00007FF7B35C28EC,FFFFFFFF,00000000,00007FF7B35C3362), ref: 00007FF7B35C7382
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CreateDirectory
                                                                                                                                                                                                              • String ID: %.*s$%s%c$\
                                                                                                                                                                                                              • API String ID: 4241100979-1685191245
                                                                                                                                                                                                              • Opcode ID: d6b0fa5a9360523a913fa8a1ec13b0d7e89b388012948b944b947363b6689328
                                                                                                                                                                                                              • Instruction ID: 0f90fcafc0778fa04458775e000681642ec2ae41430001c85ab89ff005dc1350
                                                                                                                                                                                                              • Opcode Fuzzy Hash: d6b0fa5a9360523a913fa8a1ec13b0d7e89b388012948b944b947363b6689328
                                                                                                                                                                                                              • Instruction Fuzzy Hash: BB31EB2171DAC545E661A739A4107EAA258EF95BE4FC00230EF5D53BCDDF2CD2858720
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF7B35DDDEB), ref: 00007FF7B35DDF1C
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF7B35DDDEB), ref: 00007FF7B35DDFA7
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ConsoleErrorLastMode
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 953036326-0
                                                                                                                                                                                                              • Opcode ID: 72bdbade8f7f3669228eabd23d25320e309643dcfe9983c62a88d960f5e90d12
                                                                                                                                                                                                              • Instruction ID: 223f08e9d8e09e750f431c0498ea63539936f55019655c1ad33281ed9237dc86
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 72bdbade8f7f3669228eabd23d25320e309643dcfe9983c62a88d960f5e90d12
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 7B91B462A0C65285F790AF3D9440A7DABA0AF66B88F944135DF1E76688DE38D4C5C720
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _get_daylight$_isindst
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 4170891091-0
                                                                                                                                                                                                              • Opcode ID: 1e65149fea67db38c583cbef9075d189eb690351c339e1a8e9f7c5b338f54ae1
                                                                                                                                                                                                              • Instruction ID: 8379cac8fc562d796be5b8da3b48354caa745b25b1131f14664e35b853734005
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 1e65149fea67db38c583cbef9075d189eb690351c339e1a8e9f7c5b338f54ae1
                                                                                                                                                                                                              • Instruction Fuzzy Hash: C1510872F0822146EB54EBBD9D456BCA765AF21358F910335DF1E63ADCDB38A4818720
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: File$ErrorHandleInformationLastNamedPeekPipeType
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2780335769-0
                                                                                                                                                                                                              • Opcode ID: 77bca5f2b499945077be2e31c411e207fda1b30dacdec75b7e6b5811779d4ab0
                                                                                                                                                                                                              • Instruction ID: 7383e0a988545eb63a4a2003af6e2afcb7f71d736fcb4895695609d08d2cb329
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 77bca5f2b499945077be2e31c411e207fda1b30dacdec75b7e6b5811779d4ab0
                                                                                                                                                                                                              • Instruction Fuzzy Hash: ED51A022E086419AF794EF78D4507BDA3E1AF69B48F904534DF1D6768CDF38D4868360
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CloseCreateFileHandle_invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 1279662727-0
                                                                                                                                                                                                              • Opcode ID: 615a019661923f18b870c88d8c8c2e3de58a1ea0c3f5553ccf0a12bc46e2c946
                                                                                                                                                                                                              • Instruction ID: 7e44d842bd0d9aa241b1e207dddb73d3af0aef2e873e0f51b50aec9df5a7e97f
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 615a019661923f18b870c88d8c8c2e3de58a1ea0c3f5553ccf0a12bc46e2c946
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 0641E462D1C78193E790AB349500779A260FFB6764F908334E7AC23AD9DF7CA1E18760
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Process$CurrentExitTerminate
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 1703294689-0
                                                                                                                                                                                                              • Opcode ID: ad533715cf3b8ba661eb0a16145d01eebe53b03fcab9f2b2c8fa490b2e23822a
                                                                                                                                                                                                              • Instruction ID: 2995d8ad32a7bd2a609c75c2d3046d7a688a90290b240ea7f83038dcc49b792a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: ad533715cf3b8ba661eb0a16145d01eebe53b03fcab9f2b2c8fa490b2e23822a
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 77D05E54F0C64246EA883B78588453A82A14FABB00F811538CA5F2A3ABDD2CE4CD4220
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3215553584-0
                                                                                                                                                                                                              • Opcode ID: 141dc46c6224036006d776e19841065f05dd1418e65b387591b1a003cf84bd0f
                                                                                                                                                                                                              • Instruction ID: 0976c69595002e6217248c4f31ed2e5cf36afe6787f56246b82b501797e9b3a0
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 141dc46c6224036006d776e19841065f05dd1418e65b387591b1a003cf84bd0f
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 3051D521A0D24246EAA4BE399800679A291BF66BA8FD44735DF7C267DDCF3CD4908770
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_release_startup_lock
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 1236291503-0
                                                                                                                                                                                                              • Opcode ID: 0062f537d7c131bdaaf4aef5eb59421e6e9ee6bfc8727e8bca4d357a962c4ab6
                                                                                                                                                                                                              • Instruction ID: b8d75cb4109ced18e6681c5c033bebb31cee9ee95d2509d7762952b65e77a313
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 0062f537d7c131bdaaf4aef5eb59421e6e9ee6bfc8727e8bca4d357a962c4ab6
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 5B313E11E0C14241FA90BBBCA5513BA9291AF77788FC44035DB5E6B6EFDE2CA4C6C270
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: FileHandleType
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3000768030-0
                                                                                                                                                                                                              • Opcode ID: 336ff322d096320c7609ad2a1ebfb1af701ecd8db59b0b6a36a9cc413741d25d
                                                                                                                                                                                                              • Instruction ID: 787b2f56c7fd8a641bb04705cb3339d5b891f542daff008d466cd586f9205028
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 336ff322d096320c7609ad2a1ebfb1af701ecd8db59b0b6a36a9cc413741d25d
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 2D31A861A1CB4582D7A05B2D854057CA690FF56BB0BA40335DB7E277E4CF38E4E5C310
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • SetFilePointerEx.KERNELBASE(?,?,?,?,?,00007FF7B35DCFC0,?,?,?,?,?,00007FF7B35DD0C9), ref: 00007FF7B35DD020
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,?,?,00007FF7B35DCFC0,?,?,?,?,?,00007FF7B35DD0C9), ref: 00007FF7B35DD02A
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ErrorFileLastPointer
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2976181284-0
                                                                                                                                                                                                              • Opcode ID: c8d9032d6f18d1acbd55ff3d5784a6e8b9f1708e95d0104a6ada3112851001ef
                                                                                                                                                                                                              • Instruction ID: 02da0227911f738a4e7c9071ac6c99de60500bd97d321224ef584b66cdc2f5e4
                                                                                                                                                                                                              • Opcode Fuzzy Hash: c8d9032d6f18d1acbd55ff3d5784a6e8b9f1708e95d0104a6ada3112851001ef
                                                                                                                                                                                                              • Instruction Fuzzy Hash: A511E2A160CB4181DA90AB39B844069A3A1AF96BF4F940331EF7D1B7DDDE7CD0858700
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • FileTimeToSystemTime.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF7B35D6795), ref: 00007FF7B35D68B3
                                                                                                                                                                                                              • SystemTimeToTzSpecificLocalTime.KERNELBASE(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF7B35D6795), ref: 00007FF7B35D68C9
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Time$System$FileLocalSpecific
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 1707611234-0
                                                                                                                                                                                                              • Opcode ID: 3a94ee504119d0a5112130d15b8324ff604b1d1e2425208ec9014ecb5db7cc3c
                                                                                                                                                                                                              • Instruction ID: 3c9167dd9e71977bd2e39c56a96612d33cda8409bae762ae10fab39a27b39e0d
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 3a94ee504119d0a5112130d15b8324ff604b1d1e2425208ec9014ecb5db7cc3c
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 9211867250C65681EB949B29A40153AF7B0EFA2761FD00335FBAE955D8EF7CD085CB10
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • RtlFreeHeap.NTDLL(?,?,?,00007FF7B35E3F32,?,?,?,00007FF7B35E3F6F,?,?,00000000,00007FF7B35E4435,?,?,?,00007FF7B35E4367), ref: 00007FF7B35DB41A
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,00007FF7B35E3F32,?,?,?,00007FF7B35E3F6F,?,?,00000000,00007FF7B35E4435,?,?,?,00007FF7B35E4367), ref: 00007FF7B35DB424
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ErrorFreeHeapLast
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 485612231-0
                                                                                                                                                                                                              • Opcode ID: 0e9bd81d70d272d571b15e7d509907a6bc8aa23799849ce19584cafaa201c9c5
                                                                                                                                                                                                              • Instruction ID: 4271c8ced3a78cc5f657c5e7456ee9ac29e5a1af1a7ada67a16b95f0bfe0d81a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 0e9bd81d70d272d571b15e7d509907a6bc8aa23799849ce19584cafaa201c9c5
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 51E08650F0D10246FFC4BBF9984943891925F76700BC44530CB5D6B35DDE2C64C54230
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • CloseHandle.KERNELBASE(?,?,?,00007FF7B35DB87D,?,?,00000000,00007FF7B35DB932), ref: 00007FF7B35DBA6E
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,00007FF7B35DB87D,?,?,00000000,00007FF7B35DB932), ref: 00007FF7B35DBA78
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CloseErrorHandleLast
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 918212764-0
                                                                                                                                                                                                              • Opcode ID: 77e2bcd66fe63b7e32e9c420d5456187ea64b38b498190725808e49f9c0985ab
                                                                                                                                                                                                              • Instruction ID: da72571d634b1785e4deae0f77062f43c42cc3d9760f124a9be25e071d080fac
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 77e2bcd66fe63b7e32e9c420d5456187ea64b38b498190725808e49f9c0985ab
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 2021B011B0C64241EAE07B39A4846BD96825FA2BA0F844235DB7E673C9CE6CE4C54320
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3215553584-0
                                                                                                                                                                                                              • Opcode ID: 2072840c731903ab9ed2d0e336d6e3b3477313bb5cf3c8f9750581c4cd4e8c29
                                                                                                                                                                                                              • Instruction ID: aa45ba38ceaacb4e0f7d622e73aaebf5c7ff3df976eedd58c8d4bca44b742a19
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 2072840c731903ab9ed2d0e336d6e3b3477313bb5cf3c8f9750581c4cd4e8c29
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 6F41C67290C64187EAB4AB2DE540679B7A1EF67B40F900131D7AE576D9CF3CE482C760
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _fread_nolock
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 840049012-0
                                                                                                                                                                                                              • Opcode ID: 63af86d316915705a8fa2a3cf8f64119d6c223795c5089363200e084fe5ca5f9
                                                                                                                                                                                                              • Instruction ID: a90df266af9e0e3d5ff0d0b35afda754cc6dd2a372c6d9c265233fd7efd9e210
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 63af86d316915705a8fa2a3cf8f64119d6c223795c5089363200e084fe5ca5f9
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 8721A925B0C65146FA90B63A65447F5DA45BF56BDCFC84431EF4D17B4ACE3DE081C220
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3215553584-0
                                                                                                                                                                                                              • Opcode ID: bb97ccad92982b38df476f566c579dbeeb9f67f5901e23cab2fcf296bede837b
                                                                                                                                                                                                              • Instruction ID: 78dfff5e102826a93ef55498242e3c2dc1aa2144f4a97ea36ea39fe31293d248
                                                                                                                                                                                                              • Opcode Fuzzy Hash: bb97ccad92982b38df476f566c579dbeeb9f67f5901e23cab2fcf296bede837b
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 9F318B22E1C60285E7917B6D8841E7CA650AFA6B94F910135EB3D633DACF7CA4818730
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: HandleModule$AddressFreeLibraryProc
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3947729631-0
                                                                                                                                                                                                              • Opcode ID: da7d5aaa001a85c1e13054e7b60926c5ebf14781b4d980b1a631c30dc526fcea
                                                                                                                                                                                                              • Instruction ID: 5b54ee556a1da72bf399868ca29d778137aca228c07c52740d4dd3427b01778a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: da7d5aaa001a85c1e13054e7b60926c5ebf14781b4d980b1a631c30dc526fcea
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 59218D32E1970589EBA4AF78C4406AD73A0EF55718F840635DB2D26AEDEF38D885C750
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3215553584-0
                                                                                                                                                                                                              • Opcode ID: 0e1df9a836e05c53306103cf914f9f5afd0b17d2d4247778ac0f8a736a470cc7
                                                                                                                                                                                                              • Instruction ID: d4cbfd1e096a0f7f84f12e9a40bfb8cdff4b5e9f72361983be733188a119e1a0
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 0e1df9a836e05c53306103cf914f9f5afd0b17d2d4247778ac0f8a736a470cc7
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 1F118421A0C64182EAA0BF69D40097EE260EF67B80FD44431EBAC6778EDF3DD5918760
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3215553584-0
                                                                                                                                                                                                              • Opcode ID: 3767eff042e46cd651120d9163f396646e5b690a05a83219cc7a0fcdceb2a680
                                                                                                                                                                                                              • Instruction ID: 2cfdc35adf4f054675d9dab2274f53a5399c16a2fc16018ce8e6f9810cb8c570
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 3767eff042e46cd651120d9163f396646e5b690a05a83219cc7a0fcdceb2a680
                                                                                                                                                                                                              • Instruction Fuzzy Hash: F921B332A0C68287DBA1AF2CD440379B2A4AF96B94FA40335E76D576DDDF3CD4408B10
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3215553584-0
                                                                                                                                                                                                              • Opcode ID: 43297e0cb54a728217cf8f13d9f8c23c45e2da10c33361e46a2ef0799771412d
                                                                                                                                                                                                              • Instruction ID: 3b7cb7120d6e00d2754465552cf0fe4df2aca6df3da63202c43ed62c30c9956b
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 43297e0cb54a728217cf8f13d9f8c23c45e2da10c33361e46a2ef0799771412d
                                                                                                                                                                                                              • Instruction Fuzzy Hash: FB018621A0C74541ED84AB7A9900569D6A5BF66FE4BC84631EF6C237DECE3CD5818720
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • __scrt_dllmain_crt_thread_attach.LIBCMT ref: 00007FF7B35CC390
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35CCDB8: __vcrt_uninitialize_ptd.LIBVCRUNTIME ref: 00007FF7B35CCDC0
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35CCDB8: __vcrt_uninitialize_locks.LIBVCRUNTIME ref: 00007FF7B35CCDC5
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: __scrt_dllmain_crt_thread_attach__vcrt_uninitialize_locks__vcrt_uninitialize_ptd
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 1208906642-0
                                                                                                                                                                                                              • Opcode ID: 86517d9d3c6548b93fa1a500576de9512fe9d6a130677b1fbe86fe464c74cea3
                                                                                                                                                                                                              • Instruction ID: cf56bf78003734fd1f41f3931c5418909c9bfdd50561d3191e6c9b60485273bc
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 86517d9d3c6548b93fa1a500576de9512fe9d6a130677b1fbe86fe464c74cea3
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 5BE0B650D0D24381FEE9767929A22B896400F3770DFC100B9DB4E761CB9D4E30D795B1
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • HeapAlloc.KERNEL32(?,?,00000000,00007FF7B35DC1CA,?,?,?,00007FF7B35D5DF1,?,?,?,?,00007FF7B35DB332), ref: 00007FF7B35DFDF9
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: AllocHeap
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 4292702814-0
                                                                                                                                                                                                              • Opcode ID: c31ce9282523e7e70075863a15ee72f4cf677a1c6170370e1c64cff724d2af1b
                                                                                                                                                                                                              • Instruction ID: 34f820b9870271c069ee93691e5fd068009118f8058640429196c60b4b145a55
                                                                                                                                                                                                              • Opcode Fuzzy Hash: c31ce9282523e7e70075863a15ee72f4cf677a1c6170370e1c64cff724d2af1b
                                                                                                                                                                                                              • Instruction Fuzzy Hash: BBF04F40B0D20385FED47A7A5D11BB582905F6A740FC84430CB2DA62DEEE2CA4C04230
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • HeapAlloc.KERNEL32(?,?,?,00007FF7B35D0208,?,?,?,00007FF7B35D1872,?,?,?,?,?,00007FF7B35D4535), ref: 00007FF7B35DE6A2
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: AllocHeap
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 4292702814-0
                                                                                                                                                                                                              • Opcode ID: 3c31cf8336a648e9ecfad8ff9b709a6d49b8502715341f1fffc2c41753e32efa
                                                                                                                                                                                                              • Instruction ID: b0568bdf9c39c97f4883086e07fd3df3e6699ea2e4766748e287d8f4919750f4
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 3c31cf8336a648e9ecfad8ff9b709a6d49b8502715341f1fffc2c41753e32efa
                                                                                                                                                                                                              • Instruction Fuzzy Hash: ADF05E40E1D20244FAE47A7D6941A7992805FA6760FD80630DF3E652C9DE2CA4C0C171
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • GetProcAddress.KERNEL32(?,00007FF7B35C591F,00000000,00007FF7B35C272E), ref: 00007FF7B35C4C60
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,00007FF7B35C591F,00000000,00007FF7B35C272E), ref: 00007FF7B35C4C72
                                                                                                                                                                                                              • GetProcAddress.KERNEL32(?,00007FF7B35C591F,00000000,00007FF7B35C272E), ref: 00007FF7B35C4CA9
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,00007FF7B35C591F,00000000,00007FF7B35C272E), ref: 00007FF7B35C4CBB
                                                                                                                                                                                                              • GetProcAddress.KERNEL32(?,00007FF7B35C591F,00000000,00007FF7B35C272E), ref: 00007FF7B35C4CD4
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,00007FF7B35C591F,00000000,00007FF7B35C272E), ref: 00007FF7B35C4CE6
                                                                                                                                                                                                              • GetProcAddress.KERNEL32(?,00007FF7B35C591F,00000000,00007FF7B35C272E), ref: 00007FF7B35C4CFF
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,00007FF7B35C591F,00000000,00007FF7B35C272E), ref: 00007FF7B35C4D11
                                                                                                                                                                                                              • GetProcAddress.KERNEL32(?,00007FF7B35C591F,00000000,00007FF7B35C272E), ref: 00007FF7B35C4D2D
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,00007FF7B35C591F,00000000,00007FF7B35C272E), ref: 00007FF7B35C4D3F
                                                                                                                                                                                                              • GetProcAddress.KERNEL32(?,00007FF7B35C591F,00000000,00007FF7B35C272E), ref: 00007FF7B35C4D5B
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,00007FF7B35C591F,00000000,00007FF7B35C272E), ref: 00007FF7B35C4D6D
                                                                                                                                                                                                              • GetProcAddress.KERNEL32(?,00007FF7B35C591F,00000000,00007FF7B35C272E), ref: 00007FF7B35C4D89
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,00007FF7B35C591F,00000000,00007FF7B35C272E), ref: 00007FF7B35C4D9B
                                                                                                                                                                                                              • GetProcAddress.KERNEL32(?,00007FF7B35C591F,00000000,00007FF7B35C272E), ref: 00007FF7B35C4DB7
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,00007FF7B35C591F,00000000,00007FF7B35C272E), ref: 00007FF7B35C4DC9
                                                                                                                                                                                                              • GetProcAddress.KERNEL32(?,00007FF7B35C591F,00000000,00007FF7B35C272E), ref: 00007FF7B35C4DE5
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,00007FF7B35C591F,00000000,00007FF7B35C272E), ref: 00007FF7B35C4DF7
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: AddressErrorLastProc
                                                                                                                                                                                                              • String ID: Failed to get address for %hs$GetProcAddress$PyConfig_Clear$PyConfig_InitIsolatedConfig$PyConfig_Read$PyConfig_SetBytesString$PyConfig_SetString$PyConfig_SetWideStringList$PyErr_Clear$PyErr_Fetch$PyErr_NormalizeException$PyErr_Occurred$PyErr_Print$PyErr_Restore$PyEval_EvalCode$PyImport_AddModule$PyImport_ExecCodeModule$PyImport_ImportModule$PyMarshal_ReadObjectFromString$PyMem_RawFree$PyModule_GetDict$PyObject_CallFunction$PyObject_CallFunctionObjArgs$PyObject_GetAttrString$PyObject_SetAttrString$PyObject_Str$PyPreConfig_InitIsolatedConfig$PyRun_SimpleStringFlags$PyStatus_Exception$PySys_GetObject$PySys_SetObject$PyUnicode_AsUTF8$PyUnicode_Decode$PyUnicode_DecodeFSDefault$PyUnicode_FromFormat$PyUnicode_FromString$PyUnicode_Join$PyUnicode_Replace$Py_DecRef$Py_DecodeLocale$Py_ExitStatusException$Py_Finalize$Py_InitializeFromConfig$Py_IsInitialized$Py_PreInitialize
                                                                                                                                                                                                              • API String ID: 199729137-653951865
                                                                                                                                                                                                              • Opcode ID: d85cd9fcf26276e168e517ee9abf5ede364ec1e9effdf9a011e7fffbe194a537
                                                                                                                                                                                                              • Instruction ID: 3f4e54b08b5eee102e2018c2e949dbdf09048bb0fa34fcddc34e479b69fb4e0e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: d85cd9fcf26276e168e517ee9abf5ede364ec1e9effdf9a011e7fffbe194a537
                                                                                                                                                                                                              • Instruction Fuzzy Hash: A722D6B090DB1795FAC5BB7CA844674A3A1AF3674ABD40631C60E2566CEF3CB5C9C270
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo$memcpy_s$fegetenv
                                                                                                                                                                                                              • String ID: 1#IND$1#INF$1#QNAN$1#SNAN
                                                                                                                                                                                                              • API String ID: 808467561-2761157908
                                                                                                                                                                                                              • Opcode ID: dcc314a457104bdb667cbbd9859ad8e9c2a847357f7a40157f721af0dd0c9056
                                                                                                                                                                                                              • Instruction ID: 61122ec5057b923caf56fa8288e7fde4a3ac5bf16367f9edac2e4183aef3abed
                                                                                                                                                                                                              • Opcode Fuzzy Hash: dcc314a457104bdb667cbbd9859ad8e9c2a847357f7a40157f721af0dd0c9056
                                                                                                                                                                                                              • Instruction Fuzzy Hash: E8B2E872A1C2A28BE7A49E78D4407FDB7A1FF65384F901635DB0967A8CDB38E540CB50
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID: invalid bit length repeat$invalid code -- missing end-of-block$invalid code lengths set$invalid distance code$invalid distance too far back$invalid distances set$invalid literal/length code$invalid literal/lengths set$too many length or distance symbols
                                                                                                                                                                                                              • API String ID: 0-2665694366
                                                                                                                                                                                                              • Opcode ID: b821f53a202d8d869612a2403107f568f7f04b6f9c6dbaa081d11706b55d0279
                                                                                                                                                                                                              • Instruction ID: c5163e3038733d9631c454267ff74d5ef42dfa53b3bcc7b805a8160070f1eeeb
                                                                                                                                                                                                              • Opcode Fuzzy Hash: b821f53a202d8d869612a2403107f568f7f04b6f9c6dbaa081d11706b55d0279
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 7C521772A186A587E7949F28C458B7D7BA9FF55344F814139E74EA3784DB3CD880CB20
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ExceptionFilterPresentUnhandled$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3140674995-0
                                                                                                                                                                                                              • Opcode ID: 4c3f9a964b5662b5dbbc0689ef1495c1f66ffbf8daaed71a8dc58c0a28c42fd7
                                                                                                                                                                                                              • Instruction ID: dcead506e67cf08ca9f942f7d3d0838d01840d0401ea8bf3f398a402575b6927
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 4c3f9a964b5662b5dbbc0689ef1495c1f66ffbf8daaed71a8dc58c0a28c42fd7
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 56313476608B8189EBA49F64E8403EDB3A4FB95748F844139DB4D57B98DF38D588C720
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ExceptionFilterUnhandled$CaptureContextDebuggerEntryFunctionLookupPresentUnwindVirtual
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 1239891234-0
                                                                                                                                                                                                              • Opcode ID: c2ba82a54335b4e9d04d7430b1e7b135fe56bba1662feab656e26de9ce49381a
                                                                                                                                                                                                              • Instruction ID: 74a50e248cadf3325b2ca2d7e7da16509a01a088676f4e43290c3faf9478752c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: c2ba82a54335b4e9d04d7430b1e7b135fe56bba1662feab656e26de9ce49381a
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 92318F76608B8185EBA09F38E8406AEB3A0FF95758F800235EB9D57B58DF38C185CB10
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: FileFindFirst_invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2227656907-0
                                                                                                                                                                                                              • Opcode ID: 167224c4b3cc4c3efdc91e29f9533d8029eb5d88ba9d1f4f684eee253c955cc6
                                                                                                                                                                                                              • Instruction ID: 18dc887ae2cf39acf262e52a3733b2537c34743d9b7446dbfc9aa2bc2b861545
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 167224c4b3cc4c3efdc91e29f9533d8029eb5d88ba9d1f4f684eee253c955cc6
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 5AB1CA62B1C6A641EAA0FB39D5005B9A351EF6ABD4F845231DF5D27B8DDE3CE481C310
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2933794660-0
                                                                                                                                                                                                              • Opcode ID: d3533d9dc536a73865986143b90d72cf7f467817cff5a9e1fc853e7b0dbb7422
                                                                                                                                                                                                              • Instruction ID: d72639eedf9e423eeb7188ebcccde0e848cc62941b55f042ab136a7476c2298a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: d3533d9dc536a73865986143b90d72cf7f467817cff5a9e1fc853e7b0dbb7422
                                                                                                                                                                                                              • Instruction Fuzzy Hash: E1119162B18F0189EB40DF74E8552B873A0FB29758F800E30DB6D56768DF7CD0988350
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: memcpy_s
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 1502251526-0
                                                                                                                                                                                                              • Opcode ID: b41cb84a548d2e61bdeb7bb10330278f5fecde395d7a0ce6ff99175555b28b3c
                                                                                                                                                                                                              • Instruction ID: 96a05ee299107a6e15453e8f314799c8448de5ac2c354af9279934e3a06800f2
                                                                                                                                                                                                              • Opcode Fuzzy Hash: b41cb84a548d2e61bdeb7bb10330278f5fecde395d7a0ce6ff99175555b28b3c
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 64C11472B1C29687E764DF29A04466AF791FBA5B84F808234DB4A5378CDB3DF841CB40
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID: $header crc mismatch$unknown header flags set
                                                                                                                                                                                                              • API String ID: 0-1127688429
                                                                                                                                                                                                              • Opcode ID: 69f7c752826ced8c5928def6f82431f123fb005599f15c6df2b2ad3acda2252f
                                                                                                                                                                                                              • Instruction ID: 855aaee9bc3b6cad0eb979c208cb3a84e43e09d73851c38148d35b2b6f847e99
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 69f7c752826ced8c5928def6f82431f123fb005599f15c6df2b2ad3acda2252f
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 4CF1A87261C3D54BE7D5AB28C088A3ABAE9FF66748F854538DB4D67394CB38D480C760
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ExceptionRaise_clrfp
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 15204871-0
                                                                                                                                                                                                              • Opcode ID: cc6ff36f15a987c5b1bf507e00e0aa7011c6f5d0d309d4bd8392734804a295b4
                                                                                                                                                                                                              • Instruction ID: 1e96afbac60659d88bd6891c43fd0ea19285d1c41305eda5cfc5426453ffcd39
                                                                                                                                                                                                              • Opcode Fuzzy Hash: cc6ff36f15a987c5b1bf507e00e0aa7011c6f5d0d309d4bd8392734804a295b4
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 55B14773608B98CAE7558F3DC4463687BA0FB55B48F158A21DB5D837A8CB39D891C710
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID: $
                                                                                                                                                                                                              • API String ID: 0-227171996
                                                                                                                                                                                                              • Opcode ID: 0021d0b55369085dcf1ff5482033bdc548e1137304a7c6608840e23669f70ad1
                                                                                                                                                                                                              • Instruction ID: 0dcc2ac56d3ba09ed99d247e95ce4f2afcb07d07a5b898f22d31468a902d89ba
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 0021d0b55369085dcf1ff5482033bdc548e1137304a7c6608840e23669f70ad1
                                                                                                                                                                                                              • Instruction Fuzzy Hash: C1E1E8B294C64242EBA4AE3DD05093DA3A0FF66B48F944135CB6E23798CF29F8C1C750
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID: incorrect header check$invalid window size
                                                                                                                                                                                                              • API String ID: 0-900081337
                                                                                                                                                                                                              • Opcode ID: 768132f209fad99936151e5971b7a71c7f1c569ad84797471c6492c5d3e51a18
                                                                                                                                                                                                              • Instruction ID: 56c8ccc30fd5c1f11593b9149dd53ec3242beb562c63b94e06cd5315a7a593f6
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 768132f209fad99936151e5971b7a71c7f1c569ad84797471c6492c5d3e51a18
                                                                                                                                                                                                              • Instruction Fuzzy Hash: FF91CB72A0C2C547E7E49A28C448B7E7AA9FF55358FD14139DB4D67788CB38E580CB60
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID: e+000$gfff
                                                                                                                                                                                                              • API String ID: 0-3030954782
                                                                                                                                                                                                              • Opcode ID: 8b6ee54fbb186269fe71b90b1026ad24f386125e73444afbdf5cadaf5bd6b187
                                                                                                                                                                                                              • Instruction ID: de61fba2b4b6679b5eba61c6458950dadeac8535a7bec1c289d58d0de734b17f
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 8b6ee54fbb186269fe71b90b1026ad24f386125e73444afbdf5cadaf5bd6b187
                                                                                                                                                                                                              • Instruction Fuzzy Hash: B3515C62B1C2C546E7649A3DE801B69F791EB56B94F88C231CBBC57AC9CE3DE4848710
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentFeaturePresentProcessProcessor
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 1010374628-0
                                                                                                                                                                                                              • Opcode ID: f284fe1203af8cb7ad24ccfe294dd2b258390ffea7df5946cb9025d6fe94c312
                                                                                                                                                                                                              • Instruction ID: 52361fddbf7396b056cd5f3c9edac870c21bc606a59f28ea670ae28baaef1438
                                                                                                                                                                                                              • Opcode Fuzzy Hash: f284fe1203af8cb7ad24ccfe294dd2b258390ffea7df5946cb9025d6fe94c312
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 3B02B121A0D66240FAE5FB3DD401279E695AF23B90FC54634DB6D6A2DADE3CA5C18330
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID: gfffffff
                                                                                                                                                                                                              • API String ID: 0-1523873471
                                                                                                                                                                                                              • Opcode ID: 1e22957b1159dd03df7ccd337d5a67203babfefd7ac1e182ea12ea91d3eef3d6
                                                                                                                                                                                                              • Instruction ID: 8c3ba79ced6c3736c1553bab32ad729825c0a8db5afb4db7a3a7d2c280fa2715
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 1e22957b1159dd03df7ccd337d5a67203babfefd7ac1e182ea12ea91d3eef3d6
                                                                                                                                                                                                              • Instruction Fuzzy Hash: AEA18762A0C78586EB61DF3D9400BA9B790EF62B84F858031DF5D57799DE3DE882C310
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID: TMP
                                                                                                                                                                                                              • API String ID: 3215553584-3125297090
                                                                                                                                                                                                              • Opcode ID: 99790e8c3e6fb60506200e2aa0b8d900239d419619a9b9dba0657c5dbd7d84e4
                                                                                                                                                                                                              • Instruction ID: 1b4ff7146a94b912484ac91a0a5090501530650fccda150404498efd67094d4c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 99790e8c3e6fb60506200e2aa0b8d900239d419619a9b9dba0657c5dbd7d84e4
                                                                                                                                                                                                              • Instruction Fuzzy Hash: BB517E11B0C24641FAE8BE3A950197AD291AF67F84FC84535DF2D6779EEE3CE4C18220
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: HeapProcess
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 54951025-0
                                                                                                                                                                                                              • Opcode ID: 8d8bf03bc1d3c2add78311a657f4b90d934f15b0b18570f2c87e070252fc9345
                                                                                                                                                                                                              • Instruction ID: bacfccf92d6c16bdf736e615069b53f3f5ba42a454eeea1ea64ae37206dce7aa
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 8d8bf03bc1d3c2add78311a657f4b90d934f15b0b18570f2c87e070252fc9345
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 3CB09220E1BA02CAEA887B696C8222463A57F69701FD84138C60C61324EE2C21EA5721
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID:
                                                                                                                                                                                                              • Opcode ID: 452a8a0d8feebdf1122eaccf447c44c0daa3d090f9a155463ed8f505442a48ba
                                                                                                                                                                                                              • Instruction ID: fc5681de844b02e10559cc564593a05480b59a0e5640bb300ea5d8275d2a3b38
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 452a8a0d8feebdf1122eaccf447c44c0daa3d090f9a155463ed8f505442a48ba
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 16E1C5A694C24242EBA4AA3D914093DA7A1FF62B44F944135CF6D2B79CCF39F8D1C720
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID:
                                                                                                                                                                                                              • Opcode ID: c1d7b7b3454c8bcad5c9b4cf135b982f8fa5d1e780f0237f0391cdb5e6506841
                                                                                                                                                                                                              • Instruction ID: 302ab8dbbc1bb2a3a5a70032453c6f8ff7477fda2398f90ceea4c91b71c4aae4
                                                                                                                                                                                                              • Opcode Fuzzy Hash: c1d7b7b3454c8bcad5c9b4cf135b982f8fa5d1e780f0237f0391cdb5e6506841
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 23E1C672A0C60285E7E4AA3CC554B78A7A1AF66744F944275CF6D272DDCF28E8C1C760
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID:
                                                                                                                                                                                                              • Opcode ID: 5cd5c4a82e290d99fc75fabc4b345746dc03237e35c2450d1ffc439358ea8dbf
                                                                                                                                                                                                              • Instruction ID: 9660d78f29f595df7ce2936269b635248c6a6e356dceaf0f03dddf015e46e41c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 5cd5c4a82e290d99fc75fabc4b345746dc03237e35c2450d1ffc439358ea8dbf
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 0FD1EB32A0C64285EBA8AA3D8440A3DA790EF26B48F944175CF2D676EDDF3DD4C5C760
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID:
                                                                                                                                                                                                              • Opcode ID: 35751a9e422b3a2b47e876a48a130e726752458af00060ec1017eb4795a0a546
                                                                                                                                                                                                              • Instruction ID: 316ad395252c70bf5ad41fc4d5b5cc46c1c81d618503534d4005e535473890bb
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 35751a9e422b3a2b47e876a48a130e726752458af00060ec1017eb4795a0a546
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 16C1A9722141E14BD289EB29E46A57B73E1F79938DBC4803AEF8B47B85C63CE054D721
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID:
                                                                                                                                                                                                              • Opcode ID: f16fb8a4f792395a96249c32a5e1723cb20c7f6a9977c10f3922fef282cb15bd
                                                                                                                                                                                                              • Instruction ID: 5957e1231c09985ef3cf0093d795d34ec4d38505d6eaae8f0e12ec6f8f9b8d5c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: f16fb8a4f792395a96249c32a5e1723cb20c7f6a9977c10f3922fef282cb15bd
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 78B17C72A0C74995E7A4AF39C060A2DBBA0EF66B48F984135CB5D67399CF29D480C760
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID:
                                                                                                                                                                                                              • Opcode ID: 67ea6f0edc2c58364f58995ddce025b390f3c278012a74096240329ea132a1c8
                                                                                                                                                                                                              • Instruction ID: 9ad87cc457cf4ac6f90507d07755bf2337805bd28689d3935a1382b669633f6c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 67ea6f0edc2c58364f58995ddce025b390f3c278012a74096240329ea132a1c8
                                                                                                                                                                                                              • Instruction Fuzzy Hash: A2B18D7290C78995E7A59F3D805063CBBA0EB6AB48FA40135CF5E67399CF69D4C1C720
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID:
                                                                                                                                                                                                              • Opcode ID: 847d6bf65b96cba8c7d30e9d62c328f88bdcc6dffd0926808ea1049b5e5cea66
                                                                                                                                                                                                              • Instruction ID: ef755aba39ec949aee8b60c816d9fa5741ed9f04037f1f0e8f7a503878c2ed93
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 847d6bf65b96cba8c7d30e9d62c328f88bdcc6dffd0926808ea1049b5e5cea66
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 6081E572A0C78186D7A4DB3DA840B69AB90FF56794F904235DBAD53B9DCF3CD4808B10
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3215553584-0
                                                                                                                                                                                                              • Opcode ID: 2bdfc0d2ab862e9cd35af8ac59e49a170fecad67048bd66347de651b0e282819
                                                                                                                                                                                                              • Instruction ID: 66ca7bda971b8fd65ba1a09429bba96f6cbf1d46399130d4804245d086ca4f2d
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 2bdfc0d2ab862e9cd35af8ac59e49a170fecad67048bd66347de651b0e282819
                                                                                                                                                                                                              • Instruction Fuzzy Hash: E3610A26E0C1A246F7E4AA3C845063DE689EF72364FD50335D72DA66DCDE7DE8808720
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID:
                                                                                                                                                                                                              • Opcode ID: 27099d1c67046ba5536a5c52bb1b19252402c8bb4a5167aa336477e7b6d5f807
                                                                                                                                                                                                              • Instruction ID: cab53136bfe34c13cfd679ad004bed99fe6c70c088863838169dd7c42611d7ed
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 27099d1c67046ba5536a5c52bb1b19252402c8bb4a5167aa336477e7b6d5f807
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 93518236A1C65182E7E49B3DC040A2CB7A1EF66B58F644131CB5D27B98CF3AE983C750
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID:
                                                                                                                                                                                                              • Opcode ID: 8e69dfdcc94a0aa650623f7423aa354004c1f2fa01d5c1268249020d4c21f447
                                                                                                                                                                                                              • Instruction ID: b5d280c66d2289d39841fc45aad51fee79e49d1e4744b03e990ffa261924b5a1
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 8e69dfdcc94a0aa650623f7423aa354004c1f2fa01d5c1268249020d4c21f447
                                                                                                                                                                                                              • Instruction Fuzzy Hash: DD519536A1C65181E7E49B3DC05063873A1EF66B58F644131CB6D277A8CF3AE983C790
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID:
                                                                                                                                                                                                              • Opcode ID: 68a3f5aab59b2fac328bd6ba34d5b1cd1fa94c6914f84dc4a79da3b9d8ff9a98
                                                                                                                                                                                                              • Instruction ID: 42298e29decf4c1e16cd66f3b3a1f54e01268e49e3b3de76e1fe17cd5cacfb1c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 68a3f5aab59b2fac328bd6ba34d5b1cd1fa94c6914f84dc4a79da3b9d8ff9a98
                                                                                                                                                                                                              • Instruction Fuzzy Hash: B851B932A1C65682E7A49B3DD0406787360EF66B68F744131CF5D27798CB3AE983C760
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID:
                                                                                                                                                                                                              • Opcode ID: 7710b6301a9c53c0f35ccf6fc131232db227f89fb6367f1206a3fe51f4b04988
                                                                                                                                                                                                              • Instruction ID: a307b9b5a5919da025bbef3b82e9536cf0031cca73d28c95bd6a295569ade9d5
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 7710b6301a9c53c0f35ccf6fc131232db227f89fb6367f1206a3fe51f4b04988
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 7251B936A1C65186E7E49F3DC040A3867A0EF56B58F644131CF5D27798CF3AE982CB90
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID:
                                                                                                                                                                                                              • Opcode ID: 3b300af1d1946d5df55db44b3d4e0876ae34829a82d49cb6751e26c04e9c1898
                                                                                                                                                                                                              • Instruction ID: 3a71ec2519a02db1e7536e92ecd7dd696e263c4ed5e0a98c521bbb4dbe5ca849
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 3b300af1d1946d5df55db44b3d4e0876ae34829a82d49cb6751e26c04e9c1898
                                                                                                                                                                                                              • Instruction Fuzzy Hash: BF519832A1C65586E7A4AB3DC44063977A0EF56B58FA54131CF5C2779CCB3AE883C760
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID:
                                                                                                                                                                                                              • Opcode ID: 7c9c7dfd85d7e05c9dc9b7e40d932aad9843605f203f1a6a08d3cc10701c718b
                                                                                                                                                                                                              • Instruction ID: fcd922f7b6bac65b5f082fa514f467678dbfd5a750416b251c79a0214e3b6e82
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 7c9c7dfd85d7e05c9dc9b7e40d932aad9843605f203f1a6a08d3cc10701c718b
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 3151B332A1C69186E7E49B7DC040A38A7B0EF66B58F644131CF5D67798CB3AE982C750
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID:
                                                                                                                                                                                                              • Opcode ID: dde3b7cfbcf26fc8d7513faefc9a59c4b8821272907dfbb35b6db6355186da00
                                                                                                                                                                                                              • Instruction ID: 114c16c0025f09226d22e1c4a7a1d2c949a2136afb5b1016901feadebd810742
                                                                                                                                                                                                              • Opcode Fuzzy Hash: dde3b7cfbcf26fc8d7513faefc9a59c4b8821272907dfbb35b6db6355186da00
                                                                                                                                                                                                              • Instruction Fuzzy Hash: F5419D5284E78A15E9D5A97C8500AB8AA80DF33BA0DD812B0CFB9773DFCD0D25D78220
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ErrorFreeHeapLast
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 485612231-0
                                                                                                                                                                                                              • Opcode ID: 8ebaae5e878847fb0972dee39ef615be72aee41a86628d284291b13d6747971f
                                                                                                                                                                                                              • Instruction ID: 3721856f6ef4a8fc5065471364037c830bb3de7c6ded8a518d72da810b68939f
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 8ebaae5e878847fb0972dee39ef615be72aee41a86628d284291b13d6747971f
                                                                                                                                                                                                              • Instruction Fuzzy Hash: DF411762B18A5581FF44DF3AD955569B3A2FB59FC4B489032DF1DA7B58DE3CD0818300
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID:
                                                                                                                                                                                                              • Opcode ID: 3b4b82ba6feb1f2c625fcdd7b78fc6310e7e433b3778e25011fb45a65c2c329c
                                                                                                                                                                                                              • Instruction ID: 8da4f981e3a0b357d4f2ac000ee51332990ec3b6926cf4f6b1b3037e16195224
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 3b4b82ba6feb1f2c625fcdd7b78fc6310e7e433b3778e25011fb45a65c2c329c
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 2231B73170CB4142E794EF39B44053DB695AF96B90F544238EBADA3B9ADF3CD1818714
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID:
                                                                                                                                                                                                              • Opcode ID: 00e5edaf8da66d94c9ca9aff6d9c04a456296df9a737362746998e6ef114c740
                                                                                                                                                                                                              • Instruction ID: 26f25f918c33f9e54576837d911303460cad33b4265814573dba1b013f77f8c5
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 00e5edaf8da66d94c9ca9aff6d9c04a456296df9a737362746998e6ef114c740
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 7EF044716282958AEBD8DF3DB44362977E1E7183C4B908039D78987A08D67C94908F14
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID:
                                                                                                                                                                                                              • Opcode ID: c92d020b70be0a3987cc02b3edb33e09e79c2d1aa04247a81d94d631aa8b8d9b
                                                                                                                                                                                                              • Instruction ID: 91bb23b98bc009ed922567c4d2b5d6a8606158dff42d0f40050a64fe72a151f7
                                                                                                                                                                                                              • Opcode Fuzzy Hash: c92d020b70be0a3987cc02b3edb33e09e79c2d1aa04247a81d94d631aa8b8d9b
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 4DA0016190C812D4F684AB28A964021A3A1BF62304BC00135D21E650A89F6CA4868260
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: AddressErrorLastProc
                                                                                                                                                                                                              • String ID: Failed to get address for %hs$GetProcAddress$Tcl_Alloc$Tcl_ConditionFinalize$Tcl_ConditionNotify$Tcl_ConditionWait$Tcl_CreateInterp$Tcl_CreateObjCommand$Tcl_CreateThread$Tcl_DeleteInterp$Tcl_DoOneEvent$Tcl_EvalEx$Tcl_EvalFile$Tcl_EvalObjv$Tcl_Finalize$Tcl_FinalizeThread$Tcl_FindExecutable$Tcl_Free$Tcl_GetCurrentThread$Tcl_GetObjResult$Tcl_GetString$Tcl_GetVar2$Tcl_Init$Tcl_JoinThread$Tcl_MutexFinalize$Tcl_MutexLock$Tcl_MutexUnlock$Tcl_NewByteArrayObj$Tcl_NewStringObj$Tcl_SetVar2$Tcl_SetVar2Ex$Tcl_ThreadAlert$Tcl_ThreadQueueEvent$Tk_GetNumMainWindows$Tk_Init
                                                                                                                                                                                                              • API String ID: 199729137-3427451314
                                                                                                                                                                                                              • Opcode ID: 3bd3e37efd012c8e2e3270f1ddacdcfc1e24b7bb52a0dbabcea0a7cbd221c97c
                                                                                                                                                                                                              • Instruction ID: 83117089878978b256e32507f0dbbd72d3ddd2fe4283d1b94b0fe4eab23d8a5c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 3bd3e37efd012c8e2e3270f1ddacdcfc1e24b7bb52a0dbabcea0a7cbd221c97c
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 5502BB6490DB1795FAC4FB7CBC54174A3A1AF6674ABD90235C60E2526CEF3CA6C9C230
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C88F0: MultiByteToWideChar.KERNEL32(?,?,?,00007FF7B35C3A14,00000000,00007FF7B35C1965), ref: 00007FF7B35C8929
                                                                                                                                                                                                              • ExpandEnvironmentStringsW.KERNEL32(00000000,00007FF7B35C7B07,FFFFFFFF,00000000,?,00007FF7B35C3101), ref: 00007FF7B35C767C
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ByteCharEnvironmentExpandMultiStringsWide
                                                                                                                                                                                                              • String ID: %.*s$CreateDirectory$LOADER: failed to convert runtime-tmpdir to a wide string.$LOADER: failed to create runtime-tmpdir path %ls!$LOADER: failed to expand environment variables in the runtime-tmpdir.$LOADER: failed to obtain the absolute path of the runtime-tmpdir.$LOADER: runtime-tmpdir points to non-existent drive %ls (type: %d)!$\
                                                                                                                                                                                                              • API String ID: 2001182103-930877121
                                                                                                                                                                                                              • Opcode ID: 8054c3c0650854d0b40b7a035891c415250060ac884c921d421b6e0c89ed4a50
                                                                                                                                                                                                              • Instruction ID: 52714e11fa4850ae78087ba7d0b379994f365ec3b46adb8aa768d9027b3f2d5b
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 8054c3c0650854d0b40b7a035891c415250060ac884c921d421b6e0c89ed4a50
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 1F51A925A2C64245FAD0F73DD8516B9E295AFB6788FC40432D70E66A9DEE3CE184C370
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: LongWindow$BlockCreateErrorLastReasonShutdown
                                                                                                                                                                                                              • String ID: Needs to remove its temporary files.
                                                                                                                                                                                                              • API String ID: 3975851968-2863640275
                                                                                                                                                                                                              • Opcode ID: 11bce47d0d0e64839e27bb7d3290e638deefce497560f6bcecbf4d4959fd4dcd
                                                                                                                                                                                                              • Instruction ID: 91594da8975f72a2ebbb28c8902b96b571c8eea124659fc5734b6edb2e03df8f
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 11bce47d0d0e64839e27bb7d3290e638deefce497560f6bcecbf4d4959fd4dcd
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 0321D869B0CA428AE7C5AB3DE444178A394EF9AB94FC84230DF1D5779DDE2CD5C48230
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID: -$:$f$p$p
                                                                                                                                                                                                              • API String ID: 3215553584-2013873522
                                                                                                                                                                                                              • Opcode ID: 65d4a0ffdc8e7253b8e60b637b85ac8f97459ea152ba9c8238927d2e88e0f15e
                                                                                                                                                                                                              • Instruction ID: fe4ce6d8f95249a9988d8885ced422528d7b1865fae9b47a56326bfcba6cc8e8
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 65d4a0ffdc8e7253b8e60b637b85ac8f97459ea152ba9c8238927d2e88e0f15e
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 8312806AE0C14386FBA0BE2CD044A79A699EF62750FC44435D7B9666CCDB3CE5C0CB21
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID: f$f$p$p$f
                                                                                                                                                                                                              • API String ID: 3215553584-1325933183
                                                                                                                                                                                                              • Opcode ID: fc8e2330ab6ced16bd3d959f6bc8057a9fc686b659d09149717256120edd57c1
                                                                                                                                                                                                              • Instruction ID: ad94b73a3369dc979e4cb87cf167b27ad86111c558570b04b930139c4631668e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: fc8e2330ab6ced16bd3d959f6bc8057a9fc686b659d09149717256120edd57c1
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 73129361A0C14B85FBA07B29E054A79E261EF62758FD44131D7AA676CCDF3CE9C09B30
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentProcess
                                                                                                                                                                                                              • String ID: Failed to extract %s: failed to allocate data buffer (%u bytes)!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$fread$fseek$malloc
                                                                                                                                                                                                              • API String ID: 2050909247-3659356012
                                                                                                                                                                                                              • Opcode ID: f535e673c39ac7ce9a6c386ce8e3b8af4a7a4b48d33bece56dc0cc43f4b89150
                                                                                                                                                                                                              • Instruction ID: 947e6985fcb900989e2b307ae3c6231d2a0511475821ce227a59de5aea52a3eb
                                                                                                                                                                                                              • Opcode Fuzzy Hash: f535e673c39ac7ce9a6c386ce8e3b8af4a7a4b48d33bece56dc0cc43f4b89150
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 90417361A0C69246EA80FB3998046B9E291FF66BC8FD44532DF0C2779DDE3CE5858770
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentProcess
                                                                                                                                                                                                              • String ID: Failed to extract %s: failed to allocate data buffer (%u bytes)!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$fread$fseek$malloc
                                                                                                                                                                                                              • API String ID: 2050909247-3659356012
                                                                                                                                                                                                              • Opcode ID: 7b0bb8b84d757510e3b332b54b324784eea265275007ec901ab666ec5f3dc4c4
                                                                                                                                                                                                              • Instruction ID: fa3c0ee27dbb9421933613d3e3119414e96562073457b4a992a43741a708c9db
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 7b0bb8b84d757510e3b332b54b324784eea265275007ec901ab666ec5f3dc4c4
                                                                                                                                                                                                              • Instruction Fuzzy Hash: AF419231A0C64245EA80FB39D4405B9A390EF66788FC44532EF4D27B9EDE3CE6858B70
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: BlockFrameHandler3::Unwind$CatchExecutionHandlerIs_bad_exception_allowedSearchStatestd::bad_alloc::bad_alloc
                                                                                                                                                                                                              • String ID: csm$csm$csm
                                                                                                                                                                                                              • API String ID: 849930591-393685449
                                                                                                                                                                                                              • Opcode ID: a729206dc09f3ae888f69fb8db1d25833570b00ee2d7cb806a54919031002ad3
                                                                                                                                                                                                              • Instruction ID: c63df62f07f4dffe8bbca9dcd83a2cc363eecc2882dba259c38fc49aa7d3bed4
                                                                                                                                                                                                              • Opcode Fuzzy Hash: a729206dc09f3ae888f69fb8db1d25833570b00ee2d7cb806a54919031002ad3
                                                                                                                                                                                                              • Instruction Fuzzy Hash: B0D18E6290C64186EBA0AB7D94403ADA7A0FF6678DF800135EF8D67799CF38E0D5C760
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • GetCurrentProcessId.KERNEL32(?,?,?,?,?,?,?,?,00007FF7B35C2AC6,?,00007FF7B35C2BC5), ref: 00007FF7B35C2360
                                                                                                                                                                                                              • FormatMessageW.KERNEL32(?,?,?,?,?,?,?,?,00007FF7B35C2AC6,?,00007FF7B35C2BC5), ref: 00007FF7B35C241A
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentFormatMessageProcess
                                                                                                                                                                                                              • String ID: %ls$%ls: $<FormatMessageW failed.>$[PYI-%d:ERROR]
                                                                                                                                                                                                              • API String ID: 27993502-4247535189
                                                                                                                                                                                                              • Opcode ID: 5c54806743b5fc5ca5748e300e790daf69093409d5698ed67d8ea85ca9e7f6b1
                                                                                                                                                                                                              • Instruction ID: efc585ebfe3291b09a6a33ead807bbe4649d362b7a6875cd6fc9f43973c6ce2a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 5c54806743b5fc5ca5748e300e790daf69093409d5698ed67d8ea85ca9e7f6b1
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 95312572B0C64141E660B739B8106EAA2A1BF95BC8FC00131EF4D67A5DDE3CE286C320
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • LoadLibraryExW.KERNEL32(?,?,?,00007FF7B35CD4AA,?,?,?,00007FF7B35CD19C,?,?,?,00007FF7B35CCD99), ref: 00007FF7B35CD27D
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,00007FF7B35CD4AA,?,?,?,00007FF7B35CD19C,?,?,?,00007FF7B35CCD99), ref: 00007FF7B35CD28B
                                                                                                                                                                                                              • LoadLibraryExW.KERNEL32(?,?,?,00007FF7B35CD4AA,?,?,?,00007FF7B35CD19C,?,?,?,00007FF7B35CCD99), ref: 00007FF7B35CD2B5
                                                                                                                                                                                                              • FreeLibrary.KERNEL32(?,?,?,00007FF7B35CD4AA,?,?,?,00007FF7B35CD19C,?,?,?,00007FF7B35CCD99), ref: 00007FF7B35CD323
                                                                                                                                                                                                              • GetProcAddress.KERNEL32(?,?,?,00007FF7B35CD4AA,?,?,?,00007FF7B35CD19C,?,?,?,00007FF7B35CCD99), ref: 00007FF7B35CD32F
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Library$Load$AddressErrorFreeLastProc
                                                                                                                                                                                                              • String ID: api-ms-
                                                                                                                                                                                                              • API String ID: 2559590344-2084034818
                                                                                                                                                                                                              • Opcode ID: cfe7c3e8e36681254bad5299873ee692e307dc20b52bfdb0e9be079fe62a9b1d
                                                                                                                                                                                                              • Instruction ID: 4b28a223cbaebbda24cb633a16e10538d10f929dd8839fda75b58e70a8444368
                                                                                                                                                                                                              • Opcode Fuzzy Hash: cfe7c3e8e36681254bad5299873ee692e307dc20b52bfdb0e9be079fe62a9b1d
                                                                                                                                                                                                              • Instruction Fuzzy Hash: B031D861A0E64190EE91AB2AA400575A3D4FF66BA8FD90535DF1DA7748EF3CE4C9C330
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentProcess
                                                                                                                                                                                                              • String ID: Failed to load Python DLL '%ls'.$LoadLibrary$Path of Python shared library (%s) and its name (%s) exceed buffer size (%d)$Path of ucrtbase.dll (%s) and its name exceed buffer size (%d)$Reported length (%d) of Python shared library name (%s) exceeds buffer size (%d)$ucrtbase.dll
                                                                                                                                                                                                              • API String ID: 2050909247-2434346643
                                                                                                                                                                                                              • Opcode ID: 8f8472b69da7ad2400b48cde234c674b4b334e3c1831ca79e191f0f0e614e6f1
                                                                                                                                                                                                              • Instruction ID: 0b222055d0d77214197108a2ccd08004cb5636c456e17c2a9c053fef6c86344a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 8f8472b69da7ad2400b48cde234c674b4b334e3c1831ca79e191f0f0e614e6f1
                                                                                                                                                                                                              • Instruction Fuzzy Hash: FE417231A1C68691EA91EB79E4441E9A361FF65348FC00132EB5D6369DDE3CE685C370
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Value$ErrorLast
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2506987500-0
                                                                                                                                                                                                              • Opcode ID: 0b20348f9c1a83954d0a053c40579325a412568fb84c9ff09bb00993ff3f795b
                                                                                                                                                                                                              • Instruction ID: a59e1dbf93f7914919a3b3f077111febf133dbc4a940292cb5ec45cff7676c4e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 0b20348f9c1a83954d0a053c40579325a412568fb84c9ff09bb00993ff3f795b
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 11217F20E0C25242F9D8B779A65553DD2928F667B0F984735DB3E2B6DEDE3CA4C14220
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ConsoleWrite$CloseCreateErrorFileHandleLast
                                                                                                                                                                                                              • String ID: CONOUT$
                                                                                                                                                                                                              • API String ID: 3230265001-3130406586
                                                                                                                                                                                                              • Opcode ID: 09dec002ca810f05fd5d7c823bfe6aa00a703a0ca75bfd1bbea9b479bbcb78f6
                                                                                                                                                                                                              • Instruction ID: de9dc6748eff2a5fab613d9e6f6ee9be483c3faa56295e455e3dbc0cdd0a0710
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 09dec002ca810f05fd5d7c823bfe6aa00a703a0ca75bfd1bbea9b479bbcb78f6
                                                                                                                                                                                                              • Instruction Fuzzy Hash: F6118461A1CA518AE390AB2AE854325F3A0FF6AFE4F940334DB1D97798CF3CD4848750
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • GetCurrentProcess.KERNEL32(?,?,00000000,00007FF7B35C33DE), ref: 00007FF7B35C834D
                                                                                                                                                                                                              • K32EnumProcessModules.KERNEL32(?,?,00000000,00007FF7B35C33DE), ref: 00007FF7B35C83AA
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C88F0: MultiByteToWideChar.KERNEL32(?,?,?,00007FF7B35C3A14,00000000,00007FF7B35C1965), ref: 00007FF7B35C8929
                                                                                                                                                                                                              • K32GetModuleFileNameExW.KERNEL32(?,?,00000000,00007FF7B35C33DE), ref: 00007FF7B35C8435
                                                                                                                                                                                                              • K32GetModuleFileNameExW.KERNEL32(?,?,00000000,00007FF7B35C33DE), ref: 00007FF7B35C8494
                                                                                                                                                                                                              • FreeLibrary.KERNEL32(?,?,00000000,00007FF7B35C33DE), ref: 00007FF7B35C84A5
                                                                                                                                                                                                              • FreeLibrary.KERNEL32(?,?,00000000,00007FF7B35C33DE), ref: 00007FF7B35C84BA
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: FileFreeLibraryModuleNameProcess$ByteCharCurrentEnumModulesMultiWide
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3462794448-0
                                                                                                                                                                                                              • Opcode ID: 637bc6f7c9f7680885116a859534d49be4f6c8cd185415c736321e4bb6400c1e
                                                                                                                                                                                                              • Instruction ID: 99e224521af89e4f9853c402625303ce2fbd4ebed12cdf1989161acafd4f6cec
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 637bc6f7c9f7680885116a859534d49be4f6c8cd185415c736321e4bb6400c1e
                                                                                                                                                                                                              • Instruction Fuzzy Hash: B041B562A1D68241EAB0AB25A5406FAB394FF56B88FC50135DF8D6778DDE3CE480C724
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,00007FF7B35D5DF1,?,?,?,?,00007FF7B35DB332,?,?,?,?,00007FF7B35D806B), ref: 00007FF7B35DC177
                                                                                                                                                                                                              • FlsSetValue.KERNEL32(?,?,?,00007FF7B35D5DF1,?,?,?,?,00007FF7B35DB332,?,?,?,?,00007FF7B35D806B), ref: 00007FF7B35DC1AD
                                                                                                                                                                                                              • FlsSetValue.KERNEL32(?,?,?,00007FF7B35D5DF1,?,?,?,?,00007FF7B35DB332,?,?,?,?,00007FF7B35D806B), ref: 00007FF7B35DC1DA
                                                                                                                                                                                                              • FlsSetValue.KERNEL32(?,?,?,00007FF7B35D5DF1,?,?,?,?,00007FF7B35DB332,?,?,?,?,00007FF7B35D806B), ref: 00007FF7B35DC1EB
                                                                                                                                                                                                              • FlsSetValue.KERNEL32(?,?,?,00007FF7B35D5DF1,?,?,?,?,00007FF7B35DB332,?,?,?,?,00007FF7B35D806B), ref: 00007FF7B35DC1FC
                                                                                                                                                                                                              • SetLastError.KERNEL32(?,?,?,00007FF7B35D5DF1,?,?,?,?,00007FF7B35DB332,?,?,?,?,00007FF7B35D806B), ref: 00007FF7B35DC217
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Value$ErrorLast
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2506987500-0
                                                                                                                                                                                                              • Opcode ID: 6aa970e24f5ca119c8451d38d23d2f51b6f731ec3ce752582579c637f9f4275c
                                                                                                                                                                                                              • Instruction ID: 4f08a4084a0462baaf68bbd3e6f313bcf9e133cacaf6905473495a31c2b8a69f
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 6aa970e24f5ca119c8451d38d23d2f51b6f731ec3ce752582579c637f9f4275c
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 7D116F20E0C25242F9D4B3B99651539E2929F667B0F940335DA3E6B7DEDE3CA4C14320
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: AddressFreeHandleLibraryModuleProc
                                                                                                                                                                                                              • String ID: CorExitProcess$mscoree.dll
                                                                                                                                                                                                              • API String ID: 4061214504-1276376045
                                                                                                                                                                                                              • Opcode ID: 418ea1e238ba9159b4af0c063643a1e1072a19be9fd93c352edfae4455fd553e
                                                                                                                                                                                                              • Instruction ID: 4d22086a4144b548a4eee85b48c8398d79a4362b782ab0932b2133eac9018cac
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 418ea1e238ba9159b4af0c063643a1e1072a19be9fd93c352edfae4455fd553e
                                                                                                                                                                                                              • Instruction Fuzzy Hash: C3F044A1A0DA0241EB546B38E4447399360AF6A7A1FD40735C76E592FCDF2CD189C320
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _set_statfp
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 1156100317-0
                                                                                                                                                                                                              • Opcode ID: bce21d2362216a5e504affcf34f2858e363de54600403cac3d1eeb36cb2ab404
                                                                                                                                                                                                              • Instruction ID: c9eb8f6112aa0cb23fef860a16ef69b74a6c36bf03379e224ed248e9be92216d
                                                                                                                                                                                                              • Opcode Fuzzy Hash: bce21d2362216a5e504affcf34f2858e363de54600403cac3d1eeb36cb2ab404
                                                                                                                                                                                                              • Instruction Fuzzy Hash: C011EF22E5CA2381FAE4357CD58533495616F77370FC54331EB3E262DE8E2CA8C08120
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • FlsGetValue.KERNEL32(?,?,?,00007FF7B35DB487,?,?,00000000,00007FF7B35DB722,?,?,?,?,?,00007FF7B35DB6AE), ref: 00007FF7B35DC24F
                                                                                                                                                                                                              • FlsSetValue.KERNEL32(?,?,?,00007FF7B35DB487,?,?,00000000,00007FF7B35DB722,?,?,?,?,?,00007FF7B35DB6AE), ref: 00007FF7B35DC26E
                                                                                                                                                                                                              • FlsSetValue.KERNEL32(?,?,?,00007FF7B35DB487,?,?,00000000,00007FF7B35DB722,?,?,?,?,?,00007FF7B35DB6AE), ref: 00007FF7B35DC296
                                                                                                                                                                                                              • FlsSetValue.KERNEL32(?,?,?,00007FF7B35DB487,?,?,00000000,00007FF7B35DB722,?,?,?,?,?,00007FF7B35DB6AE), ref: 00007FF7B35DC2A7
                                                                                                                                                                                                              • FlsSetValue.KERNEL32(?,?,?,00007FF7B35DB487,?,?,00000000,00007FF7B35DB722,?,?,?,?,?,00007FF7B35DB6AE), ref: 00007FF7B35DC2B8
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Value
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3702945584-0
                                                                                                                                                                                                              • Opcode ID: 55c2cfa3c6c0b66b4a1c6f957022f3ceea8d13f022cba7a3d54dd2efb067ed29
                                                                                                                                                                                                              • Instruction ID: a141eb7f2e91b8b5a452d46ba175cbde47ed936f9277344c8395b928873da2bf
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 55c2cfa3c6c0b66b4a1c6f957022f3ceea8d13f022cba7a3d54dd2efb067ed29
                                                                                                                                                                                                              • Instruction Fuzzy Hash: F3116010E0C20242F9D4B3BD9691579A1925F767B0F884334DABD367EEDE3CA4C14230
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Value
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3702945584-0
                                                                                                                                                                                                              • Opcode ID: ea3a9fca6980d96fa6a8d584e22936267001dce1870df9540930b962f91c0f75
                                                                                                                                                                                                              • Instruction ID: 811a6e40ab5c2a01e00a65b0e95f48279f6254ead9745a152aa53a1dd140c489
                                                                                                                                                                                                              • Opcode Fuzzy Hash: ea3a9fca6980d96fa6a8d584e22936267001dce1870df9540930b962f91c0f75
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 04111C10E4C25342F9E8B2BD985297992928F67774ED84734DB3E3A2DADD3CB4C14230
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID: verbose
                                                                                                                                                                                                              • API String ID: 3215553584-579935070
                                                                                                                                                                                                              • Opcode ID: 5742ae6ca51b03e9d6fd204cb41504e479b7e72b202bc53543779a715851f7d3
                                                                                                                                                                                                              • Instruction ID: de32a89c635df003e8d1096bc752c3e7f807bd95491845a7493d29b45bef695e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 5742ae6ca51b03e9d6fd204cb41504e479b7e72b202bc53543779a715851f7d3
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 5B91E326A0CA4641E7A0AE38D410B7DB399AF62B54FC44235DB79573CCDE3CE4858761
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID: UTF-16LEUNICODE$UTF-8$ccs
                                                                                                                                                                                                              • API String ID: 3215553584-1196891531
                                                                                                                                                                                                              • Opcode ID: 0f94fbfdb2a41be3f3cf5a79916f7e54565c06583a8995a71c4ffc2f48f318d6
                                                                                                                                                                                                              • Instruction ID: 205518c604b4c2e27237ed4024f6bb89f5f121e01c32a0e2aca7604ed0188e08
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 0f94fbfdb2a41be3f3cf5a79916f7e54565c06583a8995a71c4ffc2f48f318d6
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 8981A032E0C26285FAE46F3EC110278A6A0EF22B44FD54234DB597728DDB3DE9919731
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentImageNonwritableUnwind__except_validate_context_record
                                                                                                                                                                                                              • String ID: csm
                                                                                                                                                                                                              • API String ID: 2395640692-1018135373
                                                                                                                                                                                                              • Opcode ID: ef1879a6950a8d40b8b6b13be53b940b4e1f0e07f3723e86cdcfdad74941457a
                                                                                                                                                                                                              • Instruction ID: 9b1cce48093acf5fc1d915a3e77ddfb0675d663c4efea787743fb334347610d3
                                                                                                                                                                                                              • Opcode Fuzzy Hash: ef1879a6950a8d40b8b6b13be53b940b4e1f0e07f3723e86cdcfdad74941457a
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 3A51BF32A1D6428ADB94AB29E014678A791EF65B8CFD14131DB5E5778CDF3CE882C720
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CallEncodePointerTranslator
                                                                                                                                                                                                              • String ID: MOC$RCC
                                                                                                                                                                                                              • API String ID: 3544855599-2084237596
                                                                                                                                                                                                              • Opcode ID: 0008505033c860c887c654c4879225e67528ed16fc7c6c3a96efc88f305ea5d8
                                                                                                                                                                                                              • Instruction ID: 1a5daa323ea274fa6d8762836bf7d8a0010fbf8445bf5096acf6dfa42f6c7627
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 0008505033c860c887c654c4879225e67528ed16fc7c6c3a96efc88f305ea5d8
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 4B61947290CBC581D7609B29E4403AAF7A0FB95789F844225EB9C53799DF7CD1D4CB20
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Frame$EmptyHandler3::StateUnwind__except_validate_context_record
                                                                                                                                                                                                              • String ID: csm$csm
                                                                                                                                                                                                              • API String ID: 3896166516-3733052814
                                                                                                                                                                                                              • Opcode ID: 3d688b2030f6ff0abdfc3dd59f0c327938197cf645ae74c01235bdaf5d58afed
                                                                                                                                                                                                              • Instruction ID: 4d04eaa6aa4ea636a3a9643286d932eb05eaf3b7376e490359d4013fec02165b
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 3d688b2030f6ff0abdfc3dd59f0c327938197cf645ae74c01235bdaf5d58afed
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 6551903290C64286DAA4AB2D9444268F6A0FF66B89FD45135DB9D63789CF3CE4E0C760
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • GetCurrentProcessId.KERNEL32(FFFFFFFF,00000000,00000000,?,00000000,00007FF7B35C862F), ref: 00007FF7B35C226E
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentProcess
                                                                                                                                                                                                              • String ID: %ls$WARNING$[PYI-%d:%ls]
                                                                                                                                                                                                              • API String ID: 2050909247-3372507544
                                                                                                                                                                                                              • Opcode ID: 9a27952706b0edcce65802af7f1770e3887db089615dac0ef249cc8ca7ea00ce
                                                                                                                                                                                                              • Instruction ID: b8bcf530609fa060c953ba6b1e54e255d39660ee8910f45614f73a7dc08f6038
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 9a27952706b0edcce65802af7f1770e3887db089615dac0ef249cc8ca7ea00ce
                                                                                                                                                                                                              • Instruction Fuzzy Hash: BC21D362A0C74291E650AB68B4416EAB364FF957C4FC00136EF8D2765EDE3CE285C760
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: FileWrite$ConsoleErrorLastOutput
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2718003287-0
                                                                                                                                                                                                              • Opcode ID: ed63d01fdc9f0d7cd72e25070a387a5b046f77b67a2e02b147e50877afa29e90
                                                                                                                                                                                                              • Instruction ID: b91feff0d12b123f04a730d8358b1c331e6b572a87f362968c9022e9b991a0e7
                                                                                                                                                                                                              • Opcode Fuzzy Hash: ed63d01fdc9f0d7cd72e25070a387a5b046f77b67a2e02b147e50877afa29e90
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 8FD10372B0CA4089E751DF79D4406AC77B1FF66798B804225CF6DA7B99DE38E08AC350
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Window$Process$ConsoleCurrentShowThread
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 242035731-0
                                                                                                                                                                                                              • Opcode ID: ef1b52002b078da6e4bc146513f63fb1d7b490387893660315a42f1c57b8f302
                                                                                                                                                                                                              • Instruction ID: 6a41b6283a1ceb5a96a01b01ca4410a397946cd21d5c99ea352074d4063a218e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: ef1b52002b078da6e4bc146513f63fb1d7b490387893660315a42f1c57b8f302
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 7EF03761A2C74682EED46B79A444539A3A1EFAAB88F881034DA4E1775CDE3CF4D5C730
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Window$Process$ConsoleCurrentShowThread
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 242035731-0
                                                                                                                                                                                                              • Opcode ID: dc119808c190f3f609372cde833c1319ecd6838c5863d1c5dc0248c8f4992b64
                                                                                                                                                                                                              • Instruction ID: 149e4c930bd86ec912dc57192e7b91e66bc9b3d7448750a733ed960723967adf
                                                                                                                                                                                                              • Opcode Fuzzy Hash: dc119808c190f3f609372cde833c1319ecd6838c5863d1c5dc0248c8f4992b64
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 01F03761E2CB4292EAD46B3AA484039A3F1AF99B84F885134DA4E1665CDE3CF4D58630
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _get_daylight$_invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID: ?
                                                                                                                                                                                                              • API String ID: 1286766494-1684325040
                                                                                                                                                                                                              • Opcode ID: fffe139c3efa292f6124a3946bb52bccadd4f1441fdc513cd03e48c006c18545
                                                                                                                                                                                                              • Instruction ID: bd7371b23fe10d67e415c88be9bae730ced36dee21f02caba333da7f7168bb81
                                                                                                                                                                                                              • Opcode Fuzzy Hash: fffe139c3efa292f6124a3946bb52bccadd4f1441fdc513cd03e48c006c18545
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 90410812A0C2A251FBA4A739D50177A9660EFA2BE4F944335EF5C26ADDDE3CD4C1C710
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • _invalid_parameter_noinfo.LIBCMT ref: 00007FF7B35D9F22
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35DB404: RtlFreeHeap.NTDLL(?,?,?,00007FF7B35E3F32,?,?,?,00007FF7B35E3F6F,?,?,00000000,00007FF7B35E4435,?,?,?,00007FF7B35E4367), ref: 00007FF7B35DB41A
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35DB404: GetLastError.KERNEL32(?,?,?,00007FF7B35E3F32,?,?,?,00007FF7B35E3F6F,?,?,00000000,00007FF7B35E4435,?,?,?,00007FF7B35E4367), ref: 00007FF7B35DB424
                                                                                                                                                                                                              • GetModuleFileNameW.KERNEL32(?,?,?,?,?,00007FF7B35CC105), ref: 00007FF7B35D9F40
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ErrorFileFreeHeapLastModuleName_invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID: C:\Users\user\Desktop\main.exe
                                                                                                                                                                                                              • API String ID: 3580290477-1027480231
                                                                                                                                                                                                              • Opcode ID: 496cb20121ffb358d8bc6bcc3f9a42c329008a34e001e0b57ef52f5ac5fb1638
                                                                                                                                                                                                              • Instruction ID: b4503e2676542577a913179aa84535abc6f752b8293bcf3128080a40246ec98a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 496cb20121ffb358d8bc6bcc3f9a42c329008a34e001e0b57ef52f5ac5fb1638
                                                                                                                                                                                                              • Instruction Fuzzy Hash: DF41A032A0C71285EB95FF39E4814B9A3A5EF56B84B844035EB5D57B99DF3CE4C18320
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ErrorFileLastWrite
                                                                                                                                                                                                              • String ID: U
                                                                                                                                                                                                              • API String ID: 442123175-4171548499
                                                                                                                                                                                                              • Opcode ID: cb87ea1d99dc886f50d571e7adc08eb5a7dc8047dd93f89a11db01e9e971137a
                                                                                                                                                                                                              • Instruction ID: 7801d3d10cf8c1ab502aebb74c03c737caf6ae7df324fd625f7f76b66d57dec6
                                                                                                                                                                                                              • Opcode Fuzzy Hash: cb87ea1d99dc886f50d571e7adc08eb5a7dc8047dd93f89a11db01e9e971137a
                                                                                                                                                                                                              • Instruction Fuzzy Hash: C041C46261CA8181E7A0DF29E4447A9A7A0FFA5794F804131EF8D97758DF7CD485CB10
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • GetCurrentProcessId.KERNEL32(?,?,?,?,00000000,00000000,?,00000000,00007FF7B35C1B4A), ref: 00007FF7B35C2070
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentProcess
                                                                                                                                                                                                              • String ID: %s: %s$[PYI-%d:ERROR]
                                                                                                                                                                                                              • API String ID: 2050909247-3704582800
                                                                                                                                                                                                              • Opcode ID: cf9b01a4511ef92980d36f6eaa2bfca0541e126ccd784a3e4475787c2cf8d358
                                                                                                                                                                                                              • Instruction ID: 84bf1021f995aae638efaf06dd10d132d07308c7b92bcddf3b585e7b43a15d3b
                                                                                                                                                                                                              • Opcode Fuzzy Hash: cf9b01a4511ef92980d36f6eaa2bfca0541e126ccd784a3e4475787c2cf8d358
                                                                                                                                                                                                              • Instruction Fuzzy Hash: CC212672B1C68155E760A739B8416E6A294BF99BD8FC00132FF8D6374DDE3CD286C220
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentDirectory
                                                                                                                                                                                                              • String ID: :
                                                                                                                                                                                                              • API String ID: 1611563598-336475711
                                                                                                                                                                                                              • Opcode ID: 576b735185a232e7c4c7703006db41f83a331aa74a964717a1a8a85435f6eb25
                                                                                                                                                                                                              • Instruction ID: ed2e9bb668269af3e1cf28e934de2a6cc24fc852449f6942ff9417cc0b371cac
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 576b735185a232e7c4c7703006db41f83a331aa74a964717a1a8a85435f6eb25
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 1821E362A0C25181EBA0AB2AD44427DB3A1FFA9B44FC54135C79D23689CF7CD9C4C7B0
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • GetCurrentProcessId.KERNEL32(00000000,?,?,?,00000000,00007FF7B35C28DA,FFFFFFFF,00000000,00007FF7B35C3362), ref: 00007FF7B35C218E
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentProcess
                                                                                                                                                                                                              • String ID: WARNING$[PYI-%d:%s]
                                                                                                                                                                                                              • API String ID: 2050909247-3752221249
                                                                                                                                                                                                              • Opcode ID: 7d68ee11a32ffdc820f588c9092a71756a31bd868f965a857c73b3f1f744551a
                                                                                                                                                                                                              • Instruction ID: 7d2a4c54435e6530a33d464da1b16a119e85aa104f551191f8e14edd29c018a3
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 7d68ee11a32ffdc820f588c9092a71756a31bd868f965a857c73b3f1f744551a
                                                                                                                                                                                                              • Instruction Fuzzy Hash: AE11D172A0CB8141E660AB65B8816EAB3A4EF957C4F800131FBCD63A5DDE7CD2858720
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • GetCurrentProcessId.KERNEL32(?,00000000,00000000,?,00000000,00007FF7B35C1B79), ref: 00007FF7B35C1E9E
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentProcess
                                                                                                                                                                                                              • String ID: ERROR$[PYI-%d:%s]
                                                                                                                                                                                                              • API String ID: 2050909247-3005936843
                                                                                                                                                                                                              • Opcode ID: 62cbc377ad39f0f57ac113c1b5e744fc407643feec6e9a2503ac327b26b25e1c
                                                                                                                                                                                                              • Instruction ID: 42211835a5bade373c273f23bb90db599f08387dc6d4d7203d1fde77357c8508
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 62cbc377ad39f0f57ac113c1b5e744fc407643feec6e9a2503ac327b26b25e1c
                                                                                                                                                                                                              • Instruction Fuzzy Hash: C111D17260CB8141E660AB65B8816EAB3A4EF957C4F800131FBCD63A5DDE7CD2858710
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ExceptionFileHeaderRaise
                                                                                                                                                                                                              • String ID: csm
                                                                                                                                                                                                              • API String ID: 2573137834-1018135373
                                                                                                                                                                                                              • Opcode ID: 2d92b8b7d521df9494866c30e4ae755c0f7892732a35e9ef4a1741b3f71c7287
                                                                                                                                                                                                              • Instruction ID: 4579520f89e0b0035dcc66314e8d0a00ba1979f68e5a58ecc61383c4bab86312
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 2d92b8b7d521df9494866c30e4ae755c0f7892732a35e9ef4a1741b3f71c7287
                                                                                                                                                                                                              • Instruction Fuzzy Hash: E8110A36618B4182EB619B29E840259B7E4FB99B88F984230DF8D17758DF3CD591C710
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000000.00000002.1840488871.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840396759.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840534578.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840571670.00007FF7B3604000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000000.00000002.1840639129.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_0_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DriveType_invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID: :
                                                                                                                                                                                                              • API String ID: 2595371189-336475711
                                                                                                                                                                                                              • Opcode ID: bb470fc7cf78428f0d9dc0079e6dc4031c2c99e910ba5258b42cac156009a768
                                                                                                                                                                                                              • Instruction ID: eb1b9729abce603d8ffb33c7af445fef31f63ae5e51c004baea2bbe8fb36454e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: bb470fc7cf78428f0d9dc0079e6dc4031c2c99e910ba5258b42cac156009a768
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 3001716191C21286F7A0BF78946127EA2A0EF66708FC00535D75EA6689DF3CE6848734

                                                                                                                                                                                                              Execution Graph

                                                                                                                                                                                                              Execution Coverage:9.8%
                                                                                                                                                                                                              Dynamic/Decrypted Code Coverage:0%
                                                                                                                                                                                                              Signature Coverage:0%
                                                                                                                                                                                                              Total number of Nodes:1247
                                                                                                                                                                                                              Total number of Limit Nodes:105
                                                                                                                                                                                                              execution_graph 27081 7ffdfad45d80 27087 7ffdfad45db3 27081->27087 27082 7ffdfad45db8 27083 7ffdfad45e4a 27085 7ffdfad45e5d 27083->27085 27089 7ffdfad45eed 27083->27089 27084 7ffdfad45ddd 27086 7ffdfad45de6 _errno 27084->27086 27093 7ffdfad45df7 27084->27093 27095 7ffdfad45e67 27085->27095 27101 7ffdfada0280 27085->27101 27086->27093 27087->27082 27087->27083 27087->27084 27087->27086 27090 7ffdfad460a1 27089->27090 27091 7ffdfada0280 25 API calls 27089->27091 27090->27093 27116 7ffdfad75b50 TlsGetValue TlsGetValue 27090->27116 27094 7ffdfad45f1b 27091->27094 27096 7ffdfad46073 27094->27096 27099 7ffdfad45f8b 27094->27099 27113 7ffdfad53730 28 API calls 27094->27113 27096->27090 27115 7ffdfad75b50 TlsGetValue TlsGetValue 27096->27115 27099->27096 27114 7ffdfad912a0 26 API calls 27099->27114 27102 7ffdfada02ac TlsGetValue 27101->27102 27103 7ffdfada028d TlsAlloc 27101->27103 27105 7ffdfada02d7 27102->27105 27106 7ffdfada02c9 GetLastError 27102->27106 27103->27102 27111 7ffdfada02e1 27105->27111 27117 7ffdfad9fc10 27105->27117 27106->27105 27108 7ffdfada03c9 27108->27095 27109 7ffdfada0361 LeaveCriticalSection 27109->27108 27110 7ffdfada0377 GetProcessHeap HeapAlloc 27109->27110 27112 7ffdfada039d 27110->27112 27111->27108 27111->27109 27112->27108 27113->27099 27114->27099 27115->27090 27116->27093 27118 7ffdfad9fd49 27117->27118 27119 7ffdfad9fc2d 27117->27119 27122 7ffdfad9fd56 GetProcessHeap HeapAlloc 27118->27122 27123 7ffdfad9fdd1 27118->27123 27120 7ffdfad9fc36 InitializeCriticalSection 27119->27120 27121 7ffdfad9fc4d 27119->27121 27120->27121 27126 7ffdfad9fc67 malloc 27121->27126 27127 7ffdfad9fd3c LeaveCriticalSection 27121->27127 27124 7ffdfad9fd75 memset 27122->27124 27125 7ffdfad9fde4 27122->27125 27123->27111 27128 7ffdfaddfa00 27124->27128 27135 7ffdfad9fdf1 27125->27135 27129 7ffdfad9fc7e InitializeCriticalSection malloc 27126->27129 27126->27135 27127->27118 27130 7ffdfad9fd91 LeaveCriticalSection GetCurrentThreadId TlsSetValue 27128->27130 27131 7ffdfad9fca9 InitializeCriticalSection 27129->27131 27129->27135 27130->27123 27130->27135 27132 7ffdfad9fcd0 malloc 27131->27132 27134 7ffdfad9fd20 InitializeCriticalSection 27132->27134 27132->27135 27134->27127 27134->27132 27136 7ffdfad9fe21 TlsAlloc 27135->27136 27137 7ffdfad9fe40 TlsGetValue 27136->27137 27141 7ffdfad9ff44 27136->27141 27139 7ffdfad9fe6b 27137->27139 27140 7ffdfad9fe5d GetLastError 27137->27140 27142 7ffdfad9fe94 GetProcessHeap HeapAlloc 27139->27142 27140->27139 27140->27141 27143 7ffdfad9feb7 27142->27143 27143->27111 27144 7ff7b35d6584 27145 7ff7b35d65bb 27144->27145 27150 7ff7b35d659e 27144->27150 27146 7ff7b35d65ce CreateFileW 27145->27146 27145->27150 27147 7ff7b35d6602 27146->27147 27148 7ff7b35d6638 27146->27148 27153 7ff7b35d662d CloseHandle 27147->27153 27154 7ff7b35d6617 CloseHandle 27147->27154 27158 7ff7b35d6b60 10 API calls __CxxCallCatchBlock 27148->27158 27152 7ff7b35d65ab _invalid_parameter_noinfo 27150->27152 27151 7ff7b35d663d 27157 7ff7b35d6641 27151->27157 27159 7ff7b35d6920 _invalid_parameter_noinfo _invalid_parameter_noinfo 27151->27159 27155 7ff7b35d6659 27152->27155 27153->27155 27154->27155 27157->27155 27158->27151 27159->27157 27160 7ff7b35c2480 27161 7ff7b35c2490 27160->27161 27162 7ff7b35c24e1 27161->27162 27163 7ff7b35c24cb 27161->27163 27165 7ff7b35c2501 27162->27165 27174 7ff7b35c2517 27162->27174 27164 7ff7b35c1e50 36 API calls 27163->27164 27177 7ff7b35c24d7 27164->27177 27166 7ff7b35c1e50 36 API calls 27165->27166 27166->27177 27168 7ff7b35c269a 27170 7ff7b35c2706 27171 7ff7b35c1e50 36 API calls 27170->27171 27171->27177 27172 7ff7b35c26f0 27173 7ff7b35c1e50 36 API calls 27172->27173 27173->27177 27174->27170 27174->27172 27175 7ff7b35c26ca 27174->27175 27174->27177 27178 7ff7b35c26a7 27174->27178 27180 7ff7b35c1450 27174->27180 27176 7ff7b35c1e50 36 API calls 27175->27176 27176->27177 27204 7ff7b35cbab0 27177->27204 27196 7ff7b35c1e50 27178->27196 27210 7ff7b35c39e0 27180->27210 27183 7ff7b35c149c 27216 7ff7b35cfbcc 27183->27216 27184 7ff7b35c147b 27185 7ff7b35c1e50 36 API calls 27184->27185 27187 7ff7b35c148b 27185->27187 27187->27174 27188 7ff7b35c14b1 27189 7ff7b35c14b5 27188->27189 27190 7ff7b35c1518 27188->27190 27192 7ff7b35c152b 27188->27192 27230 7ff7b35cf544 27189->27230 27220 7ff7b35c11f0 27190->27220 27192->27189 27234 7ff7b35cf894 27192->27234 27195 7ff7b35c15a4 27195->27174 27197 7ff7b35cbdb0 27196->27197 27198 7ff7b35c1e74 GetCurrentProcessId 27197->27198 27199 7ff7b35c1ec5 27198->27199 27341 7ff7b35c1cc0 27199->27341 27202 7ff7b35cbab0 __CxxCallCatchBlock 3 API calls 27203 7ff7b35c1f1c 27202->27203 27203->27177 27205 7ff7b35cbab9 27204->27205 27206 7ff7b35cbac4 27205->27206 27207 7ff7b35cbe40 IsProcessorFeaturePresent 27205->27207 27206->27168 27208 7ff7b35cbe5f capture_previous_context __raise_securityfailure 27207->27208 27209 7ff7b35cbe58 27207->27209 27208->27168 27209->27208 27211 7ff7b35c39ec 27210->27211 27237 7ff7b35d6ef4 27211->27237 27213 7ff7b35c3a36 27214 7ff7b35cbab0 __CxxCallCatchBlock 3 API calls 27213->27214 27215 7ff7b35c1473 27214->27215 27215->27183 27215->27184 27217 7ff7b35cfbfc 27216->27217 27311 7ff7b35cf95c 27217->27311 27219 7ff7b35cfc15 27219->27188 27221 7ff7b35c1248 27220->27221 27222 7ff7b35c124f 27221->27222 27229 7ff7b35c1277 27221->27229 27223 7ff7b35c1e50 36 API calls 27222->27223 27224 7ff7b35c1262 27223->27224 27224->27189 27225 7ff7b35cf894 _fread_nolock 27 API calls 27225->27229 27226 7ff7b35c1291 27226->27189 27227 7ff7b35c13af 27228 7ff7b35c1e50 36 API calls 27227->27228 27228->27226 27229->27225 27229->27226 27229->27227 27231 7ff7b35cf574 27230->27231 27320 7ff7b35cf320 27231->27320 27233 7ff7b35cf58d 27233->27195 27329 7ff7b35cf8b4 27234->27329 27238 7ff7b35d6e28 27237->27238 27239 7ff7b35d6e4e 27238->27239 27241 7ff7b35d6e81 27238->27241 27240 7ff7b35d6e53 _invalid_parameter_noinfo 27239->27240 27242 7ff7b35d6e5e 27240->27242 27241->27242 27248 7ff7b35dbad0 27241->27248 27242->27213 27244 7ff7b35d6e9e 27244->27242 27253 7ff7b35e10dc 27244->27253 27246 7ff7b35d6ec8 27257 7ff7b35d6288 LeaveCriticalSection 27246->27257 27258 7ff7b35e14e8 EnterCriticalSection 27248->27258 27250 7ff7b35dbae7 27251 7ff7b35dbb44 EnterCriticalSection LeaveCriticalSection HeapFree GetLastError InitializeCriticalSectionAndSpinCount 27250->27251 27252 7ff7b35dbaf2 27251->27252 27252->27244 27254 7ff7b35e1102 27253->27254 27255 7ff7b35e1136 27254->27255 27259 7ff7b35e7f64 27254->27259 27255->27246 27262 7ff7b35e7564 27259->27262 27263 7ff7b35e757b 27262->27263 27264 7ff7b35e7599 27262->27264 27266 7ff7b35e7580 _invalid_parameter_noinfo 27263->27266 27264->27263 27265 7ff7b35e75b5 27264->27265 27271 7ff7b35e7b74 27265->27271 27269 7ff7b35e758e 27266->27269 27268 7ff7b35e75e0 27268->27269 27296 7ff7b35d93d4 LeaveCriticalSection 27268->27296 27269->27255 27272 7ff7b35e7bbb 27271->27272 27273 7ff7b35e7be9 27272->27273 27297 7ff7b35d93fc 27272->27297 27273->27268 27310 7ff7b35e14e8 EnterCriticalSection 27297->27310 27312 7ff7b35cf9c6 27311->27312 27313 7ff7b35cf986 27311->27313 27312->27313 27319 7ff7b35d627c EnterCriticalSection 27312->27319 27313->27219 27315 7ff7b35cf9d7 27316 7ff7b35cfae0 SetFilePointerEx GetLastError 27315->27316 27317 7ff7b35cf9e9 27316->27317 27318 7ff7b35d6288 _fread_nolock LeaveCriticalSection 27317->27318 27318->27313 27321 7ff7b35cf369 27320->27321 27327 7ff7b35cf33b 27320->27327 27321->27327 27328 7ff7b35d627c EnterCriticalSection 27321->27328 27323 7ff7b35cf380 27324 7ff7b35cf39c 7 API calls 27323->27324 27325 7ff7b35cf38c 27324->27325 27326 7ff7b35d6288 _fread_nolock LeaveCriticalSection 27325->27326 27326->27327 27327->27233 27330 7ff7b35cf8ac 27329->27330 27331 7ff7b35cf8de 27329->27331 27330->27192 27331->27330 27332 7ff7b35cf8ed 27331->27332 27333 7ff7b35cf92a 27331->27333 27337 7ff7b35cf902 _invalid_parameter_noinfo 27332->27337 27340 7ff7b35d627c EnterCriticalSection 27333->27340 27335 7ff7b35cf932 27336 7ff7b35cf634 _fread_nolock 24 API calls 27335->27336 27338 7ff7b35cf949 27336->27338 27337->27330 27339 7ff7b35d6288 _fread_nolock LeaveCriticalSection 27338->27339 27339->27330 27343 7ff7b35c1ccc 27341->27343 27342 7ff7b35c1d17 27345 7ff7b35cbab0 __CxxCallCatchBlock 3 API calls 27342->27345 27343->27342 27347 7ff7b35c1e00 27343->27347 27346 7ff7b35c1d40 27345->27346 27346->27202 27348 7ff7b35c1e26 27347->27348 27351 7ff7b35d5740 27348->27351 27350 7ff7b35c1e3c 27350->27342 27352 7ff7b35d576a 27351->27352 27354 7ff7b35d57a2 27352->27354 27355 7ff7b35d0078 27352->27355 27354->27350 27362 7ff7b35d627c EnterCriticalSection 27355->27362 27357 7ff7b35d0095 27358 7ff7b35d2118 33 API calls 27357->27358 27359 7ff7b35d009e 27358->27359 27360 7ff7b35d6288 _fread_nolock LeaveCriticalSection 27359->27360 27361 7ff7b35d00a8 27360->27361 27361->27354 27363 7ffdfac9c9f8 27388 7ffdfad13290 27363->27388 27365 7ffdfac9ca08 27366 7ffdfad13290 memcpy 27365->27366 27367 7ffdfac9ca42 27366->27367 27368 7ffdfad13290 memcpy 27367->27368 27369 7ffdfac9ca79 27368->27369 27370 7ffdfad13290 memcpy 27369->27370 27371 7ffdfac9caae 27370->27371 27372 7ffdfad13290 memcpy 27371->27372 27373 7ffdfac9cb59 27372->27373 27374 7ffdfada0280 25 API calls 27373->27374 27382 7ffdfac9cc9f 27373->27382 27374->27382 27375 7ffdfac9ccac 27377 7ffdfac9d96e 27375->27377 27381 7ffdfac9db0b 27375->27381 27401 7ffdfad75b50 TlsGetValue TlsGetValue 27375->27401 27379 7ffdfac9da64 27377->27379 27402 7ffdfad75b50 TlsGetValue TlsGetValue 27377->27402 27382->27375 27382->27377 27382->27381 27383 7ffdfad53730 28 API calls 27382->27383 27384 7ffdfad75b50 TlsGetValue TlsGetValue 27382->27384 27386 7ffdfac9d828 27382->27386 27392 7ffdfac9baa0 27382->27392 27399 7ffdfad94330 25 API calls 27382->27399 27383->27382 27384->27382 27400 7ffdfad75b50 TlsGetValue TlsGetValue 27386->27400 27389 7ffdfad132d7 27388->27389 27390 7ffdfad1346e memcpy 27389->27390 27391 7ffdfad132f0 27389->27391 27390->27391 27391->27365 27394 7ffdfac9babf 27392->27394 27393 7ffdfac9bb3a 27393->27382 27394->27393 27403 7ffdfacb73a0 27394->27403 27423 7ffdfacacfd0 27394->27423 27429 7ffdfacac8a0 27394->27429 27434 7ffdfacaca60 27394->27434 27399->27382 27400->27375 27401->27375 27402->27379 27404 7ffdfacb7748 27403->27404 27417 7ffdfacb740a 27403->27417 27405 7ffdfacb793c 27404->27405 27407 7ffdfacb7897 27404->27407 27420 7ffdfacb751f 27404->27420 27406 7ffdfacb7940 27405->27406 27414 7ffdfacb79a4 27405->27414 27408 7ffdfad8a640 29 API calls 27406->27408 27409 7ffdfada0280 25 API calls 27407->27409 27408->27420 27409->27420 27410 7ffdfacb7a01 27450 7ffdfad8a640 27410->27450 27413 7ffdfacb7503 27415 7ffdfada0280 25 API calls 27413->27415 27413->27420 27414->27410 27455 7ffdfad75b50 TlsGetValue TlsGetValue 27414->27455 27415->27420 27417->27404 27417->27413 27418 7ffdfacb7984 27417->27418 27418->27394 27419 7ffdfada0280 25 API calls 27421 7ffdfacb7a1b 27419->27421 27420->27418 27454 7ffdfad75b50 TlsGetValue TlsGetValue 27420->27454 27421->27418 27421->27419 27456 7ffdfad75b50 TlsGetValue TlsGetValue 27421->27456 27424 7ffdfacacfe6 27423->27424 27426 7ffdfacad00d 27423->27426 27424->27394 27425 7ffdfacad0cb 27425->27394 27426->27425 27427 7ffdfada0280 25 API calls 27426->27427 27428 7ffdfacad029 27427->27428 27428->27394 27430 7ffdfacac8b3 27429->27430 27431 7ffdfacac8d1 27429->27431 27430->27394 27432 7ffdfacad695 _errno 27431->27432 27433 7ffdfacad671 27431->27433 27432->27433 27433->27394 27435 7ffdfacaca94 27434->27435 27436 7ffdfacaca72 27434->27436 27437 7ffdfacacacf GetNamedSecurityInfoW 27435->27437 27436->27394 27438 7ffdfacacb06 GetCurrentProcess OpenProcessToken 27437->27438 27443 7ffdfacacbc7 27437->27443 27439 7ffdfacacbb7 27438->27439 27440 7ffdfacacb25 GetTokenInformation 27438->27440 27441 7ffdfacacbc1 LocalFree 27439->27441 27439->27443 27442 7ffdfacacbac CloseHandle 27440->27442 27444 7ffdfacacb58 27440->27444 27441->27443 27442->27439 27443->27394 27445 7ffdfacacb6f GetTokenInformation 27444->27445 27447 7ffdfacacc0e 27444->27447 27445->27442 27446 7ffdfacacb9b EqualSid 27445->27446 27446->27442 27448 7ffdfacad695 _errno 27447->27448 27449 7ffdfacacc33 27447->27449 27448->27449 27449->27394 27451 7ffdfad8a674 27450->27451 27452 7ffdfad8a69d 27451->27452 27457 7ffdfad8a9c0 TlsGetValue 27451->27457 27452->27421 27454->27418 27455->27410 27456->27421 27458 7ffdfad8aa0e 27457->27458 27459 7ffdfad8aa39 memset 27458->27459 27460 7ffdfad8ab02 27458->27460 27461 7ffdfad8aa58 27458->27461 27459->27461 27460->27452 27461->27460 27463 7ffdfad8ac61 27461->27463 27465 7ffdfadac340 26 API calls 27461->27465 27463->27460 27464 7ffdfad8b10d memcpy 27463->27464 27464->27460 27465->27463 27466 7ffe0e16c460 27467 7ffe0e16c482 27466->27467 27468 7ffe0e16c520 malloc 27466->27468 27470 7ffe0e16c4a2 memcpy 27467->27470 27471 7ffe0e16c4d0 memcpy 27467->27471 27468->27467 27469 7ffe0e16c4c2 27468->27469 27470->27469 27471->27469 27472 7ffe0e16c558 memcpy 27471->27472 27473 7ffe0cfc8ec3 27504 7ffe0cfc41e0 27473->27504 27475 7ffe0cfc8f07 27476 7ffe0cfc8f43 27475->27476 27480 7ffe0cfc8f1e 27475->27480 27477 7ffe0cfc8f69 27476->27477 27481 7ffe0cfc8f60 _Py_Dealloc 27476->27481 27478 7ffe0cfc8f81 27477->27478 27482 7ffe0cfc8f78 _Py_Dealloc 27477->27482 27479 7ffe0cfc8fa4 27478->27479 27485 7ffe0cfc8f9e _Py_Dealloc 27478->27485 27483 7ffe0cfc8fc7 27479->27483 27489 7ffe0cfc8fc1 _Py_Dealloc 27479->27489 27484 7ffe0cfc8f31 27480->27484 27486 7ffe0cfc8f28 _Py_Dealloc 27480->27486 27481->27477 27482->27478 27487 7ffe0cfc8fea 27483->27487 27491 7ffe0cfc8fe4 _Py_Dealloc 27483->27491 27485->27479 27486->27484 27488 7ffe0cfc900d 27487->27488 27492 7ffe0cfc9007 _Py_Dealloc 27487->27492 27490 7ffe0cfc9030 27488->27490 27494 7ffe0cfc902a _Py_Dealloc 27488->27494 27489->27483 27493 7ffe0cfc9053 27490->27493 27497 7ffe0cfc904d _Py_Dealloc 27490->27497 27491->27487 27492->27488 27495 7ffe0cfc9076 27493->27495 27499 7ffe0cfc9070 _Py_Dealloc 27493->27499 27494->27490 27496 7ffe0cfc9099 27495->27496 27500 7ffe0cfc9093 _Py_Dealloc 27495->27500 27498 7ffe0cfc90bc 27496->27498 27502 7ffe0cfc90b6 _Py_Dealloc 27496->27502 27497->27493 27501 7ffe0cfc90df 27498->27501 27503 7ffe0cfc90d9 _Py_Dealloc 27498->27503 27499->27495 27500->27496 27502->27498 27503->27501 27505 7ffe0cfc421a 27504->27505 27506 7ffe0cfc432f 27505->27506 27509 7ffe0cfc42d5 PyUnicode_FromStringAndSize 27505->27509 27506->27506 27513 7ffe0cfc43a5 PyBytes_FromStringAndSize 27506->27513 27514 7ffe0cfc43ea 27506->27514 27507 7ffe0cfc4471 27508 7ffe0cfc44b1 PyFloat_FromDouble 27507->27508 27517 7ffe0cfc44d7 27507->27517 27508->27507 27510 7ffe0cfc4614 27508->27510 27509->27510 27511 7ffe0cfc42fd PyUnicode_InternInPlace 27509->27511 27510->27475 27511->27505 27512 7ffe0cfc4430 PyLong_FromString 27512->27510 27512->27514 27513->27506 27513->27510 27514->27507 27514->27512 27515 7ffe0cfc4510 PyComplex_FromDoubles 27515->27510 27515->27517 27516 7ffe0cfc4550 PyTuple_New 27516->27510 27518 7ffe0cfc453b 27516->27518 27517->27515 27517->27518 27518->27516 27520 7ffe0cfc45ac 27518->27520 27519 7ffe0cfc45c0 PyFrozenSet_New 27519->27510 27519->27520 27520->27510 27520->27519 27521 7ffe0cfc45f4 PySet_Add 27520->27521 27521->27510 27521->27520 27522 7ff7b35de378 27533 7ff7b35db324 27522->27533 27525 7ff7b35de3d8 27526 7ff7b35de39f 27525->27526 27528 7ff7b35de419 27525->27528 27546 7ff7b35de510 _invalid_parameter_noinfo _invalid_parameter_noinfo _fread_nolock 27525->27546 27537 7ff7b35de108 27528->27537 27531 7ff7b35de40d 27531->27528 27547 7ff7b35e4b8c HeapFree GetLastError _fread_nolock 27531->27547 27534 7ff7b35db342 27533->27534 27535 7ff7b35db32d 27533->27535 27534->27525 27534->27526 27545 7ff7b35de2fc SetFilePointerEx GetFileSizeEx 27534->27545 27536 7ff7b35db332 _invalid_parameter_noinfo 27535->27536 27536->27534 27538 7ff7b35db324 _fread_nolock _invalid_parameter_noinfo 27537->27538 27539 7ff7b35de12d 27538->27539 27540 7ff7b35de1ce 27539->27540 27541 7ff7b35de13d 27539->27541 27548 7ff7b35ddce0 27540->27548 27543 7ff7b35ddce0 28 API calls 27541->27543 27544 7ff7b35de169 27541->27544 27543->27544 27544->27526 27545->27525 27546->27531 27547->27528 27549 7ff7b35ddd36 27548->27549 27550 7ff7b35ddd09 27548->27550 27549->27550 27556 7ff7b35d92ec EnterCriticalSection 27549->27556 27550->27544 27552 7ff7b35dddad 27553 7ff7b35dddc4 27552->27553 27554 7ff7b35dde00 26 API calls 27552->27554 27555 7ff7b35d93d4 _fread_nolock LeaveCriticalSection 27553->27555 27554->27553 27555->27550 27557 7ffdfacf1830 27558 7ffdfacf1882 27557->27558 27567 7ffdfacf3660 27558->27567 27561 7ffdfacf1a8a 27563 7ffdfacf1b0a 27561->27563 27576 7ffdfacf4b90 27561->27576 27562 7ffdfacf18fe 27562->27561 27564 7ffdfacf19a6 27562->27564 27565 7ffdfacf19a8 strncmp 27562->27565 27566 7ffdfacf3660 29 API calls 27564->27566 27565->27564 27566->27561 27568 7ffdfacf369e 27567->27568 27574 7ffdfacf3774 27567->27574 27569 7ffdfacf36d0 27568->27569 27575 7ffdfacf3791 27568->27575 27570 7ffdfada0280 25 API calls 27569->27570 27571 7ffdfacf36d5 27570->27571 27571->27574 27587 7ffdfacd7b40 29 API calls 27571->27587 27574->27562 27575->27574 27588 7ffdfacd7b40 29 API calls 27575->27588 27577 7ffdfacf4f8d 27576->27577 27578 7ffdfacf4bbc 27576->27578 27578->27577 27579 7ffdfacf4d90 memcpy 27578->27579 27580 7ffdfacf4e93 27579->27580 27586 7ffdfacf4e17 27579->27586 27581 7ffdfacf4ea7 memcpy 27580->27581 27582 7ffdfacf4ebf 27580->27582 27581->27582 27583 7ffdfacf4ed6 memcpy 27582->27583 27584 7ffdfacf4ef1 27582->27584 27583->27584 27584->27563 27586->27580 27589 7ffdfad912a0 26 API calls 27586->27589 27587->27574 27588->27574 27589->27586 27590 7ff7b35da839 27597 7ff7b35db2f8 27590->27597 27592 7ff7b35da83e 27593 7ff7b35da865 GetModuleHandleW 27592->27593 27594 7ff7b35da8af 27592->27594 27593->27594 27595 7ff7b35da872 27593->27595 27595->27594 27596 7ff7b35da960 GetModuleHandleExW GetProcAddress FreeLibrary 27595->27596 27596->27594 27599 7ff7b35db301 27597->27599 27601 7ff7b35db3ac 10 API calls __CxxCallCatchBlock 27599->27601 27602 7ffdfad11bd0 27603 7ffdfad11be9 27602->27603 27683 7ffdfaddfad0 LeaveCriticalSection 27603->27683 27605 7ffdfad11c41 exit 27608 7ffdfad11c76 27605->27608 27606 7ffdfad11bfc 27606->27605 27609 7ffdfad11b40 LeaveCriticalSection LeaveCriticalSection 27606->27609 27620 7ffdfad11c01 27606->27620 27607 7ffdfad11dbc GetCurrentThreadId 27614 7ffdfad11dd8 27607->27614 27608->27607 27610 7ffdfad11c9d GetProcessHeap HeapAlloc 27608->27610 27611 7ffdfad11daf LeaveCriticalSection 27608->27611 27609->27620 27613 7ffdfad11cbe TlsAlloc 27610->27613 27624 7ffdfad11ed5 27610->27624 27611->27607 27612 7ffdfad11df7 TlsGetValue 27621 7ffdfad11e14 27612->27621 27617 7ffdfad11ccf WSAStartup GetModuleHandleW GetProcAddress GetProcAddress 27613->27617 27613->27624 27614->27612 27615 7ffdfad11e8c LeaveCriticalSection 27614->27615 27618 7ffdfad11ec0 27615->27618 27616 7ffdfad11e3d 27616->27615 27619 7ffdfad9cae0 57 API calls 27617->27619 27622 7ffdfad11d33 27619->27622 27620->27605 27621->27616 27621->27624 27623 7ffdfad11d38 TlsGetValue 27622->27623 27626 7ffdfad11d53 27623->27626 27625 7ffdfad11b40 LeaveCriticalSection LeaveCriticalSection 27624->27625 27627 7ffdfad11f2d 27625->27627 27626->27624 27628 7ffdfad04920 LeaveCriticalSection memset memset memset 27626->27628 27629 7ffdfad11f6a EnterCriticalSection 27627->27629 27630 7ffdfad11f3c InitializeCriticalSection InitializeCriticalSection InitializeCriticalSection 27627->27630 27631 7ffdfad11da5 27628->27631 27632 7ffdfad11f96 TlsGetValue 27629->27632 27682 7ffdfad12539 27629->27682 27630->27629 27631->27611 27644 7ffdfad11fb8 27632->27644 27633 7ffdfad125ea EnterCriticalSection DeleteCriticalSection DeleteCriticalSection 27635 7ffdfad12621 DeleteCriticalSection 27633->27635 27636 7ffdfad12635 LeaveCriticalSection DeleteCriticalSection 27633->27636 27634 7ffdfad125bc InitializeCriticalSection InitializeCriticalSection InitializeCriticalSection 27634->27633 27635->27636 27639 7ffdfad12679 27636->27639 27637 7ffdfad12055 LeaveCriticalSection 27641 7ffdfad12075 27637->27641 27638 7ffdfad12014 LeaveCriticalSection 27638->27644 27640 7ffdfad12091 LeaveCriticalSection 27642 7ffdfaddfa00 27640->27642 27641->27640 27643 7ffdfad120aa LeaveCriticalSection 27642->27643 27645 7ffdfad120ca 27643->27645 27644->27637 27644->27638 27646 7ffdfad75b50 TlsGetValue TlsGetValue 27645->27646 27648 7ffdfad120fa 27645->27648 27646->27648 27647 7ffdfad1219c LeaveCriticalSection 27650 7ffdfad121b5 27647->27650 27648->27647 27649 7ffdfad121d1 LeaveCriticalSection 27651 7ffdfaddfa00 27649->27651 27650->27649 27652 7ffdfad121ea LeaveCriticalSection 27651->27652 27653 7ffdfad04c10 27652->27653 27654 7ffdfad121fc TlsGetValue 27653->27654 27655 7ffdfad12210 27654->27655 27657 7ffdfad12231 27654->27657 27656 7ffdfad12218 TlsSetValue 27655->27656 27656->27639 27656->27657 27658 7ffdfadbe280 25 API calls 27657->27658 27659 7ffdfad12271 27657->27659 27658->27657 27660 7ffdfadbe280 25 API calls 27659->27660 27661 7ffdfad12291 27659->27661 27660->27659 27661->27639 27662 7ffdfad122d4 LeaveCriticalSection 27661->27662 27663 7ffdfad12318 EnterCriticalSection 27662->27663 27664 7ffdfad122ea InitializeCriticalSection InitializeCriticalSection InitializeCriticalSection 27662->27664 27665 7ffdfad1236d TlsFree 27663->27665 27667 7ffdfad12331 27663->27667 27664->27663 27665->27639 27666 7ffdfad1238b GetProcessHeap HeapFree 27665->27666 27671 7ffdfad123c4 27666->27671 27676 7ffdfad12403 27666->27676 27667->27665 27668 7ffdfad1246e 27670 7ffdfad12484 LeaveCriticalSection 27668->27670 27669 7ffdfad123d8 DeleteCriticalSection 27669->27671 27672 7ffdfad124a4 27670->27672 27671->27669 27671->27676 27674 7ffdfad124ac DeleteCriticalSection free 27672->27674 27675 7ffdfad124cb 27672->27675 27673 7ffdfad12443 DeleteCriticalSection 27673->27676 27674->27672 27677 7ffdfad124ef 27675->27677 27678 7ffdfad124dc DeleteCriticalSection free 27675->27678 27676->27668 27676->27673 27679 7ffdfad12502 DeleteCriticalSection free 27677->27679 27680 7ffdfad12515 27677->27680 27678->27677 27679->27680 27681 7ffdfad12525 TlsFree 27680->27681 27680->27682 27681->27639 27681->27682 27682->27633 27682->27634 27684 7ffe0e16c8f0 27685 7ffe0e16c906 27684->27685 27687 7ffe0e16c960 27684->27687 27686 7ffe0e16c947 malloc 27685->27686 27685->27687 27686->27687 27688 7ffdfad052a0 27689 7ffdfada0280 25 API calls 27688->27689 27694 7ffdfad052c0 27689->27694 27690 7ffdfad05455 LeaveCriticalSection 27691 7ffdfad05467 27690->27691 27708 7ffdfadad510 27691->27708 27693 7ffdfada0280 25 API calls 27693->27694 27694->27690 27694->27693 27696 7ffdfad053c4 memcpy 27694->27696 27698 7ffdfad0544d 27694->27698 27701 7ffdfad055c5 27694->27701 27695 7ffdfad05473 27697 7ffdfad05515 27695->27697 27699 7ffdfad054fb 27695->27699 27695->27701 27696->27694 27698->27690 27699->27697 27720 7ffdfacf9b00 TlsGetValue TlsGetValue 27699->27720 27702 7ffdfad05622 LeaveCriticalSection 27701->27702 27707 7ffdfad05600 27701->27707 27702->27707 27703 7ffdfad0569e LeaveCriticalSection 27704 7ffdfaddfa00 27703->27704 27706 7ffdfad056be LeaveCriticalSection 27704->27706 27705 7ffdfad0560d 27707->27703 27707->27705 27714 7ffdfadad350 27708->27714 27709 7ffdfadad713 27709->27695 27710 7ffdfadad6d4 27721 7ffdfad912a0 26 API calls 27710->27721 27712 7ffdfadad6ef LeaveCriticalSection 27712->27709 27714->27708 27714->27709 27714->27710 27715 7ffdfadad417 memcpy 27714->27715 27719 7ffdfadad44b 27714->27719 27715->27714 27716 7ffdfadad495 27715->27716 27718 7ffdfadad4bd LeaveCriticalSection 27716->27718 27717 7ffdfadad488 LeaveCriticalSection 27717->27716 27718->27695 27719->27717 27721->27712 27722 7ffdfacf2960 27723 7ffdfacf29ad 27722->27723 27725 7ffdfacf2b43 27723->27725 27726 7ffdfacf3d60 27723->27726 27733 7ffdfacf3def 27726->27733 27727 7ffdfacf3660 29 API calls 27727->27733 27728 7ffdfacf468c 27728->27723 27729 7ffdfacf4233 memcpy 27729->27733 27730 7ffdfacf41bb memcpy 27730->27729 27731 7ffdfacf4369 27731->27728 27732 7ffdfacf3d60 29 API calls 27731->27732 27734 7ffdfacf474b 27732->27734 27733->27727 27733->27729 27733->27730 27733->27731 27735 7ffdfade02d0 27736 7ffdfade0421 27735->27736 27737 7ffdfade02e1 27735->27737 27740 7ffdfade044b QueryPerformanceCounter EnterCriticalSection LeaveCriticalSection 27736->27740 27743 7ffdfade048f 27736->27743 27738 7ffdfade02ea InitializeCriticalSection InitializeCriticalSection InitializeCriticalSection 27737->27738 27739 7ffdfade031b EnterCriticalSection 27737->27739 27738->27739 27741 7ffdfade0335 QueryPerformanceFrequency 27739->27741 27742 7ffdfade0414 LeaveCriticalSection 27739->27742 27740->27743 27744 7ffdfade040a 27741->27744 27745 7ffdfade0364 7 API calls 27741->27745 27742->27736 27744->27742 27745->27744 27746 7ffdfad39ba0 27747 7ffdfad39bc8 27746->27747 27748 7ffdfad39c16 27747->27748 27750 7ffdfad39e40 27747->27750 27751 7ffdfad39e8f 27750->27751 27752 7ffdfad3a3db memcpy 27751->27752 27753 7ffdfad3a401 27751->27753 27752->27753 27753->27747 27754 7ffdfad39360 TlsGetValue 27755 7ffdfad39383 27754->27755 27756 7ffdfad393ff 27755->27756 27757 7ffdfad397e5 memcpy 27755->27757 27757->27756 27758 7ffdfad37fe0 27759 7ffdfad3804a 27758->27759 27760 7ffdfad3806f memchr 27759->27760 27771 7ffdfad38087 27759->27771 27760->27771 27761 7ffdfad38480 27762 7ffdfad384b7 _errno 27761->27762 27770 7ffdfad3846c 27761->27770 27762->27770 27763 7ffdfad38107 memcpy 27763->27771 27764 7ffdfad384f0 27765 7ffdfada0280 25 API calls 27764->27765 27767 7ffdfad3853a 27765->27767 27766 7ffdfad383ae memcpy 27766->27771 27773 7ffdfad385e9 27767->27773 27774 7ffdfad75b50 TlsGetValue TlsGetValue 27767->27774 27769 7ffdfad385d7 27771->27761 27771->27763 27771->27764 27771->27766 27771->27770 27772 7ffdfad3834c memchr 27771->27772 27772->27771 27774->27769 27775 7ffdfad62ae0 27776 7ffdfad62bc0 27775->27776 27778 7ffdfad62b1f 27775->27778 27782 7ffdfad60f10 27776->27782 27778->27776 27779 7ffdfad62b7c 27778->27779 27794 7ffdfad94330 25 API calls 27779->27794 27781 7ffdfad62b8b 27783 7ffdfad60f4a 27782->27783 27785 7ffdfad611e7 27783->27785 27795 7ffdfac99050 27783->27795 27787 7ffdfad61282 TlsGetValue 27785->27787 27792 7ffdfad61379 27785->27792 27793 7ffdfad6129f 27785->27793 27786 7ffdfad6113d 27786->27785 27789 7ffdfad61162 27786->27789 27787->27793 27788 7ffdfad6135c TlsGetValue 27788->27792 27790 7ffdfac99050 29 API calls 27789->27790 27791 7ffdfad611b5 27790->27791 27791->27781 27792->27781 27793->27788 27793->27792 27794->27781 27797 7ffdfac99092 27795->27797 27796 7ffdfac990ce 27796->27786 27797->27796 27798 7ffdfad13290 memcpy 27797->27798 27800 7ffdfac9931d 27797->27800 27798->27800 27799 7ffdfac99395 27799->27786 27800->27799 27801 7ffdfad13290 memcpy 27800->27801 27806 7ffdfac99489 27800->27806 27801->27806 27802 7ffdfac99669 27803 7ffdfada0280 25 API calls 27803->27806 27804 7ffdfac99640 27804->27786 27806->27802 27806->27803 27807 7ffdfac99582 27806->27807 27808 7ffdfac99541 memcpy 27806->27808 27807->27804 27809 7ffdfad75b50 TlsGetValue TlsGetValue 27807->27809 27808->27806 27809->27807 27810 7ffdfac9de0d 27811 7ffdfac9de1d 27810->27811 27812 7ffdfac9de27 27811->27812 27816 7ffdfac9df93 27811->27816 27813 7ffdfac9df01 27812->27813 27814 7ffdfac9de65 27812->27814 27815 7ffdfac9de74 27812->27815 27813->27815 27824 7ffdfac9e128 27813->27824 27817 7ffdfad13290 memcpy 27814->27817 27818 7ffdfada0280 25 API calls 27815->27818 27819 7ffdfac9deed 27815->27819 27816->27819 27820 7ffdfada0280 25 API calls 27816->27820 27817->27815 27818->27819 27820->27819 27821 7ffdfac9e1e2 27822 7ffdfac9e247 27821->27822 27831 7ffdfad75b50 TlsGetValue TlsGetValue 27821->27831 27824->27821 27825 7ffdfac9e28c 27824->27825 27826 7ffdfac9e30c 27825->27826 27832 7ffdfad75b50 TlsGetValue TlsGetValue 27825->27832 27827 7ffdfac9e36a 27826->27827 27833 7ffdfad75b50 TlsGetValue TlsGetValue 27826->27833 27830 7ffdfac9e358 27831->27822 27832->27826 27833->27830 27834 7ff7b35cc19c 27841 7ff7b35cc37c 27834->27841 27836 7ff7b35cc200 __CxxCallCatchBlock 27837 7ff7b35cc286 27847 7ff7b35c1000 27837->27847 27838 7ff7b35cc1b5 __scrt_acquire_startup_lock __scrt_release_startup_lock 27838->27836 27838->27837 27928 7ff7b35daa04 10 API calls 27838->27928 27842 7ff7b35cc384 27841->27842 27843 7ff7b35cc390 __scrt_dllmain_crt_thread_attach 27842->27843 27844 7ff7b35cc39d 27843->27844 27846 7ff7b35cc399 27843->27846 27929 7ff7b35db2ac 27844->27929 27846->27838 27848 7ff7b35c2b80 27847->27848 27941 7ff7b35c2a70 27848->27941 27852 7ff7b35cbab0 __CxxCallCatchBlock 3 API calls 27854 7ff7b35c30ec 27852->27854 27854->27836 27855 7ff7b35c2bfd 27970 7ff7b35c7c80 27855->27970 27856 7ff7b35c39e0 64 API calls 27857 7ff7b35c2ceb 27856->27857 27859 7ff7b35c2d2a 27857->27859 27991 7ff7b35c73e0 27857->27991 27860 7ff7b35c1e50 36 API calls 27859->27860 27921 7ff7b35c2bc9 27860->27921 27862 7ff7b35c2d1d 27863 7ff7b35c2d22 27862->27863 27867 7ff7b35c2d45 27862->27867 27865 7ff7b35cf544 9 API calls 27863->27865 27864 7ff7b35c2c4f 27866 7ff7b35c7c80 5 API calls 27864->27866 27872 7ff7b35c2c9e 27864->27872 27865->27859 27866->27872 27867->27867 27868 7ff7b35c1930 73 API calls 27867->27868 27869 7ff7b35c2d8e 27868->27869 27869->27855 27870 7ff7b35c2d9e 27869->27870 27871 7ff7b35c1e50 36 API calls 27870->27871 27871->27921 27873 7ff7b35c7c80 5 API calls 27872->27873 27874 7ff7b35c2e04 27873->27874 27875 7ff7b35c2ef9 27874->27875 27881 7ff7b35c2e29 27874->27881 27876 7ff7b35c1e50 36 API calls 27875->27876 27876->27921 27877 7ff7b35c7c80 5 API calls 27878 7ff7b35c304f 27877->27878 27879 7ff7b35c3094 27878->27879 27880 7ff7b35c311a 27878->27880 27892 7ff7b35c3171 27878->27892 27884 7ff7b35c30a5 27879->27884 27885 7ff7b35c30f9 27879->27885 27882 7ff7b35c7c80 5 API calls 27880->27882 27881->27877 27883 7ff7b35c3126 27882->27883 27883->27884 27887 7ff7b35c3133 27883->27887 27889 7ff7b35c1e50 36 API calls 27884->27889 28000 7ff7b35c7ab0 8 API calls __CxxCallCatchBlock 27885->28000 27887->27892 27893 7ff7b35c3158 27887->27893 27888 7ff7b35c3101 27890 7ff7b35c3105 27888->27890 27891 7ff7b35c310e 27888->27891 27889->27921 27890->27884 27891->27892 27894 7ff7b35c31ed LoadLibraryExW 27892->27894 27897 7ff7b35c3202 27892->27897 27895 7ff7b35c1e50 36 API calls 27893->27895 27894->27897 27895->27921 27896 7ff7b35c3226 SetDllDirectoryW 27898 7ff7b35c3248 27896->27898 27918 7ff7b35c3299 27896->27918 27897->27896 27899 7ff7b35c7c80 5 API calls 27898->27899 27911 7ff7b35c3254 27899->27911 27900 7ff7b35c3437 27980 7ff7b35c2720 27900->27980 27901 7ff7b35c335a 27901->27921 28005 7ff7b35c8510 LocalFree 27901->28005 27904 7ff7b35c3462 27987 7ff7b35c2a30 27904->27987 27909 7ff7b35c3478 27915 7ff7b35c32e1 27911->27915 27911->27918 27920 7ff7b35c32c4 27911->27920 28001 7ff7b35c6250 38 API calls __CxxCallCatchBlock 27911->28001 27914 7ff7b35c331f 28004 7ff7b35c6410 FreeLibrary 27914->28004 27915->27920 28002 7ff7b35c6940 37 API calls 27915->28002 27918->27900 27918->27901 27920->27918 28003 7ff7b35c2140 36 API calls __CxxCallCatchBlock 27920->28003 27921->27852 27928->27837 27930 7ff7b35e46bc 27929->27930 27931 7ff7b35e46fe 27930->27931 27933 7ff7b35dd3c0 27930->27933 27931->27846 27940 7ff7b35e14e8 EnterCriticalSection 27933->27940 27935 7ff7b35dd3d0 27936 7ff7b35d9244 _invalid_parameter_noinfo HeapFree GetLastError InitializeCriticalSectionAndSpinCount EnterCriticalSection 27935->27936 27938 7ff7b35dd3d9 27936->27938 27937 7ff7b35dd3e7 27937->27930 27938->27937 27939 7ff7b35dd2b8 GetStdHandle GetFileType 27938->27939 27939->27937 27942 7ff7b35cbdb0 27941->27942 27943 7ff7b35c2a7c GetModuleFileNameW 27942->27943 27944 7ff7b35c2ad0 27943->27944 27945 7ff7b35c2aab GetLastError 27943->27945 28007 7ff7b35c87e0 FindFirstFileExW 27944->28007 28012 7ff7b35c2310 37 API calls __CxxCallCatchBlock 27945->28012 27948 7ff7b35cbab0 __CxxCallCatchBlock 3 API calls 27949 7ff7b35c2b75 27948->27949 27949->27921 27951 7ff7b35c1930 27949->27951 27950 7ff7b35c2ac6 __vcrt_FlsAlloc 27950->27948 27952 7ff7b35c39e0 64 API calls 27951->27952 27953 7ff7b35c1965 27952->27953 27954 7ff7b35c1c23 27953->27954 27955 7ff7b35c73e0 27 API calls 27953->27955 27956 7ff7b35cbab0 __CxxCallCatchBlock 3 API calls 27954->27956 27957 7ff7b35c19ab 27955->27957 27958 7ff7b35c1c3e 27956->27958 27959 7ff7b35cfbcc 4 API calls 27957->27959 27969 7ff7b35c19c9 27957->27969 27958->27855 27958->27856 27961 7ff7b35c19c5 27959->27961 27960 7ff7b35cf544 9 API calls 27960->27954 27962 7ff7b35cf894 _fread_nolock 27 API calls 27961->27962 27961->27969 27963 7ff7b35c1a00 27962->27963 27964 7ff7b35cfbcc 4 API calls 27963->27964 27963->27969 27965 7ff7b35c1ae1 27964->27965 27966 7ff7b35cf894 _fread_nolock 27 API calls 27965->27966 27965->27969 27967 7ff7b35c1b2a 27966->27967 27968 7ff7b35c1e50 36 API calls 27967->27968 27967->27969 27968->27969 27969->27960 27971 7ff7b35c7c8a 27970->27971 27972 7ff7b35c7ca9 GetEnvironmentVariableW 27971->27972 27973 7ff7b35c7d12 27972->27973 27974 7ff7b35c7cc6 ExpandEnvironmentStringsW 27972->27974 27975 7ff7b35cbab0 __CxxCallCatchBlock 3 API calls 27973->27975 27974->27973 27976 7ff7b35c7ce8 27974->27976 27977 7ff7b35c7d24 27975->27977 27978 7ff7b35cbab0 __CxxCallCatchBlock 3 API calls 27976->27978 27977->27864 27979 7ff7b35c7d0a 27978->27979 27979->27864 28013 7ff7b35c57b0 27980->28013 27984 7ff7b35c2741 27986 7ff7b35c274d 27984->27986 28069 7ff7b35c54a0 27984->28069 27986->27904 27988 7ff7b35c2a3e 27987->27988 27990 7ff7b35c2a4f 27988->27990 28096 7ff7b35c82b0 FreeLibrary 27988->28096 28006 7ff7b35c6410 FreeLibrary 27990->28006 27992 7ff7b35c7404 27991->27992 27993 7ff7b35c74db 27992->27993 27994 7ff7b35cfbcc 4 API calls 27992->27994 27993->27862 27995 7ff7b35c7420 27994->27995 27995->27993 28097 7ff7b35d87a4 27995->28097 27997 7ff7b35cfbcc 4 API calls 27999 7ff7b35c7435 27997->27999 27998 7ff7b35cf894 _fread_nolock 27 API calls 27998->27999 27999->27993 27999->27997 27999->27998 28000->27888 28001->27915 28002->27920 28003->27914 28004->27918 28006->27909 28008 7ff7b35c881f FindClose 28007->28008 28009 7ff7b35c8832 28007->28009 28008->28009 28010 7ff7b35cbab0 __CxxCallCatchBlock 3 API calls 28009->28010 28011 7ff7b35c8853 28010->28011 28011->27950 28012->27950 28014 7ff7b35c57c5 28013->28014 28015 7ff7b35c580a 28014->28015 28019 7ff7b35c582d 28014->28019 28016 7ff7b35c1e50 36 API calls 28015->28016 28017 7ff7b35c5823 28016->28017 28020 7ff7b35cbab0 __CxxCallCatchBlock 3 API calls 28017->28020 28018 7ff7b35c5863 28078 7ff7b35c3980 28018->28078 28019->28018 28021 7ff7b35c1e50 36 API calls 28019->28021 28024 7ff7b35c272e 28020->28024 28021->28018 28024->27986 28037 7ff7b35c5950 28024->28037 28025 7ff7b35c587b 28027 7ff7b35c58b9 28025->28027 28028 7ff7b35c5899 28025->28028 28026 7ff7b35c82d0 LoadLibraryExW 28026->28025 28082 7ff7b35c82d0 28027->28082 28029 7ff7b35c1e50 36 API calls 28028->28029 28029->28017 28031 7ff7b35c58c6 28032 7ff7b35c58d2 28031->28032 28033 7ff7b35c5911 28031->28033 28035 7ff7b35c58ea GetLastError 28032->28035 28087 7ff7b35c4c50 123 API calls 28033->28087 28086 7ff7b35c2310 37 API calls __CxxCallCatchBlock 28035->28086 28038 7ff7b35c5976 28037->28038 28039 7ff7b35c598f 28038->28039 28040 7ff7b35c597e 28038->28040 28088 7ff7b35c40b0 28039->28088 28041 7ff7b35c1e50 36 API calls 28040->28041 28048 7ff7b35c598a 28041->28048 28044 7ff7b35c59ac 28047 7ff7b35c59bc 28044->28047 28050 7ff7b35c59cd 28044->28050 28045 7ff7b35c599b 28046 7ff7b35c1e50 36 API calls 28045->28046 28046->28048 28049 7ff7b35c1e50 36 API calls 28047->28049 28048->27984 28049->28048 28051 7ff7b35c59fd 28050->28051 28052 7ff7b35c59ec 28050->28052 28054 7ff7b35c5a1d 28051->28054 28055 7ff7b35c5a0c 28051->28055 28053 7ff7b35c1e50 36 API calls 28052->28053 28053->28048 28092 7ff7b35c4170 28054->28092 28057 7ff7b35c1e50 36 API calls 28055->28057 28057->28048 28059 7ff7b35c5a2c 28060 7ff7b35c1e50 36 API calls 28059->28060 28060->28048 28061 7ff7b35c5a3d 28062 7ff7b35c5a5d 28061->28062 28063 7ff7b35c5a4c 28061->28063 28065 7ff7b35c5a6f 28062->28065 28067 7ff7b35c5a80 28062->28067 28064 7ff7b35c1e50 36 API calls 28063->28064 28064->28048 28066 7ff7b35c1e50 36 API calls 28065->28066 28066->28048 28067->28048 28068 7ff7b35c1e50 36 API calls 28067->28068 28068->28048 28070 7ff7b35c54c0 28069->28070 28070->28070 28071 7ff7b35c54e9 28070->28071 28076 7ff7b35c5500 28070->28076 28072 7ff7b35c1e50 36 API calls 28071->28072 28073 7ff7b35c54f5 28072->28073 28073->27986 28074 7ff7b35c1450 73 API calls 28074->28076 28075 7ff7b35c1e50 36 API calls 28075->28076 28076->28074 28076->28075 28077 7ff7b35c560b 28076->28077 28077->27986 28079 7ff7b35c398a 28078->28079 28080 7ff7b35cbab0 __CxxCallCatchBlock 3 API calls 28079->28080 28081 7ff7b35c39d7 28080->28081 28081->28025 28081->28026 28083 7ff7b35c88f0 28082->28083 28084 7ff7b35c82e4 LoadLibraryExW 28083->28084 28085 7ff7b35c8303 28084->28085 28085->28031 28086->28017 28087->28017 28089 7ff7b35c40e0 28088->28089 28090 7ff7b35cbab0 __CxxCallCatchBlock 3 API calls 28089->28090 28091 7ff7b35c414a 28090->28091 28091->28044 28091->28045 28093 7ff7b35c4185 28092->28093 28094 7ff7b35cbab0 __CxxCallCatchBlock 3 API calls 28093->28094 28095 7ff7b35c429e 28094->28095 28095->28059 28095->28061 28096->27990 28098 7ff7b35d87d4 28097->28098 28101 7ff7b35d82b0 28098->28101 28100 7ff7b35d87ed 28100->27999 28102 7ff7b35d82fa 28101->28102 28105 7ff7b35d82cb 28101->28105 28109 7ff7b35d627c EnterCriticalSection 28102->28109 28104 7ff7b35d82ff 28106 7ff7b35d831c _invalid_parameter_noinfo 28104->28106 28105->28100 28107 7ff7b35d830b 28106->28107 28108 7ff7b35d6288 _fread_nolock LeaveCriticalSection 28107->28108 28108->28105 28110 7ffdfad92320 28111 7ffdfad923f2 28110->28111 28112 7ffdfad92329 28110->28112 28113 7ffdfad92418 28112->28113 28116 7ffdfad923b4 28112->28116 28117 7ffdfad90930 28112->28117 28114 7ffdfad923e0 memmove 28114->28111 28116->28111 28116->28114 28118 7ffdfad9095b 28117->28118 28119 7ffdfad909c2 TlsAlloc 28118->28119 28120 7ffdfad909e1 TlsGetValue 28118->28120 28174 7ffdfad909ab 28118->28174 28175 7ffdfad90bba 28118->28175 28119->28120 28143 7ffdfad90ce0 28119->28143 28128 7ffdfad909f9 GetLastError 28120->28128 28137 7ffdfad90a0c 28120->28137 28121 7ffdfad90c37 TlsAlloc 28122 7ffdfad90c56 TlsGetValue 28121->28122 28121->28143 28129 7ffdfad90c6e GetLastError 28122->28129 28138 7ffdfad90c81 28122->28138 28123 7ffdfad90ec9 TlsAlloc 28124 7ffdfad90ee8 TlsGetValue 28123->28124 28123->28143 28130 7ffdfad90f00 GetLastError 28124->28130 28139 7ffdfad90f13 28124->28139 28131 7ffdfad90a07 28128->28131 28128->28143 28132 7ffdfad90c7c 28129->28132 28129->28143 28133 7ffdfad90f0e 28130->28133 28130->28143 28135 7ffdfad9fc10 19 API calls 28131->28135 28134 7ffdfad9fc10 19 API calls 28132->28134 28136 7ffdfad9fc10 19 API calls 28133->28136 28134->28138 28135->28137 28136->28139 28140 7ffdfad90ac9 GetProcessHeap HeapReAlloc 28137->28140 28141 7ffdfad90a3e 28137->28141 28137->28143 28138->28143 28144 7ffdfad90d31 GetProcessHeap HeapReAlloc 28138->28144 28146 7ffdfad90caf 28138->28146 28142 7ffdfad90f9a GetProcessHeap HeapReAlloc 28139->28142 28139->28143 28145 7ffdfad90f41 28139->28145 28140->28174 28141->28143 28147 7ffdfad90a7e memcpy 28141->28147 28141->28174 28142->28143 28143->28116 28144->28175 28145->28143 28148 7ffdfad90ff1 memcpy 28145->28148 28146->28143 28149 7ffdfad90d88 memcpy 28146->28149 28146->28175 28150 7ffdfad90abe TlsGetValue 28147->28150 28151 7ffdfad90a9f TlsAlloc 28147->28151 28152 7ffdfad91012 TlsAlloc 28148->28152 28153 7ffdfad91031 TlsGetValue 28148->28153 28154 7ffdfad90da9 TlsAlloc 28149->28154 28155 7ffdfad90dc8 TlsGetValue 28149->28155 28161 7ffdfad90b33 28150->28161 28162 7ffdfad90b20 GetLastError 28150->28162 28151->28143 28151->28150 28152->28143 28152->28153 28163 7ffdfad91057 28153->28163 28164 7ffdfad91049 GetLastError 28153->28164 28154->28143 28154->28155 28159 7ffdfad90df3 28155->28159 28160 7ffdfad90de0 GetLastError 28155->28160 28159->28143 28171 7ffdfad90e13 GetProcessHeap HeapFree 28159->28171 28159->28175 28160->28143 28165 7ffdfad90dee 28160->28165 28161->28143 28172 7ffdfad90b53 GetProcessHeap HeapFree 28161->28172 28161->28174 28162->28143 28166 7ffdfad90b2e 28162->28166 28167 7ffdfad91061 28163->28167 28170 7ffdfad9fc10 19 API calls 28163->28170 28164->28143 28164->28163 28168 7ffdfad9fc10 19 API calls 28165->28168 28169 7ffdfad9fc10 19 API calls 28166->28169 28167->28143 28173 7ffdfad91081 GetProcessHeap HeapFree 28167->28173 28168->28159 28169->28161 28170->28167 28171->28175 28172->28174 28173->28143 28174->28121 28174->28122 28174->28143 28174->28175 28175->28123 28175->28124 28175->28143 28176 7ff7b35dceb4 28177 7ff7b35dcf0b 28176->28177 28183 7ff7b35dcedd 28176->28183 28177->28183 28184 7ff7b35d92ec EnterCriticalSection 28177->28184 28179 7ff7b35dcf82 28180 7ff7b35dcf99 28179->28180 28181 7ff7b35dcfd4 _fread_nolock SetFilePointerEx GetLastError 28179->28181 28182 7ff7b35d93d4 _fread_nolock LeaveCriticalSection 28180->28182 28181->28180 28182->28183 28185 7ffdfac810fe 28188 7ffdfac81103 28185->28188 28186 7ffdfac8114a 28187 7ffdfac81156 __acrt_iob_func 28186->28187 28190 7ffdfac81169 28187->28190 28188->28186 28189 7ffdfac8112b memset 28188->28189 28212 7ffdfac81602 28188->28212 28189->28186 28191 7ffdfac8168d 28190->28191 28201 7ffdfac8128c 28190->28201 28193 7ffdfac81b08 28191->28193 28242 7ffdfac81743 28191->28242 28192 7ffdfac81508 28198 7ffdfac81521 TlsAlloc 28192->28198 28199 7ffdfac81540 TlsGetValue 28192->28199 28192->28212 28236 7ffdfac81f2c 28193->28236 28238 7ffdfac81b25 28193->28238 28194 7ffdfac81323 28194->28192 28195 7ffdfac81383 TlsAlloc 28194->28195 28196 7ffdfac813a2 TlsGetValue 28194->28196 28195->28196 28195->28212 28202 7ffdfac814b4 GetLastError 28196->28202 28203 7ffdfac814c7 28196->28203 28198->28199 28198->28212 28207 7ffdfac815c1 28199->28207 28208 7ffdfac815ae GetLastError 28199->28208 28201->28194 28204 7ffdfac813cf TlsGetValue 28201->28204 28205 7ffdfac813b0 TlsAlloc 28201->28205 28209 7ffdfac814c2 28202->28209 28202->28212 28203->28192 28203->28212 28217 7ffdfac814ed GetProcessHeap HeapFree 28203->28217 28210 7ffdfac813fa 28204->28210 28211 7ffdfac813e7 GetLastError 28204->28211 28205->28204 28205->28212 28207->28212 28219 7ffdfac815e7 GetProcessHeap HeapFree 28207->28219 28208->28212 28213 7ffdfac815bc 28208->28213 28214 7ffdfad9fc10 19 API calls 28209->28214 28210->28194 28210->28212 28222 7ffdfac81420 GetProcessHeap HeapFree 28210->28222 28211->28212 28215 7ffdfac813f5 28211->28215 28216 7ffdfad9fc10 19 API calls 28213->28216 28214->28203 28218 7ffdfad9fc10 19 API calls 28215->28218 28216->28207 28217->28192 28218->28210 28219->28212 28220 7ffdfac81842 TlsAlloc 28220->28212 28221 7ffdfac81861 TlsGetValue 28220->28221 28231 7ffdfac81973 GetLastError 28221->28231 28232 7ffdfac81986 28221->28232 28222->28194 28223 7ffdfac817de 28223->28220 28223->28221 28249 7ffdfac819c7 28223->28249 28224 7ffdfac819e0 TlsAlloc 28224->28212 28225 7ffdfac819ff TlsGetValue 28224->28225 28237 7ffdfac81a6d GetLastError 28225->28237 28296 7ffdfac81a80 28225->28296 28226 7ffdfac8232a 28263 7ffdfac826a1 28226->28263 28305 7ffdfac82363 28226->28305 28229 7ffdfac8188e TlsGetValue 28246 7ffdfac818b9 28229->28246 28247 7ffdfac818a6 GetLastError 28229->28247 28230 7ffdfac8186f TlsAlloc 28230->28212 28230->28229 28231->28212 28239 7ffdfac81981 28231->28239 28232->28212 28232->28249 28250 7ffdfac819ac GetProcessHeap HeapFree 28232->28250 28233 7ffdfac81c22 TlsAlloc 28233->28212 28234 7ffdfac81c41 TlsGetValue 28233->28234 28255 7ffdfac81d53 GetLastError 28234->28255 28266 7ffdfac81d66 28234->28266 28236->28226 28254 7ffdfac81fa3 28236->28254 28237->28212 28241 7ffdfac81a7b 28237->28241 28240 7ffdfac81bc0 28238->28240 28251 7ffdfac81c6e TlsGetValue 28238->28251 28252 7ffdfac81c4f TlsAlloc 28238->28252 28248 7ffdfad9fc10 19 API calls 28239->28248 28240->28233 28240->28234 28298 7ffdfac81da7 28240->28298 28253 7ffdfad9fc10 19 API calls 28241->28253 28242->28223 28242->28229 28242->28230 28244 7ffdfac81dc0 TlsAlloc 28244->28212 28245 7ffdfac81ddf TlsGetValue 28244->28245 28262 7ffdfac81e4d GetLastError 28245->28262 28282 7ffdfac81e60 28245->28282 28246->28212 28246->28223 28268 7ffdfac818df GetProcessHeap HeapFree 28246->28268 28247->28212 28256 7ffdfac818b4 28247->28256 28248->28232 28249->28212 28249->28224 28249->28225 28250->28249 28264 7ffdfac81c86 GetLastError 28251->28264 28270 7ffdfac81c99 28251->28270 28252->28212 28252->28251 28253->28296 28290 7ffdfac820ee TlsGetValue 28254->28290 28291 7ffdfac820cf TlsAlloc 28254->28291 28318 7ffdfac8203e 28254->28318 28255->28212 28260 7ffdfac81d61 28255->28260 28261 7ffdfad9fc10 19 API calls 28256->28261 28259 7ffdfac8230a GetProcessHeap HeapFree 28259->28212 28265 7ffdfad9fc10 19 API calls 28260->28265 28261->28246 28262->28212 28267 7ffdfac81e5b 28262->28267 28271 7ffdfac8276c fprintf 28263->28271 28315 7ffdfac827a9 28263->28315 28341 7ffdfac826b8 28263->28341 28264->28212 28269 7ffdfac81c94 28264->28269 28265->28266 28266->28212 28272 7ffdfac81d8c GetProcessHeap HeapFree 28266->28272 28266->28298 28273 7ffdfad9fc10 19 API calls 28267->28273 28268->28223 28277 7ffdfad9fc10 19 API calls 28269->28277 28270->28212 28270->28240 28286 7ffdfac81cbf GetProcessHeap HeapFree 28270->28286 28280 7ffdfac82798 28271->28280 28281 7ffdfac82787 fprintf 28271->28281 28272->28298 28273->28282 28274 7ffdfac820a2 TlsAlloc 28274->28212 28275 7ffdfac820c1 TlsGetValue 28274->28275 28284 7ffdfac821d3 GetLastError 28275->28284 28285 7ffdfac821e6 28275->28285 28277->28270 28278 7ffdfac82240 TlsAlloc 28278->28212 28279 7ffdfac8225f TlsGetValue 28278->28279 28279->28296 28297 7ffdfac822cd GetLastError 28279->28297 28347 7ffdfac85b00 16 API calls 28280->28347 28287 7ffdfac827a0 fflush 28281->28287 28282->28212 28283 7ffdfac81e86 GetProcessHeap HeapFree 28282->28283 28283->28212 28284->28212 28293 7ffdfac821e1 28284->28293 28285->28212 28308 7ffdfac82227 28285->28308 28309 7ffdfac8220c GetProcessHeap HeapFree 28285->28309 28286->28240 28287->28315 28303 7ffdfac82119 28290->28303 28304 7ffdfac82106 GetLastError 28290->28304 28291->28212 28291->28290 28292 7ffdfac823fe 28292->28212 28294 7ffdfac82462 TlsAlloc 28292->28294 28295 7ffdfac82481 TlsGetValue 28292->28295 28300 7ffdfad9fc10 19 API calls 28293->28300 28294->28212 28294->28295 28311 7ffdfac82593 GetLastError 28295->28311 28312 7ffdfac825a1 28295->28312 28296->28212 28296->28259 28297->28212 28301 7ffdfac822db 28297->28301 28298->28212 28298->28244 28298->28245 28300->28285 28310 7ffdfad9fc10 19 API calls 28301->28310 28303->28212 28303->28318 28319 7ffdfac8213f GetProcessHeap HeapFree 28303->28319 28304->28212 28313 7ffdfac82114 28304->28313 28305->28292 28306 7ffdfac824ae TlsGetValue 28305->28306 28307 7ffdfac8248f TlsAlloc 28305->28307 28320 7ffdfac824d9 28306->28320 28321 7ffdfac824c6 GetLastError 28306->28321 28307->28212 28307->28306 28308->28212 28308->28278 28308->28279 28309->28308 28310->28296 28311->28212 28311->28312 28316 7ffdfac825ab 28312->28316 28324 7ffdfad9fc10 19 API calls 28312->28324 28317 7ffdfad9fc10 19 API calls 28313->28317 28322 7ffdfac827d9 fprintf 28315->28322 28323 7ffdfac82816 28315->28323 28316->28212 28333 7ffdfac825d1 GetProcessHeap HeapFree 28316->28333 28317->28303 28318->28274 28318->28275 28318->28308 28319->28318 28320->28212 28320->28292 28335 7ffdfac824ff GetProcessHeap HeapFree 28320->28335 28321->28212 28325 7ffdfac824d4 28321->28325 28326 7ffdfac827f4 fprintf 28322->28326 28327 7ffdfac82805 28322->28327 28342 7ffdfac85790 28323->28342 28324->28316 28329 7ffdfad9fc10 19 API calls 28325->28329 28330 7ffdfac8280d fflush 28326->28330 28348 7ffdfac85b00 16 API calls 28327->28348 28329->28320 28330->28323 28332 7ffdfac82828 28336 7ffdfac828f4 28332->28336 28337 7ffdfac8292e 28332->28337 28332->28341 28333->28212 28334 7ffdfac82d5c __acrt_iob_func 28334->28212 28335->28292 28336->28337 28338 7ffdfac828f9 fprintf 28336->28338 28349 7ffdfac857f0 fprintf 28336->28349 28340 7ffdfac82a04 fprintf 28337->28340 28337->28341 28338->28336 28340->28341 28341->28212 28341->28334 28343 7ffdfac857b6 28342->28343 28344 7ffdfac85829 28343->28344 28346 7ffdfac8585d 28343->28346 28345 7ffdfac85849 fprintf 28344->28345 28345->28346 28346->28332 28347->28287 28348->28330 28349->28336 28350 7ffdfac960c0 28351 7ffdfac960cc 28350->28351 28367 7ffdfac97521 28351->28367 28455 7ffdfad422b0 28351->28455 28353 7ffdfac96249 28354 7ffdfac9634c strstr 28353->28354 28355 7ffdfac965a4 28353->28355 28358 7ffdfac96368 28354->28358 28356 7ffdfac966fd strstr 28355->28356 28380 7ffdfac96804 28355->28380 28362 7ffdfac96719 28356->28362 28357 7ffdfac963b6 28357->28355 28359 7ffdfac963e5 strstr 28357->28359 28358->28357 28360 7ffdfac99050 29 API calls 28358->28360 28364 7ffdfac96401 28359->28364 28360->28357 28361 7ffdfac96769 28365 7ffdfac96798 strstr 28361->28365 28361->28380 28362->28361 28368 7ffdfac99050 29 API calls 28362->28368 28363 7ffdfac9644b 28363->28355 28366 7ffdfac9647a strstr 28363->28366 28364->28363 28369 7ffdfac99050 29 API calls 28364->28369 28371 7ffdfac967b4 28365->28371 28370 7ffdfac96496 28366->28370 28368->28361 28369->28363 28372 7ffdfac99050 29 API calls 28370->28372 28373 7ffdfac964e0 28370->28373 28375 7ffdfac99050 29 API calls 28371->28375 28371->28380 28372->28373 28373->28355 28376 7ffdfac96513 strstr 28373->28376 28374 7ffdfac96913 strstr 28374->28380 28375->28380 28377 7ffdfac9652f 28376->28377 28378 7ffdfac99050 29 API calls 28377->28378 28379 7ffdfac96579 28377->28379 28378->28379 28379->28355 28381 7ffdfac965ac strstr 28379->28381 28380->28367 28380->28374 28383 7ffdfac99050 29 API calls 28380->28383 28391 7ffdfac969cb 28380->28391 28384 7ffdfac965c8 28381->28384 28382 7ffdfac96b70 28465 7ffdfacf6b30 28382->28465 28383->28380 28384->28355 28386 7ffdfac99050 29 API calls 28384->28386 28386->28355 28387 7ffdfac96b9d 28389 7ffdfada0280 25 API calls 28387->28389 28388 7ffdfac96aaf strstr 28388->28391 28390 7ffdfac96ba2 28389->28390 28390->28367 28392 7ffdfada0280 25 API calls 28390->28392 28391->28367 28391->28382 28391->28388 28393 7ffdfac99050 29 API calls 28391->28393 28394 7ffdfac96bec 28392->28394 28393->28391 28394->28367 28395 7ffdfada0280 25 API calls 28394->28395 28396 7ffdfac96c38 28395->28396 28396->28367 28397 7ffdfac96cb0 28396->28397 28504 7ffdfad75b50 TlsGetValue TlsGetValue 28396->28504 28399 7ffdfac96cc7 28397->28399 28505 7ffdfad75b50 TlsGetValue TlsGetValue 28397->28505 28401 7ffdfada0280 25 API calls 28399->28401 28402 7ffdfac96cdf 28401->28402 28402->28367 28403 7ffdfada0280 25 API calls 28402->28403 28404 7ffdfac96d2a 28403->28404 28404->28367 28405 7ffdfada0280 25 API calls 28404->28405 28406 7ffdfac96d76 28405->28406 28406->28367 28407 7ffdfac96df4 28406->28407 28506 7ffdfad75b50 TlsGetValue TlsGetValue 28406->28506 28410 7ffdfac96e0b 28407->28410 28507 7ffdfad75b50 TlsGetValue TlsGetValue 28407->28507 28411 7ffdfada0280 25 API calls 28410->28411 28412 7ffdfac96e30 28411->28412 28412->28367 28413 7ffdfada0280 25 API calls 28412->28413 28415 7ffdfac96e7c 28413->28415 28414 7ffdfac96ee5 28417 7ffdfac96ef9 28414->28417 28509 7ffdfad75b50 TlsGetValue TlsGetValue 28414->28509 28415->28367 28415->28414 28508 7ffdfad75b50 TlsGetValue TlsGetValue 28415->28508 28419 7ffdfada0280 25 API calls 28417->28419 28420 7ffdfac96f0b 28419->28420 28420->28367 28421 7ffdfada0280 25 API calls 28420->28421 28423 7ffdfac96f57 28421->28423 28422 7ffdfac96fd7 28425 7ffdfac96feb 28422->28425 28511 7ffdfad75b50 TlsGetValue TlsGetValue 28422->28511 28423->28367 28423->28422 28510 7ffdfad75b50 TlsGetValue TlsGetValue 28423->28510 28427 7ffdfada0280 25 API calls 28425->28427 28428 7ffdfac96ff0 28427->28428 28428->28367 28429 7ffdfada0280 25 API calls 28428->28429 28430 7ffdfac97038 28429->28430 28430->28367 28431 7ffdfac970c0 28430->28431 28512 7ffdfad75b50 TlsGetValue TlsGetValue 28430->28512 28433 7ffdfada0280 25 API calls 28431->28433 28434 7ffdfac970d8 28433->28434 28434->28367 28435 7ffdfada0280 25 API calls 28434->28435 28436 7ffdfac97121 28435->28436 28436->28367 28438 7ffdfac971a7 28436->28438 28513 7ffdfad75b50 TlsGetValue TlsGetValue 28436->28513 28438->28367 28439 7ffdfada0280 25 API calls 28438->28439 28440 7ffdfac97213 28439->28440 28440->28367 28441 7ffdfada0280 25 API calls 28440->28441 28442 7ffdfac97255 28441->28442 28442->28367 28443 7ffdfada0280 25 API calls 28442->28443 28444 7ffdfac972a1 28443->28444 28444->28367 28445 7ffdfac97310 28444->28445 28514 7ffdfad75b50 TlsGetValue TlsGetValue 28444->28514 28448 7ffdfac97327 28445->28448 28515 7ffdfad75b50 TlsGetValue TlsGetValue 28445->28515 28448->28367 28449 7ffdfac97456 strstr 28448->28449 28450 7ffdfac974e2 zlibVersion 28448->28450 28452 7ffdfac97476 28449->28452 28451 7ffdfacf6b30 35 API calls 28450->28451 28451->28367 28452->28450 28453 7ffdfac99050 29 API calls 28452->28453 28454 7ffdfac974c3 28452->28454 28453->28450 28454->28450 28463 7ffdfad422cf 28455->28463 28456 7ffdfad42462 28456->28353 28457 7ffdfada0280 25 API calls 28457->28463 28458 7ffdfad42376 memcpy 28458->28463 28460 7ffdfad424a0 28461 7ffdfad4250c 28460->28461 28521 7ffdfad75b50 TlsGetValue TlsGetValue 28460->28521 28461->28353 28462 7ffdfad42400 memcpy 28462->28463 28463->28456 28463->28457 28463->28458 28463->28460 28463->28462 28516 7ffdfacfab80 28463->28516 28469 7ffdfacf6b74 28465->28469 28466 7ffdfacf6bf9 28470 7ffdfada0280 25 API calls 28466->28470 28467 7ffdfacf6c53 28468 7ffdfada0280 25 API calls 28467->28468 28477 7ffdfacf6c58 28468->28477 28469->28466 28469->28467 28487 7ffdfacf6ff3 28469->28487 28471 7ffdfacf6c0e 28470->28471 28472 7ffdfacf6c32 memcpy 28471->28472 28471->28477 28471->28487 28472->28477 28473 7ffdfacf6dbf 28474 7ffdfacfab80 2 API calls 28473->28474 28484 7ffdfacf6dd2 28474->28484 28475 7ffdfada0280 25 API calls 28475->28477 28476 7ffdfacf6d4f memcpy 28476->28477 28477->28473 28477->28475 28477->28476 28481 7ffdfacfab80 2 API calls 28477->28481 28477->28487 28523 7ffdfaca2b20 26 API calls 28477->28523 28478 7ffdfacf6ece 28480 7ffdfacf6f5d strstr 28478->28480 28478->28487 28482 7ffdfacf6f72 28480->28482 28481->28477 28485 7ffdfac99050 29 API calls 28482->28485 28482->28487 28483 7ffdfacf6eb5 memcpy 28483->28478 28484->28478 28484->28483 28484->28487 28485->28487 28486 7ffdfacf74ec 28489 7ffdfada0280 25 API calls 28486->28489 28487->28486 28488 7ffdfacf71b1 28487->28488 28497 7ffdfacf6ffc 28487->28497 28491 7ffdfacf71bd 28488->28491 28493 7ffdfacf734a 28488->28493 28490 7ffdfacf720c 28489->28490 28490->28497 28526 7ffdfad75b50 TlsGetValue TlsGetValue 28490->28526 28491->28490 28495 7ffdfacf7207 28491->28495 28491->28497 28500 7ffdfacf7286 28491->28500 28492 7ffdfacf7425 28494 7ffdfada0280 25 API calls 28492->28494 28493->28492 28493->28497 28498 7ffdfacf73a7 28493->28498 28494->28490 28496 7ffdfada0280 25 API calls 28495->28496 28496->28490 28497->28387 28498->28497 28525 7ffdfad912a0 26 API calls 28498->28525 28500->28490 28500->28497 28502 7ffdfacf7316 28500->28502 28502->28497 28524 7ffdfacf9b00 TlsGetValue TlsGetValue 28502->28524 28504->28397 28505->28399 28506->28407 28507->28410 28508->28414 28509->28417 28510->28422 28511->28425 28512->28431 28513->28438 28514->28445 28515->28448 28517 7ffdfacfacb5 28516->28517 28519 7ffdfacfaba1 28516->28519 28517->28463 28518 7ffdfacfabb7 28518->28463 28519->28518 28522 7ffdfad75b50 TlsGetValue TlsGetValue 28519->28522 28521->28461 28522->28518 28523->28477 28525->28497 28526->28497 28527 7ffe0cfd252e 28528 7ffe0cfd2543 28527->28528 28529 7ffe0cfd2534 28527->28529 28535 7ffe0cfc4640 PyImport_ImportModuleLevelObject 28528->28535 28529->28528 28530 7ffe0cfd253a _Py_Dealloc 28529->28530 28530->28528 28534 7ffe0cfd382e 28536 7ffe0cfc47fb 28535->28536 28543 7ffe0cfc4683 28535->28543 28552 7ffe0cfc3880 10 API calls 28536->28552 28537 7ffe0cfc46b0 PyObject_GetAttr 28538 7ffe0cfc46cb PyUnicode_FromFormat 28537->28538 28537->28543 28541 7ffe0cfc477b PyErr_Clear PyModule_GetFilenameObject PyUnicode_FromFormat PyErr_SetImportError 28538->28541 28542 7ffe0cfc46ef PyObject_GetItem 28538->28542 28539 7ffe0cfc472d PyDict_SetItem 28539->28543 28540 7ffe0cfc4735 PyObject_SetItem 28540->28543 28544 7ffe0cfc47c4 28541->28544 28545 7ffe0cfc47d3 28541->28545 28542->28543 28543->28536 28543->28537 28543->28539 28543->28540 28543->28541 28546 7ffe0cfc47e7 28543->28546 28547 7ffe0cfc4709 _Py_Dealloc 28543->28547 28550 7ffe0cfc4748 _Py_Dealloc 28543->28550 28544->28545 28548 7ffe0cfc47ca _Py_Dealloc 28544->28548 28545->28546 28549 7ffe0cfc47de _Py_Dealloc 28545->28549 28546->28536 28551 7ffe0cfc47f2 _Py_Dealloc 28546->28551 28547->28543 28548->28545 28549->28546 28550->28543 28551->28536 28552->28534
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Heap$Alloc$ProcessValue$ErrorLast$Free$CriticalSection$InitializeLeave$mallocmemset$__acrt_iob_func$CurrentThread
                                                                                                                                                                                                              • String ID: ========= LA%d ==========$========= RAW ==========$========= SEARCH ==========$========= TREE FIXED ==========$TlsGetValue failed from TclpGetAllocCache$alloc: invalid block: %p: %x %x$could not allocate thread local storage$e$null tree$unable to alloc %u bytes
                                                                                                                                                                                                              • API String ID: 3195564845-3696316794
                                                                                                                                                                                                              • Opcode ID: 112191984abaf0579606c12aff94073ca2d9b6983290e86b65bba7c0c67b1969
                                                                                                                                                                                                              • Instruction ID: 3046563c09749a58144e63959b547b98ec385bb63c896ce9b5cdf6a253962895
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 112191984abaf0579606c12aff94073ca2d9b6983290e86b65bba7c0c67b1969
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 5513663AB0964286EB5C9B25D964B7C23A1FF04B94F1481B5CA3E0B6DDDF3DE8548710
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: TlsAlloc.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE21
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: TlsGetValue.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE4F
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: GetLastError.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE5D
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: GetProcessHeap.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE9B
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: HeapAlloc.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FEA9
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0BD0: TlsGetValue.KERNEL32(?,?,00000000,00007FFDFAD75CD1,?,?,?,00007FFDFADAD0F5,?,?,00000000,00007FFDFADAD26E), ref: 00007FFDFADA0BEF
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0BD0: GetProcessHeap.KERNEL32(?,?,00000000,00007FFDFAD75CD1,?,?,?,00007FFDFADAD0F5,?,?,00000000,00007FFDFADAD26E), ref: 00007FFDFADA0C01
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0BD0: HeapAlloc.KERNEL32(?,?,00000000,00007FFDFAD75CD1,?,?,?,00007FFDFADAD0F5,?,?,00000000,00007FFDFADAD26E), ref: 00007FFDFADA0C10
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0BD0: GetProcessHeap.KERNEL32(?,?,00000000,00007FFDFAD75CD1,?,?,?,00007FFDFADAD0F5,?,?,00000000,00007FFDFADAD26E), ref: 00007FFDFADA0C29
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0BD0: HeapAlloc.KERNEL32(?,?,00000000,00007FFDFAD75CD1,?,?,?,00007FFDFADAD0F5,?,?,00000000,00007FFDFADAD26E), ref: 00007FFDFADA0C38
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0BD0: TlsSetValue.KERNEL32(?,?,00000000,00007FFDFAD75CD1,?,?,?,00007FFDFADAD0F5,?,?,00000000,00007FFDFADAD26E), ref: 00007FFDFADA0C7F
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0BD0: LeaveCriticalSection.KERNEL32(?,?,00000000,00007FFDFAD75CD1,?,?,?,00007FFDFADAD0F5,?,?,00000000,00007FFDFADAD26E), ref: 00007FFDFADA0CBF
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0BD0: GetProcessHeap.KERNEL32(?,?,00000000,00007FFDFAD75CD1,?,?,?,00007FFDFADAD0F5,?,?,00000000,00007FFDFADAD26E), ref: 00007FFDFADA0CEF
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0BD0: HeapReAlloc.KERNEL32(?,?,00000000,00007FFDFAD75CD1,?,?,?,00007FFDFADAD0F5,?,?,00000000,00007FFDFADAD26E), ref: 00007FFDFADA0D00
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0BD0: memset.VCRUNTIME140(?,?,00000000,00007FFDFAD75CD1,?,?,?,00007FFDFADAD0F5,?,?,00000000,00007FFDFADAD26E), ref: 00007FFDFADA0D27
                                                                                                                                                                                                                • Part of subcall function 00007FFDFACA76B0: memcpy.VCRUNTIME140 ref: 00007FFDFACA77A6
                                                                                                                                                                                                                • Part of subcall function 00007FFDFACA76B0: strstr.VCRUNTIME140 ref: 00007FFDFACA7880
                                                                                                                                                                                                              • strstr.VCRUNTIME140 ref: 00007FFDFAC9635D
                                                                                                                                                                                                              • strstr.VCRUNTIME140 ref: 00007FFDFAC963F6
                                                                                                                                                                                                              • strstr.VCRUNTIME140 ref: 00007FFDFAC9648B
                                                                                                                                                                                                              • strstr.VCRUNTIME140 ref: 00007FFDFAC96524
                                                                                                                                                                                                              • strstr.VCRUNTIME140 ref: 00007FFDFAC965BD
                                                                                                                                                                                                              • strstr.VCRUNTIME140 ref: 00007FFDFAC9670E
                                                                                                                                                                                                              • strstr.VCRUNTIME140 ref: 00007FFDFAC967A9
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Heapstrstr$Alloc$Process$Value$CriticalErrorLastLeaveSectionmemcpymemset
                                                                                                                                                                                                              • String ID: 1.1.0$2.0.1$8.6.13$::tcl$::tcl::Bgerror$::tcl::mathfunc$::tcl::mathop$::tcl::prefix$::tcl::unsupported$::tcl::unsupported::assemble$::tcl::unsupported::corotype$::tcl::unsupported::disassemble$::tcl::unsupported::getbytecode$::tcl::unsupported::representation$::tcl::unsupported::timerate$Can't create math function namespace$Tcl$TclOO$array$athop::$binary$binary decode$binary encode$builtin command with NULL object command proc and a NULL compile proc$can't create math operator namespace$cp1252$dian$dict$encoding$engine$failed to create math operator %s$file$form$hLevel$info$iso8859-1$namespace$namespace eval ::tcl::zlib {variable cmdcounter 0}$package ifneeded TclOO 1.1.0 {# Already present, OK?};namespace eval ::oo { variable version 1.1.0 };namespace eval ::oo { variable patchlevel 1.1.0 };$prefix$string$tcl$tcl::tommath$tcl_precision$threaded$unable to alloc %u bytes$wordSize$zlib$zlibVersion$*($?$E$W$\$_$e$k$x,$y$+
                                                                                                                                                                                                              • API String ID: 2684404603-1668199066
                                                                                                                                                                                                              • Opcode ID: 85d520b7b1135f1fa0c3d7958e753e7d73331909ce38fe1a2ea5d1f21da145d2
                                                                                                                                                                                                              • Instruction ID: fa5dca4d98dfe1b575eaf8ddae33b8010747c8dcf09bf074205017f383c9e68b
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 85d520b7b1135f1fa0c3d7958e753e7d73331909ce38fe1a2ea5d1f21da145d2
                                                                                                                                                                                                              • Instruction Fuzzy Hash: C2D25A39B0978285EB189F11E860AAE37A5FB48788F4480B5DAAD077DDEF3CE554C740
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: AddressAllocCriticalHeapLeaveProcSectionValue$CurrentHandleModuleProcessStartupThreadexit
                                                                                                                                                                                                              • String ID: 8.6.13$CancelSynchronousIo$CreateSymbolicLinkW$KERNEL32$TlsFree failed from TclpFreeAllocCache$exit handlers were created during Tcl_Finalize$unable to alloc %u bytes$unable to allocate thread key!$unable to allocate thread-local storage$unable to delete key$unable to set global TSD value
                                                                                                                                                                                                              • API String ID: 4073625567-2392841937
                                                                                                                                                                                                              • Opcode ID: cdcff4d7e323a63006b6741260d409f99aab5f8e3b96b1774b8a607c3369d7bb
                                                                                                                                                                                                              • Instruction ID: 5300938aa2db7056dcb4b34813e105d1f1258fc2847bc4625d7477be6ce9a9ba
                                                                                                                                                                                                              • Opcode Fuzzy Hash: cdcff4d7e323a63006b6741260d409f99aab5f8e3b96b1774b8a607c3369d7bb
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 0662B525F08A4691FB1CAB15ECB0AB833A4FF98B44F4451B5D96E476E9EF3EA445C300

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CriticalSection$Initialize$Create$EnterEventLeavePerformanceQueryThread$CloseCounterFrequencyHandleObjectPrioritySingleWait
                                                                                                                                                                                                              • String ID: gfffffff
                                                                                                                                                                                                              • API String ID: 1584168963-1523873471
                                                                                                                                                                                                              • Opcode ID: 607c9e9097ddf32b083740b29507f9ea837255c11cde33d59462849dd16d69da
                                                                                                                                                                                                              • Instruction ID: 050519a11d66966c7a32fa979e4a4b2430e7da05d9c1f7038f5a1b79c0a0b39e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 607c9e9097ddf32b083740b29507f9ea837255c11cde33d59462849dd16d69da
                                                                                                                                                                                                              • Instruction Fuzzy Hash: AB512C76F08A4282EB089B19ECB0A7563A0FB94784F4451B5D96E436E8EF3DE849C700

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              • Executed
                                                                                                                                                                                                              • Not Executed
                                                                                                                                                                                                              control_flow_graph 2580 7ffdfad37fe0-7ffdfad38048 2581 7ffdfad38057-7ffdfad38067 2580->2581 2582 7ffdfad3804a-7ffdfad3804f call 7ffdfad37eb0 2580->2582 2584 7ffdfad3806f-7ffdfad3807f memchr 2581->2584 2585 7ffdfad38069-7ffdfad3806d 2581->2585 2582->2581 2587 7ffdfad38087-7ffdfad3808d 2584->2587 2585->2584 2585->2587 2588 7ffdfad38093-7ffdfad38099 2587->2588 2589 7ffdfad384ca 2587->2589 2591 7ffdfad3809f-7ffdfad380a5 2588->2591 2592 7ffdfad38484-7ffdfad3848b 2588->2592 2590 7ffdfad384cc-7ffdfad384ef call 7ffdfade1240 2589->2590 2596 7ffdfad380a7-7ffdfad380a9 2591->2596 2597 7ffdfad380ac-7ffdfad380b3 2591->2597 2594 7ffdfad3848d-7ffdfad38491 2592->2594 2595 7ffdfad38493-7ffdfad38495 2592->2595 2594->2595 2599 7ffdfad3849d-7ffdfad384b1 call 7ffdfad36580 2594->2599 2600 7ffdfad384b3-7ffdfad384b5 2595->2600 2601 7ffdfad38497-7ffdfad3849b 2595->2601 2596->2597 2602 7ffdfad380ff 2597->2602 2603 7ffdfad380b5-7ffdfad380cd call 7ffdfad9fe10 2597->2603 2599->2600 2612 7ffdfad384c3-7ffdfad384c8 2599->2612 2600->2589 2607 7ffdfad384b7-7ffdfad384bd _errno 2600->2607 2601->2599 2601->2600 2604 7ffdfad38102-7ffdfad38105 2602->2604 2615 7ffdfad380cf-7ffdfad380d1 2603->2615 2616 7ffdfad380d7-7ffdfad380fd 2603->2616 2608 7ffdfad38107-7ffdfad38129 memcpy 2604->2608 2609 7ffdfad3812c-7ffdfad38130 2604->2609 2607->2612 2608->2609 2613 7ffdfad38136-7ffdfad3817b 2609->2613 2614 7ffdfad3850c-7ffdfad38559 call 7ffdfad7a3f0 call 7ffdfada0280 call 7ffdfad38650 2609->2614 2612->2590 2618 7ffdfad3817d-7ffdfad38180 2613->2618 2619 7ffdfad38182-7ffdfad38184 2613->2619 2635 7ffdfad3855e-7ffdfad38562 2614->2635 2615->2616 2617 7ffdfad384f0-7ffdfad384fe call 7ffdfad7a3f0 2615->2617 2616->2604 2628 7ffdfad384ff-7ffdfad3850b call 7ffdfad7a3f0 2617->2628 2622 7ffdfad3819a-7ffdfad3820c 2618->2622 2619->2622 2623 7ffdfad38186-7ffdfad3818d 2619->2623 2632 7ffdfad3820e-7ffdfad38213 2622->2632 2633 7ffdfad38219-7ffdfad3822e 2622->2633 2626 7ffdfad38190-7ffdfad38198 2623->2626 2626->2622 2626->2626 2628->2614 2632->2633 2637 7ffdfad38230-7ffdfad38237 2633->2637 2638 7ffdfad38245-7ffdfad3827b 2633->2638 2640 7ffdfad38564-7ffdfad3856b 2635->2640 2641 7ffdfad385b3-7ffdfad385bd 2635->2641 2637->2638 2639 7ffdfad38239-7ffdfad38241 2637->2639 2642 7ffdfad38281-7ffdfad38284 2638->2642 2643 7ffdfad383a5-7ffdfad383ac 2638->2643 2639->2638 2646 7ffdfad3856d-7ffdfad38578 2640->2646 2647 7ffdfad385a7-7ffdfad385ae call 7ffdfadabc30 2640->2647 2649 7ffdfad3860f-7ffdfad38620 2641->2649 2650 7ffdfad385bf-7ffdfad385c6 2641->2650 2642->2643 2648 7ffdfad3828a-7ffdfad38290 2642->2648 2644 7ffdfad383ae-7ffdfad383d0 memcpy 2643->2644 2645 7ffdfad383d3-7ffdfad383e2 2643->2645 2644->2645 2651 7ffdfad383f4-7ffdfad383f7 2645->2651 2652 7ffdfad383e4-7ffdfad383f0 2645->2652 2653 7ffdfad3857e-7ffdfad3858b 2646->2653 2654 7ffdfad38621-7ffdfad38630 call 7ffdfad7a3f0 2646->2654 2647->2641 2655 7ffdfad38292-7ffdfad38295 2648->2655 2656 7ffdfad382b5 2648->2656 2658 7ffdfad385c8-7ffdfad385cd 2650->2658 2659 7ffdfad385e9-7ffdfad385f0 2650->2659 2662 7ffdfad3843e-7ffdfad38442 2651->2662 2663 7ffdfad383f9-7ffdfad3840d call 7ffdfad36580 2651->2663 2652->2651 2680 7ffdfad38631-7ffdfad38682 call 7ffdfad7a3f0 call 7ffdfad3af40 2653->2680 2681 7ffdfad38591-7ffdfad38597 2653->2681 2654->2680 2664 7ffdfad38297-7ffdfad3829a 2655->2664 2665 7ffdfad382a6-7ffdfad382b3 2655->2665 2667 7ffdfad382bb 2656->2667 2658->2659 2668 7ffdfad385cf-7ffdfad385e8 call 7ffdfad75b50 2658->2668 2660 7ffdfad38600-7ffdfad3860a call 7ffdfada0420 2659->2660 2661 7ffdfad385f2-7ffdfad385f9 2659->2661 2660->2649 2661->2660 2669 7ffdfad385fb call 7ffdfad9ff60 2661->2669 2676 7ffdfad38447-7ffdfad3844a 2662->2676 2687 7ffdfad3840f-7ffdfad38426 2663->2687 2688 7ffdfad3846c-7ffdfad3846f 2663->2688 2664->2628 2673 7ffdfad382a0-7ffdfad382a4 2664->2673 2674 7ffdfad382c2-7ffdfad3833f 2665->2674 2667->2674 2669->2660 2673->2667 2696 7ffdfad38341-7ffdfad38346 2674->2696 2697 7ffdfad3834c-7ffdfad3839d memchr 2674->2697 2682 7ffdfad38454-7ffdfad3845d 2676->2682 2683 7ffdfad3844c-7ffdfad3844f call 7ffdfad9ff60 2676->2683 2705 7ffdfad38684-7ffdfad38697 call 7ffdfad3c810 2680->2705 2706 7ffdfad3869c-7ffdfad386ad 2680->2706 2681->2680 2689 7ffdfad3859d-7ffdfad385a1 2681->2689 2685 7ffdfad38480 2682->2685 2686 7ffdfad3845f-7ffdfad38467 2682->2686 2683->2682 2685->2592 2686->2588 2687->2676 2694 7ffdfad38428-7ffdfad3842b 2687->2694 2688->2612 2693 7ffdfad38471-7ffdfad3847e call 7ffdfad9ff60 2688->2693 2689->2647 2689->2680 2693->2590 2699 7ffdfad3842d-7ffdfad38432 2694->2699 2700 7ffdfad38434-7ffdfad3843c 2694->2700 2696->2697 2697->2643 2699->2676 2699->2700 2700->2676 2705->2706
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _errnomemchrmemcpy
                                                                                                                                                                                                              • String ID: Reuse of ChannelBuffer! %p$UpdateStringProc for type '%s' failed to create a valid string rep$UpdateStringProc should not be invoked for type %s$bgerror failed to handle background error.$unable to alloc %u bytes$unknown output translation requested
                                                                                                                                                                                                              • API String ID: 3559638299-3146131670
                                                                                                                                                                                                              • Opcode ID: 6ce8476d7d7c3a28b61c5570146fa917516e307c08081b8fd72cba7a409bc29f
                                                                                                                                                                                                              • Instruction ID: 9217cdb2432af6e0eafe4f453f5e7aed321ede9bb0e571483ef913db46d721f4
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 6ce8476d7d7c3a28b61c5570146fa917516e307c08081b8fd72cba7a409bc29f
                                                                                                                                                                                                              • Instruction Fuzzy Hash: D6129372B0878186E758CF25E850BAEB7A1FB84794F148075DA6D47B98EF3DE491CB00

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              • Executed
                                                                                                                                                                                                              • Not Executed
                                                                                                                                                                                                              control_flow_graph 2868 7ff7b35e7b74-7ff7b35e7be7 call 7ff7b35e78a8 2871 7ff7b35e7c01-7ff7b35e7c0b call 7ff7b35d93fc 2868->2871 2872 7ff7b35e7be9-7ff7b35e7bf2 call 7ff7b35d5dc8 2868->2872 2878 7ff7b35e7c26-7ff7b35e7c8f CreateFileW 2871->2878 2879 7ff7b35e7c0d-7ff7b35e7c24 call 7ff7b35d5dc8 call 7ff7b35d5de8 2871->2879 2877 7ff7b35e7bf5-7ff7b35e7bfc call 7ff7b35d5de8 2872->2877 2892 7ff7b35e7f42-7ff7b35e7f62 2877->2892 2882 7ff7b35e7c91-7ff7b35e7c97 2878->2882 2883 7ff7b35e7d0c-7ff7b35e7d17 GetFileType 2878->2883 2879->2877 2888 7ff7b35e7cd9-7ff7b35e7d07 GetLastError call 7ff7b35d5d5c 2882->2888 2889 7ff7b35e7c99-7ff7b35e7c9d 2882->2889 2885 7ff7b35e7d6a-7ff7b35e7d71 2883->2885 2886 7ff7b35e7d19-7ff7b35e7d54 GetLastError call 7ff7b35d5d5c CloseHandle 2883->2886 2895 7ff7b35e7d73-7ff7b35e7d77 2885->2895 2896 7ff7b35e7d79-7ff7b35e7d7c 2885->2896 2886->2877 2903 7ff7b35e7d5a-7ff7b35e7d65 call 7ff7b35d5de8 2886->2903 2888->2877 2889->2888 2890 7ff7b35e7c9f-7ff7b35e7cd7 CreateFileW 2889->2890 2890->2883 2890->2888 2900 7ff7b35e7d82-7ff7b35e7dd7 call 7ff7b35d9314 2895->2900 2896->2900 2901 7ff7b35e7d7e 2896->2901 2906 7ff7b35e7df6-7ff7b35e7e27 call 7ff7b35e7628 2900->2906 2907 7ff7b35e7dd9-7ff7b35e7de5 call 7ff7b35e7ab0 2900->2907 2901->2900 2903->2877 2914 7ff7b35e7e2d-7ff7b35e7e6f 2906->2914 2915 7ff7b35e7e29-7ff7b35e7e2b 2906->2915 2907->2906 2913 7ff7b35e7de7 2907->2913 2916 7ff7b35e7de9-7ff7b35e7df1 call 7ff7b35db968 2913->2916 2917 7ff7b35e7e91-7ff7b35e7e9c 2914->2917 2918 7ff7b35e7e71-7ff7b35e7e75 2914->2918 2915->2916 2916->2892 2919 7ff7b35e7f40 2917->2919 2920 7ff7b35e7ea2-7ff7b35e7ea6 2917->2920 2918->2917 2922 7ff7b35e7e77-7ff7b35e7e8c 2918->2922 2919->2892 2920->2919 2923 7ff7b35e7eac-7ff7b35e7ef1 CloseHandle CreateFileW 2920->2923 2922->2917 2925 7ff7b35e7ef3-7ff7b35e7f21 GetLastError call 7ff7b35d5d5c call 7ff7b35d953c 2923->2925 2926 7ff7b35e7f26-7ff7b35e7f3b 2923->2926 2925->2926 2926->2919
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: File$CreateErrorLast_invalid_parameter_noinfo$CloseHandle$Type
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 1617910340-0
                                                                                                                                                                                                              • Opcode ID: 6900b12a6c6c443aa41c68e268e6275e38d412fb7e8bb922b7a0c5fbdd2459d5
                                                                                                                                                                                                              • Instruction ID: 295bdcbf190dfd96455fd70fa42c69d17e7117482e11012bd840b777fc71c1e6
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 6900b12a6c6c443aa41c68e268e6275e38d412fb7e8bb922b7a0c5fbdd2459d5
                                                                                                                                                                                                              • Instruction Fuzzy Hash: A2C10236B18A5185EB90EFB8C4806AC7765FB5AB98B410335DF2E6B398CF38D091C310
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: memcpy
                                                                                                                                                                                                              • String ID: GetCmdLocEncodingSize: bad code length$GetCmdLocEncodingSize: bad code offset$GetCmdLocEncodingSize: bad source length$TclInitByteCodeObj() called on uninitialized CompileEnv$unable to alloc %u bytes
                                                                                                                                                                                                              • API String ID: 3510742995-538860164
                                                                                                                                                                                                              • Opcode ID: cb3ffd5e70dc97193fbe00917be8fecc049cde036e217a249a813b5914134ff2
                                                                                                                                                                                                              • Instruction ID: 32634b171f421749c0472ba8922dda25fe63a5009c80bc82d8c01f3633cb4847
                                                                                                                                                                                                              • Opcode Fuzzy Hash: cb3ffd5e70dc97193fbe00917be8fecc049cde036e217a249a813b5914134ff2
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 9CC1AC76B04B8186DB68CF15E590BAD77A4FB48B94F154139DB6D83B98EF38E4A0C700
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: memcpy
                                                                                                                                                                                                              • String ID: $Unexpected token type in TclCompileTokens: %d; %.*s$bad stack depth computations: is %i, should be %i$unable to alloc %u bytes$unable to realloc %u bytes
                                                                                                                                                                                                              • API String ID: 3510742995-2435792223
                                                                                                                                                                                                              • Opcode ID: 98fc6593577bff907aa3f573f9796cc8a82cddf89727d0c52fd358cc1627cc5d
                                                                                                                                                                                                              • Instruction ID: 2594014ddc0bb7c9fade907d98a0d46ab8f3dd1639522e0c2f3c3ae55691d83e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 98fc6593577bff907aa3f573f9796cc8a82cddf89727d0c52fd358cc1627cc5d
                                                                                                                                                                                                              • Instruction Fuzzy Hash: E6529D36B1868186EB18CF29D46067E7BA0FB84B88F504176DA6E477ADDF3CD841CB50
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: memcpy
                                                                                                                                                                                                              • String ID: ::pkgconfig$UpdateStringProc for type '%s' failed to create a valid string rep$UpdateStringProc should not be invoked for type %s$unable to alloc %u bytes
                                                                                                                                                                                                              • API String ID: 3510742995-2541110879
                                                                                                                                                                                                              • Opcode ID: be4a74b5637a4991609554c712aff98e596e26e4f12a9def34b3af381f8df087
                                                                                                                                                                                                              • Instruction ID: 340a2afce7f748c11313c20d9761740ccf56eb658f7bed7e82e8621b54302b7b
                                                                                                                                                                                                              • Opcode Fuzzy Hash: be4a74b5637a4991609554c712aff98e596e26e4f12a9def34b3af381f8df087
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 5102B33AB0974585EB189F26E860B6E67A4FB48B88F044075DE6D477EDEF38E451C340
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Find$CloseFileFirst
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2295610775-0
                                                                                                                                                                                                              • Opcode ID: bf04df12ed89424385b35bc97b9e30209b4e9d30cb3ee9ccc1531a0517fd62e7
                                                                                                                                                                                                              • Instruction ID: 896966a225f0a88dc4aa841ce210392be47c1457a984285d5b3490e37dfa5a29
                                                                                                                                                                                                              • Opcode Fuzzy Hash: bf04df12ed89424385b35bc97b9e30209b4e9d30cb3ee9ccc1531a0517fd62e7
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 4EF0A966A1C64186F7E09B74B455366A390FF95328F800735DB6D12AD8DF3CD0898710
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • TlsAlloc.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD909C2
                                                                                                                                                                                                              • TlsGetValue.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD909EB
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD909F9
                                                                                                                                                                                                              • memcpy.VCRUNTIME140(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90A91
                                                                                                                                                                                                              • TlsAlloc.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90A9F
                                                                                                                                                                                                              • GetProcessHeap.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90AD2
                                                                                                                                                                                                              • HeapReAlloc.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90AE3
                                                                                                                                                                                                              • TlsGetValue.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90B12
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90B20
                                                                                                                                                                                                              • GetProcessHeap.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90B5A
                                                                                                                                                                                                              • HeapFree.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90B68
                                                                                                                                                                                                              • TlsAlloc.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90C37
                                                                                                                                                                                                              • TlsGetValue.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90C60
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90C6E
                                                                                                                                                                                                              • GetProcessHeap.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90D3A
                                                                                                                                                                                                              • memcpy.VCRUNTIME140(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90D9B
                                                                                                                                                                                                              • TlsAlloc.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90DA9
                                                                                                                                                                                                              • TlsGetValue.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90DD2
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90DE0
                                                                                                                                                                                                              • GetProcessHeap.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90E1A
                                                                                                                                                                                                              • HeapFree.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90E28
                                                                                                                                                                                                              • TlsAlloc.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90EC9
                                                                                                                                                                                                              • TlsGetValue.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90EF2
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90F00
                                                                                                                                                                                                              • GetProcessHeap.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90FA5
                                                                                                                                                                                                              • HeapReAlloc.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90FB6
                                                                                                                                                                                                              • memcpy.VCRUNTIME140(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD91004
                                                                                                                                                                                                              • TlsAlloc.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD91012
                                                                                                                                                                                                              • TlsGetValue.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD9103B
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD91049
                                                                                                                                                                                                              • HeapReAlloc.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD90D4B
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: TlsAlloc.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE21
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: TlsGetValue.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE4F
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: GetLastError.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE5D
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: GetProcessHeap.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE9B
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: HeapAlloc.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FEA9
                                                                                                                                                                                                              • GetProcessHeap.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD91087
                                                                                                                                                                                                              • HeapFree.KERNEL32(?,?,?,?,?,?,00000000,00007FFDFAD94C6C,?,?,00000000,00000000,?,?,?,00007FFDFAD91E77), ref: 00007FFDFAD91095
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Heap$Alloc$ErrorLastProcessValue$Freememcpy
                                                                                                                                                                                                              • String ID: TlsGetValue failed from TclpGetAllocCache$alloc: invalid block: %p: %x %x$could not allocate thread local storage$unable to realloc %u bytes
                                                                                                                                                                                                              • API String ID: 2741067554-2645962790
                                                                                                                                                                                                              • Opcode ID: d45804a5ce2d41e09042eb3f59d6fbd060178f3183cad6db35a1a3193e6aac6e
                                                                                                                                                                                                              • Instruction ID: 8852577f4e6b4667b5257002599bbe94dbf010ce515e91fc8b4704011f36b2a7
                                                                                                                                                                                                              • Opcode Fuzzy Hash: d45804a5ce2d41e09042eb3f59d6fbd060178f3183cad6db35a1a3193e6aac6e
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 1742BE35B0874696EB589B25A864A7877A0FF08B88F4441B5DA3E03BD9FF3DE855C700
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ErrorFileLastModuleName
                                                                                                                                                                                                              • String ID: Could not create temporary directory!$Could not load PyInstaller's embedded PKG archive from the executable (%s)$Could not side-load PyInstaller's PKG archive from external file (%s)$Failed to convert DLL search path!$Failed to initialize security descriptor for temporary directory!$Failed to load Tcl/Tk shared libraries for splash screen!$Failed to load splash screen resources!$Failed to remove temporary directory: %s$Failed to start splash screen!$Failed to unpack splash screen dependencies from PKG archive!$Invalid value in _PYI_PARENT_PROCESS_LEVEL: %s$MEI$PYINSTALLER_RESET_ENVIRONMENT$PYINSTALLER_STRICT_UNPACK_MODE$PYINSTALLER_SUPPRESS_SPLASH_SCREEN$Path exceeds PYI_PATH_MAX limit.$Py_GIL_DISABLED$VCRUNTIME140.dll$_PYI_APPLICATION_HOME_DIR$_PYI_APPLICATION_HOME_DIR not set for onefile child process!$_PYI_ARCHIVE_FILE$_PYI_PARENT_PROCESS_LEVEL$_PYI_SPLASH_IPC$hide-early$hide-late$minimize-early$minimize-late$pkg$pyi-contents-directory$pyi-hide-console$pyi-python-flag$pyi-runtime-tmpdir
                                                                                                                                                                                                              • API String ID: 2776309574-3325264605
                                                                                                                                                                                                              • Opcode ID: 71b4948554ab86683f5c68fac90de922c4f36b38aa80497650e6c1c21600e403
                                                                                                                                                                                                              • Instruction ID: 9b98d692e060a842cb4ff0fadcd6aba82ba2354058c2171414e3e6b9d7d1f987
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 71b4948554ab86683f5c68fac90de922c4f36b38aa80497650e6c1c21600e403
                                                                                                                                                                                                              • Instruction Fuzzy Hash: CD42A161A0C68695FAA5B73C94152F9E691AF72748FC40031DB9E622CEDE2CE5C9C330

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              • Executed
                                                                                                                                                                                                              • Not Executed
                                                                                                                                                                                                              control_flow_graph 1995 7ffdfad9fc10-7ffdfad9fc27 1996 7ffdfad9fd49-7ffdfad9fd54 call 7ffdfaddfe90 1995->1996 1997 7ffdfad9fc2d-7ffdfad9fc34 1995->1997 2003 7ffdfad9fd56-7ffdfad9fd73 GetProcessHeap HeapAlloc 1996->2003 2004 7ffdfad9fdd1-7ffdfad9fde3 1996->2004 1999 7ffdfad9fc36-7ffdfad9fc43 InitializeCriticalSection 1997->1999 2000 7ffdfad9fc4d-7ffdfad9fc61 call 7ffdfaddfa00 1997->2000 1999->2000 2008 7ffdfad9fc67-7ffdfad9fc78 malloc 2000->2008 2009 7ffdfad9fd3c-7ffdfad9fd43 LeaveCriticalSection 2000->2009 2006 7ffdfad9fd75-7ffdfad9fdcf memset call 7ffdfaddfa00 LeaveCriticalSection GetCurrentThreadId TlsSetValue 2003->2006 2007 7ffdfad9fde4-7ffdfad9fdf0 call 7ffdfad7a3f0 2003->2007 2006->2004 2018 7ffdfad9fdfe-7ffdfad9fe3a call 7ffdfad7a3f0 TlsAlloc 2006->2018 2013 7ffdfad9fdf1-7ffdfad9fdfd call 7ffdfad7a3f0 2007->2013 2012 7ffdfad9fc7e-7ffdfad9fca3 InitializeCriticalSection malloc 2008->2012 2008->2013 2009->1996 2012->2013 2016 7ffdfad9fca9-7ffdfad9fcc6 InitializeCriticalSection 2012->2016 2013->2018 2019 7ffdfad9fcd0-7ffdfad9fcfa 2016->2019 2028 7ffdfad9fe40-7ffdfad9fe5b TlsGetValue 2018->2028 2029 7ffdfad9ff44-7ffdfad9ff50 call 7ffdfad7a3f0 2018->2029 2022 7ffdfad9fd06-7ffdfad9fd1a malloc 2019->2022 2023 7ffdfad9fcfc-7ffdfad9fd04 2019->2023 2022->2013 2024 7ffdfad9fd20-7ffdfad9fd3a InitializeCriticalSection 2022->2024 2023->2022 2024->2009 2024->2019 2033 7ffdfad9fe6b-7ffdfad9fe73 2028->2033 2034 7ffdfad9fe5d-7ffdfad9fe65 GetLastError 2028->2034 2035 7ffdfad9ff51-7ffdfad9ff5f call 7ffdfad7a3f0 2029->2035 2036 7ffdfad9fe75-7ffdfad9fe7a call 7ffdfad9fc10 2033->2036 2037 7ffdfad9fe7d-7ffdfad9feb5 GetProcessHeap HeapAlloc 2033->2037 2034->2033 2034->2035 2036->2037 2043 7ffdfad9feb7-7ffdfad9ff26 2037->2043 2044 7ffdfad9feff-7ffdfad9ff01 2037->2044 2045 7ffdfad9ff2a-7ffdfad9ff43 2043->2045 2044->2045
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CriticalSection$Initialize$malloc$AllocHeapLeaveValue$CurrentErrorLastProcessThreadmemset
                                                                                                                                                                                                              • String ID: TlsGetValue failed from TclpGetAllocCache$TlsSetValue failed from TclpSetAllocCache$alloc: could not allocate new cache$could not allocate lock$could not allocate thread local storage
                                                                                                                                                                                                              • API String ID: 2510295087-2583951768
                                                                                                                                                                                                              • Opcode ID: 5d547626ff2fe665fde4ae7ab395a0c1496ef0a3bc3035a11b27ab6bb9a7575a
                                                                                                                                                                                                              • Instruction ID: f4f4c157541cda9ed7e72098cc29264dc5070c0a77a8ae32ed291e97804f5a3c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 5d547626ff2fe665fde4ae7ab395a0c1496ef0a3bc3035a11b27ab6bb9a7575a
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 3E812C25F09B4282EB189B25ECB4B7823A0EF98B54F5440B5D96E477E9FE3DE845C310

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              • Executed
                                                                                                                                                                                                              • Not Executed
                                                                                                                                                                                                              control_flow_graph 2047 7ffe0cfc4640-7ffe0cfc467d PyImport_ImportModuleLevelObject 2048 7ffe0cfc47fb 2047->2048 2049 7ffe0cfc4683-7ffe0cfc468f 2047->2049 2050 7ffe0cfc47fd-7ffe0cfc4814 2048->2050 2051 7ffe0cfc4815-7ffe0cfc4818 2049->2051 2052 7ffe0cfc4695-7ffe0cfc46a8 2049->2052 2051->2050 2053 7ffe0cfc46b0-7ffe0cfc46c9 PyObject_GetAttr 2052->2053 2054 7ffe0cfc4717-7ffe0cfc472b 2053->2054 2055 7ffe0cfc46cb-7ffe0cfc46e9 PyUnicode_FromFormat 2053->2055 2056 7ffe0cfc472d-7ffe0cfc4733 PyDict_SetItem 2054->2056 2057 7ffe0cfc4735 PyObject_SetItem 2054->2057 2058 7ffe0cfc477b-7ffe0cfc47c2 PyErr_Clear PyModule_GetFilenameObject PyUnicode_FromFormat PyErr_SetImportError 2055->2058 2059 7ffe0cfc46ef-7ffe0cfc4701 PyObject_GetItem 2055->2059 2062 7ffe0cfc473b-7ffe0cfc4740 2056->2062 2057->2062 2063 7ffe0cfc47c4-7ffe0cfc47c8 2058->2063 2064 7ffe0cfc47d3-7ffe0cfc47d6 2058->2064 2060 7ffe0cfc4703-7ffe0cfc4707 2059->2060 2061 7ffe0cfc4712-7ffe0cfc4715 2059->2061 2060->2061 2067 7ffe0cfc4709-7ffe0cfc470c _Py_Dealloc 2060->2067 2061->2054 2061->2058 2068 7ffe0cfc4751-7ffe0cfc4753 2062->2068 2069 7ffe0cfc4742-7ffe0cfc4746 2062->2069 2063->2064 2070 7ffe0cfc47ca-7ffe0cfc47cd _Py_Dealloc 2063->2070 2065 7ffe0cfc47d8-7ffe0cfc47dc 2064->2065 2066 7ffe0cfc47e7-7ffe0cfc47ea 2064->2066 2065->2066 2071 7ffe0cfc47de-7ffe0cfc47e1 _Py_Dealloc 2065->2071 2066->2048 2072 7ffe0cfc47ec-7ffe0cfc47f0 2066->2072 2067->2061 2068->2066 2074 7ffe0cfc4759-7ffe0cfc4768 2068->2074 2069->2068 2073 7ffe0cfc4748-7ffe0cfc474b _Py_Dealloc 2069->2073 2070->2064 2071->2066 2072->2048 2075 7ffe0cfc47f2-7ffe0cfc47f5 _Py_Dealloc 2072->2075 2073->2068 2074->2051 2076 7ffe0cfc476e-7ffe0cfc4776 2074->2076 2075->2048 2076->2053
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$ItemObject_$Err_FormatFromImportObjectUnicode_$AttrClearDict_ErrorFilenameImport_LevelModuleModule_
                                                                                                                                                                                                              • String ID: %U.%U$cannot import name %R from %R (%S)
                                                                                                                                                                                                              • API String ID: 3630264407-438398067
                                                                                                                                                                                                              • Opcode ID: fcd6dac6a765cb05053f4bfe7cd39cb166bae5586e68d4d28e2f2c7c25a5bf2f
                                                                                                                                                                                                              • Instruction ID: abcb3e26be2af732e9aaa120bc62f34fa1ceea54535df309e7696915739436a6
                                                                                                                                                                                                              • Opcode Fuzzy Hash: fcd6dac6a765cb05053f4bfe7cd39cb166bae5586e68d4d28e2f2c7c25a5bf2f
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 28515076A48A4282EA148F19A9546796BE1FF45FDAF444031CE8E43BB4DF3CE055CB02

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              • Executed
                                                                                                                                                                                                              • Not Executed
                                                                                                                                                                                                              control_flow_graph 2320 7ffdfad348a0-7ffdfad348cf TlsGetValue 2321 7ffdfad348e1-7ffdfad348e4 2320->2321 2322 7ffdfad348d1-7ffdfad348d3 2320->2322 2324 7ffdfad34921-7ffdfad34934 2321->2324 2325 7ffdfad348e6-7ffdfad348f4 call 7ffdfad9fe10 2321->2325 2322->2321 2323 7ffdfad348d5-7ffdfad348d8 2322->2323 2323->2321 2328 7ffdfad348da-7ffdfad348dd 2323->2328 2326 7ffdfad3496e-7ffdfad34971 2324->2326 2327 7ffdfad34936-7ffdfad34939 2324->2327 2335 7ffdfad34985-7ffdfad349d1 call 7ffdfad7a3f0 TlsGetValue 2325->2335 2336 7ffdfad348fa-7ffdfad3491c call 7ffdfada0bd0 2325->2336 2332 7ffdfad34975-7ffdfad34984 2326->2332 2330 7ffdfad34957-7ffdfad3496d 2327->2330 2331 7ffdfad3493b-7ffdfad3493e 2327->2331 2328->2321 2331->2332 2334 7ffdfad34940-7ffdfad34956 2331->2334 2341 7ffdfad349d3-7ffdfad349d5 2335->2341 2342 7ffdfad349e6-7ffdfad349e9 2335->2342 2336->2324 2341->2342 2345 7ffdfad349d7-7ffdfad349da 2341->2345 2343 7ffdfad34a26-7ffdfad34a29 2342->2343 2344 7ffdfad349eb-7ffdfad349f9 call 7ffdfad9fe10 2342->2344 2347 7ffdfad34a2f-7ffdfad34a32 2343->2347 2348 7ffdfad34ae6-7ffdfad34ae9 2343->2348 2357 7ffdfad349ff-7ffdfad34a21 call 7ffdfada0bd0 2344->2357 2358 7ffdfad34b38-7ffdfad34b49 call 7ffdfad7a3f0 2344->2358 2345->2342 2349 7ffdfad349dc-7ffdfad349e2 2345->2349 2351 7ffdfad34a90-7ffdfad34a93 2347->2351 2352 7ffdfad34a34-7ffdfad34a37 2347->2352 2353 7ffdfad34b21 2348->2353 2354 7ffdfad34aeb-7ffdfad34af7 call 7ffdfadcaaa0 2348->2354 2349->2342 2355 7ffdfad34acf-7ffdfad34ae5 2351->2355 2356 7ffdfad34a95-7ffdfad34aa1 call 7ffdfadcaaa0 2351->2356 2359 7ffdfad34b25-7ffdfad34b37 2352->2359 2360 7ffdfad34a3d-7ffdfad34a40 2352->2360 2353->2359 2367 7ffdfad34afc-7ffdfad34b03 2354->2367 2369 7ffdfad34aa6-7ffdfad34aad 2356->2369 2357->2343 2375 7ffdfad34b4a-7ffdfad34b56 call 7ffdfad7a3f0 2358->2375 2365 7ffdfad34a42-7ffdfad34a4b call 7ffdfadcaaa0 2360->2365 2366 7ffdfad34a79-7ffdfad34a8f 2360->2366 2376 7ffdfad34a50-7ffdfad34a57 2365->2376 2367->2353 2368 7ffdfad34b05-7ffdfad34b1c 2367->2368 2372 7ffdfad34b1e 2368->2372 2373 7ffdfad34b64-7ffdfad34ba8 call 7ffdfad7a3f0 call 7ffdfad9fe10 2368->2373 2369->2355 2374 7ffdfad34aaf-7ffdfad34ac6 2369->2374 2372->2353 2389 7ffdfad34bcd-7ffdfad34bf2 call 7ffdfad7a3f0 2373->2389 2390 7ffdfad34baa-7ffdfad34bcc 2373->2390 2378 7ffdfad34b57-7ffdfad34b63 call 7ffdfad7a3f0 2374->2378 2379 7ffdfad34acc 2374->2379 2375->2378 2376->2366 2381 7ffdfad34a59-7ffdfad34a70 2376->2381 2378->2373 2379->2355 2381->2375 2384 7ffdfad34a76 2381->2384 2384->2366 2393 7ffdfad34bf8-7ffdfad34bfb 2389->2393 2394 7ffdfad34cca-7ffdfad34ccf 2389->2394 2395 7ffdfad34bfd-7ffdfad34c01 2393->2395 2396 7ffdfad34c03-7ffdfad34c0d 2393->2396 2395->2396 2397 7ffdfad34c15-7ffdfad34c1c 2395->2397 2396->2393 2398 7ffdfad34c0f-7ffdfad34c14 2396->2398 2399 7ffdfad34c1e-7ffdfad34c22 2397->2399 2400 7ffdfad34c24 2397->2400 2401 7ffdfad34c28-7ffdfad34c2f 2399->2401 2400->2401 2402 7ffdfad34c31-7ffdfad34c4a TlsAlloc 2401->2402 2403 7ffdfad34c52 2401->2403 2404 7ffdfad34c50 2402->2404 2405 7ffdfad34d4a-7ffdfad34d56 call 7ffdfad7a3f0 2402->2405 2406 7ffdfad34c58-7ffdfad34c6b TlsGetValue 2403->2406 2404->2406 2410 7ffdfad34d57-7ffdfad34d87 call 7ffdfad7a3f0 2405->2410 2407 7ffdfad34c6d-7ffdfad34c75 GetLastError 2406->2407 2408 7ffdfad34c7b-7ffdfad34c7e 2406->2408 2407->2408 2407->2410 2411 7ffdfad34c80-7ffdfad34c85 call 7ffdfad9fc10 2408->2411 2412 7ffdfad34c88-7ffdfad34c93 2408->2412 2425 7ffdfad34dac-7ffdfad34dbc call 7ffdfad9fe10 2410->2425 2426 7ffdfad34d89-7ffdfad34d99 2410->2426 2411->2412 2415 7ffdfad34d32-7ffdfad34d49 call 7ffdfad7a3f0 2412->2415 2416 7ffdfad34c99-7ffdfad34c9c 2412->2416 2415->2405 2416->2415 2420 7ffdfad34ca2-7ffdfad34ca9 2416->2420 2423 7ffdfad34cd0-7ffdfad34cf0 2420->2423 2424 7ffdfad34cab-7ffdfad34cbf GetProcessHeap HeapFree 2420->2424 2427 7ffdfad34cf2 2423->2427 2428 7ffdfad34cf6-7ffdfad34d07 2423->2428 2430 7ffdfad34cc5 2424->2430 2436 7ffdfad34dc2-7ffdfad34e2e call 7ffdfac97a70 2425->2436 2437 7ffdfad34e8c-7ffdfad34eba call 7ffdfad7a3f0 2425->2437 2426->2425 2434 7ffdfad34d9b-7ffdfad34da6 2426->2434 2427->2428 2428->2430 2432 7ffdfad34d09-7ffdfad34d19 2428->2432 2430->2394 2432->2430 2435 7ffdfad34d1b-7ffdfad34d2c 2432->2435 2434->2425 2438 7ffdfad34e7e-7ffdfad34e8b 2434->2438 2435->2415 2436->2438 2443 7ffdfad34e30-7ffdfad34e35 call 7ffdfad349a0 2436->2443 2444 7ffdfad34ec0-7ffdfad34ec3 2437->2444 2449 7ffdfad34e3a-7ffdfad34e3d 2443->2449 2446 7ffdfad35024-7ffdfad3503a call 7ffdfad2aa50 2444->2446 2447 7ffdfad34ec9-7ffdfad34ed9 2444->2447 2447->2444 2450 7ffdfad34edb-7ffdfad34eef 2447->2450 2452 7ffdfad34e3f-7ffdfad34e45 call 7ffdfad35250 2449->2452 2453 7ffdfad34e4a-7ffdfad34e4f call 7ffdfad349a0 2449->2453 2454 7ffdfad34ef4-7ffdfad34f08 2450->2454 2452->2453 2459 7ffdfad34e54-7ffdfad34e57 2453->2459 2455 7ffdfad34f0e 2454->2455 2456 7ffdfad34fb9-7ffdfad34fd6 call 7ffdfad2a980 2454->2456 2460 7ffdfad34f10-7ffdfad34f18 2455->2460 2472 7ffdfad34fd8-7ffdfad34fdd 2456->2472 2473 7ffdfad34fea-7ffdfad34fee 2456->2473 2462 7ffdfad34e64-7ffdfad34e69 call 7ffdfad349a0 2459->2462 2463 7ffdfad34e59-7ffdfad34e5f call 7ffdfad35250 2459->2463 2464 7ffdfad34f1e-7ffdfad34f21 2460->2464 2465 7ffdfad34faa 2460->2465 2476 7ffdfad34e6e-7ffdfad34e71 2462->2476 2463->2462 2468 7ffdfad34f23-7ffdfad34f2a 2464->2468 2469 7ffdfad34f2c 2464->2469 2471 7ffdfad34fad-7ffdfad34fb3 2465->2471 2475 7ffdfad34f30-7ffdfad34f50 call 7ffdfad3ca30 2468->2475 2469->2475 2471->2456 2471->2460 2472->2473 2477 7ffdfad34fdf-7ffdfad34fe5 call 7ffdfad37160 2472->2477 2474 7ffdfad34ff0-7ffdfad34ff3 2473->2474 2478 7ffdfad34ff5-7ffdfad35004 2474->2478 2479 7ffdfad3500b-7ffdfad3501f 2474->2479 2486 7ffdfad34fa0-7ffdfad34fa8 call 7ffdfad9ff60 2475->2486 2487 7ffdfad34f52-7ffdfad34f5d 2475->2487 2476->2438 2481 7ffdfad34e73-7ffdfad34e79 call 7ffdfad35250 2476->2481 2477->2473 2478->2474 2483 7ffdfad35006 2478->2483 2479->2446 2481->2438 2483->2454 2486->2471 2489 7ffdfad34f5f-7ffdfad34f64 2487->2489 2490 7ffdfad34f75-7ffdfad34f7c 2487->2490 2489->2490 2494 7ffdfad34f66-7ffdfad34f73 call 7ffdfad75b50 call 7ffdfad9ff60 2489->2494 2491 7ffdfad34f7e-7ffdfad34f85 2490->2491 2492 7ffdfad34f8c-7ffdfad34f9b call 7ffdfada0420 2490->2492 2491->2492 2495 7ffdfad34f87 call 7ffdfad9ff60 2491->2495 2492->2486 2494->2471 2495->2492
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • TlsGetValue.KERNEL32(?,?,00000000,00007FFDFADCAFA3), ref: 00007FFDFAD348BD
                                                                                                                                                                                                              • TlsGetValue.KERNEL32(?,?,00000000,00007FFDFAD10978), ref: 00007FFDFAD349BC
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADCAAA0: GetStdHandle.KERNEL32(?,?,00000000,00007FFDFAD34AFC,?,?,00000000,00007FFDFAD10978), ref: 00007FFDFADCAAED
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Value$Handle
                                                                                                                                                                                                              • String ID: Tcl_RegisterChannel: channel without name$TlsGetValue failed from TclpGetAllocCache$alloc: invalid block: %p: %x %x$could not allocate thread local storage$tclIO$unable to alloc %u bytes
                                                                                                                                                                                                              • API String ID: 3425772803-4194417986
                                                                                                                                                                                                              • Opcode ID: 186addaf73a5ae1c6aef45da1457d388db4f8a927d9b178b17dcef95f23d69e7
                                                                                                                                                                                                              • Instruction ID: 1147e2d925c491bcbe644f51ba7e4b3cd7130039e41031cd64dcca21eb160b97
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 186addaf73a5ae1c6aef45da1457d388db4f8a927d9b178b17dcef95f23d69e7
                                                                                                                                                                                                              • Instruction Fuzzy Hash: EC227D72B18B4186EB589F15E860AB963A0FF98B84F184175DA6D477DDEF3CE881C700

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              • Executed
                                                                                                                                                                                                              • Not Executed
                                                                                                                                                                                                              control_flow_graph 2502 7ff7b35c1930-7ff7b35c196b call 7ff7b35c39e0 2505 7ff7b35c1971-7ff7b35c19b1 call 7ff7b35c73e0 2502->2505 2506 7ff7b35c1c2e-7ff7b35c1c52 call 7ff7b35cbab0 2502->2506 2511 7ff7b35c19b7-7ff7b35c19c7 call 7ff7b35cfbcc 2505->2511 2512 7ff7b35c1c1b-7ff7b35c1c1e call 7ff7b35cf544 2505->2512 2517 7ff7b35c19c9-7ff7b35c19e3 call 7ff7b35d5de8 call 7ff7b35c2020 2511->2517 2518 7ff7b35c19e8-7ff7b35c1a04 call 7ff7b35cf894 2511->2518 2516 7ff7b35c1c23-7ff7b35c1c2b 2512->2516 2516->2506 2517->2512 2524 7ff7b35c1a06-7ff7b35c1a20 call 7ff7b35d5de8 call 7ff7b35c2020 2518->2524 2525 7ff7b35c1a25-7ff7b35c1a3a call 7ff7b35d5e08 2518->2525 2524->2512 2532 7ff7b35c1a3c-7ff7b35c1a56 call 7ff7b35d5de8 call 7ff7b35c2020 2525->2532 2533 7ff7b35c1a5b-7ff7b35c1ae5 call 7ff7b35c1c60 * 2 call 7ff7b35cfbcc call 7ff7b35d5e24 2525->2533 2532->2512 2546 7ff7b35c1aea-7ff7b35c1af4 2533->2546 2547 7ff7b35c1af6-7ff7b35c1b10 call 7ff7b35d5de8 call 7ff7b35c2020 2546->2547 2548 7ff7b35c1b15-7ff7b35c1b2e call 7ff7b35cf894 2546->2548 2547->2512 2554 7ff7b35c1b30-7ff7b35c1b4a call 7ff7b35d5de8 call 7ff7b35c2020 2548->2554 2555 7ff7b35c1b4f-7ff7b35c1b6b call 7ff7b35cf608 2548->2555 2554->2512 2562 7ff7b35c1b7e-7ff7b35c1b8c 2555->2562 2563 7ff7b35c1b6d-7ff7b35c1b79 call 7ff7b35c1e50 2555->2563 2562->2512 2566 7ff7b35c1b92-7ff7b35c1b99 2562->2566 2563->2512 2568 7ff7b35c1ba1-7ff7b35c1ba7 2566->2568 2569 7ff7b35c1bc0-7ff7b35c1bcf 2568->2569 2570 7ff7b35c1ba9-7ff7b35c1bb6 2568->2570 2569->2569 2571 7ff7b35c1bd1-7ff7b35c1bda 2569->2571 2570->2571 2572 7ff7b35c1bef 2571->2572 2573 7ff7b35c1bdc-7ff7b35c1bdf 2571->2573 2574 7ff7b35c1bf1-7ff7b35c1c04 2572->2574 2573->2572 2575 7ff7b35c1be1-7ff7b35c1be4 2573->2575 2577 7ff7b35c1c06 2574->2577 2578 7ff7b35c1c0d-7ff7b35c1c19 2574->2578 2575->2572 2576 7ff7b35c1be6-7ff7b35c1be9 2575->2576 2576->2572 2579 7ff7b35c1beb-7ff7b35c1bed 2576->2579 2577->2578 2578->2512 2578->2568 2579->2574
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C73E0: _fread_nolock.LIBCMT ref: 00007FF7B35C748A
                                                                                                                                                                                                              • _fread_nolock.LIBCMT ref: 00007FF7B35C19FB
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C2020: GetCurrentProcessId.KERNEL32(?,?,?,?,00000000,00000000,?,00000000,00007FF7B35C1B4A), ref: 00007FF7B35C2070
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _fread_nolock$CurrentProcess
                                                                                                                                                                                                              • String ID: Could not allocate buffer for TOC!$Could not allocate memory for archive structure!$Could not read full TOC!$Error on file.$Failed to read cookie!$Failed to seek to cookie position!$MEI$calloc$fread$fseek$malloc
                                                                                                                                                                                                              • API String ID: 2397952137-3497178890
                                                                                                                                                                                                              • Opcode ID: d1197599a16fac8870182a8f163e3d77f1811fa96085cff4d8b228ddc3630bbf
                                                                                                                                                                                                              • Instruction ID: 42803647da48ae187e15adf96d406c0948755155947795f1c1a27333e7a1d452
                                                                                                                                                                                                              • Opcode Fuzzy Hash: d1197599a16fac8870182a8f163e3d77f1811fa96085cff4d8b228ddc3630bbf
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 9C818371A0C68285E790EB38D4412B9A3A1AF66748FD04131EB8D6765DDE3CE6C58B70

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              • Executed
                                                                                                                                                                                                              • Not Executed
                                                                                                                                                                                                              control_flow_graph 2709 7ffe0cfc8ec3-7ffe0cfc8f09 call 7ffe0cfc41e0 2712 7ffe0cfc8f0b-7ffe0cfc8f15 call 7ffe0cfd23a0 2709->2712 2713 7ffe0cfc8f43-7ffe0cfc8f4d 2709->2713 2719 7ffe0cfc8f1a-7ffe0cfc8f1c 2712->2719 2715 7ffe0cfc8f69-7ffe0cfc8f6c 2713->2715 2716 7ffe0cfc8f4f-7ffe0cfc8f58 2713->2716 2717 7ffe0cfc8f6e-7ffe0cfc8f70 2715->2717 2718 7ffe0cfc8f81-7ffe0cfc8f8b 2715->2718 2716->2715 2720 7ffe0cfc8f5a-7ffe0cfc8f5e 2716->2720 2717->2718 2721 7ffe0cfc8f72-7ffe0cfc8f76 2717->2721 2722 7ffe0cfc8f8d-7ffe0cfc8f96 2718->2722 2723 7ffe0cfc8fa4-7ffe0cfc8fae 2718->2723 2719->2713 2724 7ffe0cfc8f1e-7ffe0cfc8f20 2719->2724 2720->2715 2725 7ffe0cfc8f60-7ffe0cfc8f63 _Py_Dealloc 2720->2725 2721->2718 2726 7ffe0cfc8f78-7ffe0cfc8f7b _Py_Dealloc 2721->2726 2722->2723 2727 7ffe0cfc8f98-7ffe0cfc8f9c 2722->2727 2728 7ffe0cfc8fc7-7ffe0cfc8fd1 2723->2728 2729 7ffe0cfc8fb0-7ffe0cfc8fb9 2723->2729 2730 7ffe0cfc8f22-7ffe0cfc8f26 2724->2730 2731 7ffe0cfc8f31-7ffe0cfc8f42 2724->2731 2725->2715 2726->2718 2727->2723 2732 7ffe0cfc8f9e _Py_Dealloc 2727->2732 2735 7ffe0cfc8fea-7ffe0cfc8ff4 2728->2735 2736 7ffe0cfc8fd3-7ffe0cfc8fdc 2728->2736 2729->2728 2733 7ffe0cfc8fbb-7ffe0cfc8fbf 2729->2733 2730->2731 2734 7ffe0cfc8f28-7ffe0cfc8f2b _Py_Dealloc 2730->2734 2732->2723 2733->2728 2739 7ffe0cfc8fc1 _Py_Dealloc 2733->2739 2734->2731 2737 7ffe0cfc900d-7ffe0cfc9017 2735->2737 2738 7ffe0cfc8ff6-7ffe0cfc8fff 2735->2738 2736->2735 2740 7ffe0cfc8fde-7ffe0cfc8fe2 2736->2740 2742 7ffe0cfc9019-7ffe0cfc9022 2737->2742 2743 7ffe0cfc9030-7ffe0cfc903a 2737->2743 2738->2737 2741 7ffe0cfc9001-7ffe0cfc9005 2738->2741 2739->2728 2740->2735 2744 7ffe0cfc8fe4 _Py_Dealloc 2740->2744 2741->2737 2745 7ffe0cfc9007 _Py_Dealloc 2741->2745 2742->2743 2746 7ffe0cfc9024-7ffe0cfc9028 2742->2746 2747 7ffe0cfc903c-7ffe0cfc9045 2743->2747 2748 7ffe0cfc9053-7ffe0cfc905d 2743->2748 2744->2735 2745->2737 2746->2743 2749 7ffe0cfc902a _Py_Dealloc 2746->2749 2747->2748 2750 7ffe0cfc9047-7ffe0cfc904b 2747->2750 2751 7ffe0cfc9076-7ffe0cfc9080 2748->2751 2752 7ffe0cfc905f-7ffe0cfc9068 2748->2752 2749->2743 2750->2748 2755 7ffe0cfc904d _Py_Dealloc 2750->2755 2753 7ffe0cfc9099-7ffe0cfc90a3 2751->2753 2754 7ffe0cfc9082-7ffe0cfc908b 2751->2754 2752->2751 2756 7ffe0cfc906a-7ffe0cfc906e 2752->2756 2758 7ffe0cfc90bc-7ffe0cfc90c6 2753->2758 2759 7ffe0cfc90a5-7ffe0cfc90ae 2753->2759 2754->2753 2757 7ffe0cfc908d-7ffe0cfc9091 2754->2757 2755->2748 2756->2751 2760 7ffe0cfc9070 _Py_Dealloc 2756->2760 2757->2753 2761 7ffe0cfc9093 _Py_Dealloc 2757->2761 2763 7ffe0cfc90c8-7ffe0cfc90d1 2758->2763 2764 7ffe0cfc90df-7ffe0cfc90eb 2758->2764 2759->2758 2762 7ffe0cfc90b0-7ffe0cfc90b4 2759->2762 2760->2751 2761->2753 2762->2758 2765 7ffe0cfc90b6 _Py_Dealloc 2762->2765 2763->2764 2766 7ffe0cfc90d3-7ffe0cfc90d7 2763->2766 2765->2758 2766->2764 2767 7ffe0cfc90d9 _Py_Dealloc 2766->2767 2767->2764
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$Unicode_$FromInternPlaceSizeString
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2745024575-0
                                                                                                                                                                                                              • Opcode ID: 091893d1f0e79c71c802a693a5176002506af28f025ec817263c4d69333cf0a2
                                                                                                                                                                                                              • Instruction ID: be87f4b5215ccc4891e29672471c78c50b1a812b27d13b6ea60f6e605acecb50
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 091893d1f0e79c71c802a693a5176002506af28f025ec817263c4d69333cf0a2
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 5C71D435ECAA0285FB558F6CBA8423433E6BF84B9AF144534C98E466B0DF7EA541C713

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentProcess
                                                                                                                                                                                                              • String ID: Failed to extract %s: failed to allocate data buffer (%u bytes)!$Failed to extract %s: failed to open archive file!$Failed to extract %s: failed to read data chunk!$Failed to extract %s: failed to seek to the entry's data!$fread$fseek$malloc
                                                                                                                                                                                                              • API String ID: 2050909247-3659356012
                                                                                                                                                                                                              • Opcode ID: b7dff6e97b1ce8735ebf3024584f3f9176618c683b604bbb07704a4264a016bf
                                                                                                                                                                                                              • Instruction ID: fa3c0ee27dbb9421933613d3e3119414e96562073457b4a992a43741a708c9db
                                                                                                                                                                                                              • Opcode Fuzzy Hash: b7dff6e97b1ce8735ebf3024584f3f9176618c683b604bbb07704a4264a016bf
                                                                                                                                                                                                              • Instruction Fuzzy Hash: AF419231A0C64245EA80FB39D4405B9A390EF66788FC44532EF4D27B9EDE3CE6858B70

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • LeaveCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,00007FFDFAD11DA5), ref: 00007FFDFAD049B6
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD05700: LeaveCriticalSection.KERNEL32 ref: 00007FFDFAD05807
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: TlsAlloc.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE21
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: TlsGetValue.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE4F
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: GetLastError.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE5D
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: GetProcessHeap.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE9B
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: HeapAlloc.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FEA9
                                                                                                                                                                                                              • memset.VCRUNTIME140 ref: 00007FFDFAD04A7A
                                                                                                                                                                                                              • memset.VCRUNTIME140 ref: 00007FFDFAD04AAA
                                                                                                                                                                                                              • memset.VCRUNTIME140 ref: 00007FFDFAD04AD4
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: memset$AllocCriticalHeapLeaveSection$ErrorLastProcessValue
                                                                                                                                                                                                              • String ID: identity$iso8859-1$unable to alloc %u bytes$unicode$utf-8
                                                                                                                                                                                                              • API String ID: 313328654-3412666474
                                                                                                                                                                                                              • Opcode ID: d652154ad2db49e51dbe81ec655c56e2561822c960565187f2a6835efab234d7
                                                                                                                                                                                                              • Instruction ID: bc3d63782c2c5638761a672f98e6bb6df0088d7bffe4e4a52e605b2b05cd1cab
                                                                                                                                                                                                              • Opcode Fuzzy Hash: d652154ad2db49e51dbe81ec655c56e2561822c960565187f2a6835efab234d7
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 86710935B19B5688EB08DB10ECA0AA973B5FB48748F4481B5CA6D077EDEF3DA155C340

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              • Executed
                                                                                                                                                                                                              • Not Executed
                                                                                                                                                                                                              control_flow_graph 3004 7ff7b35c11f0-7ff7b35c124d call 7ff7b35cb2e0 3007 7ff7b35c124f-7ff7b35c1276 call 7ff7b35c1e50 3004->3007 3008 7ff7b35c1277-7ff7b35c128f call 7ff7b35d5e24 3004->3008 3013 7ff7b35c1291-7ff7b35c12af call 7ff7b35d5de8 call 7ff7b35c2020 3008->3013 3014 7ff7b35c12b4-7ff7b35c12c4 call 7ff7b35d5e24 3008->3014 3027 7ff7b35c1419-7ff7b35c144d call 7ff7b35cafc0 call 7ff7b35d5e10 * 2 3013->3027 3020 7ff7b35c12c6-7ff7b35c12e4 call 7ff7b35d5de8 call 7ff7b35c2020 3014->3020 3021 7ff7b35c12e9-7ff7b35c12fb 3014->3021 3020->3027 3022 7ff7b35c1300-7ff7b35c131d call 7ff7b35cf894 3021->3022 3030 7ff7b35c1322-7ff7b35c1325 3022->3030 3033 7ff7b35c1411 3030->3033 3034 7ff7b35c132b-7ff7b35c1335 call 7ff7b35cf608 3030->3034 3033->3027 3034->3033 3040 7ff7b35c133b-7ff7b35c1347 3034->3040 3042 7ff7b35c1350-7ff7b35c1378 call 7ff7b35c9720 3040->3042 3045 7ff7b35c13f6-7ff7b35c140c call 7ff7b35c1e50 3042->3045 3046 7ff7b35c137a-7ff7b35c137d 3042->3046 3045->3033 3048 7ff7b35c13f1 3046->3048 3049 7ff7b35c137f-7ff7b35c1389 3046->3049 3048->3045 3050 7ff7b35c13b4-7ff7b35c13b7 3049->3050 3051 7ff7b35c138b-7ff7b35c13a1 call 7ff7b35cffd4 3049->3051 3053 7ff7b35c13ca-7ff7b35c13cf 3050->3053 3054 7ff7b35c13b9-7ff7b35c13c7 call 7ff7b35eb040 3050->3054 3058 7ff7b35c13af-7ff7b35c13b2 3051->3058 3059 7ff7b35c13a3-7ff7b35c13ad call 7ff7b35cf608 3051->3059 3053->3042 3057 7ff7b35c13d5-7ff7b35c13d8 3053->3057 3054->3053 3061 7ff7b35c13da-7ff7b35c13dd 3057->3061 3062 7ff7b35c13ec-7ff7b35c13ef 3057->3062 3058->3045 3059->3053 3059->3058 3061->3045 3064 7ff7b35c13df-7ff7b35c13e7 3061->3064 3062->3033 3064->3022
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentProcess
                                                                                                                                                                                                              • String ID: 1.3.1$Failed to extract %s: decompression resulted in return code %d!$Failed to extract %s: failed to allocate temporary input buffer!$Failed to extract %s: failed to allocate temporary output buffer!$Failed to extract %s: inflateInit() failed with return code %d!$malloc
                                                                                                                                                                                                              • API String ID: 2050909247-2813020118
                                                                                                                                                                                                              • Opcode ID: 0c2cb33e831b21f1d98b5c0ea7792bc460bd7d74e64b82b700147852c2791a02
                                                                                                                                                                                                              • Instruction ID: bd710fbe172637b109934f62affdd9bbca64bf85f92d1931382b22b63f49aa1a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 0c2cb33e831b21f1d98b5c0ea7792bc460bd7d74e64b82b700147852c2791a02
                                                                                                                                                                                                              • Instruction Fuzzy Hash: EF51E662A0C54245EAA0BB39A4403BAA291FF66B98FD44131DF4D6778DDF3CE585C730

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • GetModuleFileNameW.KERNEL32(?,00007FF7B35C2BC5), ref: 00007FF7B35C2AA1
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,00007FF7B35C2BC5), ref: 00007FF7B35C2AAB
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C2310: GetCurrentProcessId.KERNEL32(?,?,?,?,?,?,?,?,00007FF7B35C2AC6,?,00007FF7B35C2BC5), ref: 00007FF7B35C2360
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C2310: FormatMessageW.KERNEL32(?,?,?,?,?,?,?,?,00007FF7B35C2AC6,?,00007FF7B35C2BC5), ref: 00007FF7B35C241A
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentErrorFileFormatLastMessageModuleNameProcess
                                                                                                                                                                                                              • String ID: Failed to convert executable path to UTF-8.$Failed to obtain executable path.$Failed to resolve full path to executable %ls.$GetModuleFileNameW$\\?\
                                                                                                                                                                                                              • API String ID: 4002088556-2863816727
                                                                                                                                                                                                              • Opcode ID: aed140f8d8e2637361ba54921802919f4f3b7eb641456186ceb893f60fbbd120
                                                                                                                                                                                                              • Instruction ID: 83e1c0f940390364d6f95c9b4243a29a8cd590a4510b437e074f8937645e1f6e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: aed140f8d8e2637361ba54921802919f4f3b7eb641456186ceb893f60fbbd120
                                                                                                                                                                                                              • Instruction Fuzzy Hash: A2219461B1C64291FAA4BB3DE8043B59250BF6A348FC00232E75DA65DDEE2CE5C48334

                                                                                                                                                                                                              Control-flow Graph

                                                                                                                                                                                                              • Executed
                                                                                                                                                                                                              • Not Executed
                                                                                                                                                                                                              control_flow_graph 3094 7ffdfad052a0-7ffdfad05360 call 7ffdfada0280 call 7ffdfaddfa00 3099 7ffdfad05368-7ffdfad0536a 3094->3099 3100 7ffdfad05455-7ffdfad0546e LeaveCriticalSection call 7ffdfad04510 call 7ffdfadad510 3099->3100 3101 7ffdfad05370-7ffdfad0537c 3099->3101 3109 7ffdfad05473-7ffdfad05481 3100->3109 3101->3099 3102 7ffdfad0537e 3101->3102 3104 7ffdfad05381-7ffdfad0538b 3102->3104 3106 7ffdfad053e7-7ffdfad053ef call 7ffdfada0280 3104->3106 3107 7ffdfad0538d 3104->3107 3117 7ffdfad053f1-7ffdfad053fe 3106->3117 3111 7ffdfad05394-7ffdfad0539b 3107->3111 3112 7ffdfad054a3-7ffdfad054ae 3109->3112 3113 7ffdfad05483-7ffdfad0548f call 7ffdfacfa100 3109->3113 3111->3111 3115 7ffdfad0539d-7ffdfad053aa call 7ffdfada0280 3111->3115 3118 7ffdfad054b0-7ffdfad054b8 3112->3118 3119 7ffdfad0551d-7ffdfad05520 3112->3119 3113->3112 3126 7ffdfad05491-7ffdfad054a1 3113->3126 3115->3117 3131 7ffdfad053ac-7ffdfad053ba call 7ffdfad9fe10 3115->3131 3122 7ffdfad05403-7ffdfad0541d 3117->3122 3124 7ffdfad054bc-7ffdfad054c6 3118->3124 3123 7ffdfad05524-7ffdfad05526 3119->3123 3138 7ffdfad05442-7ffdfad05448 3122->3138 3139 7ffdfad0541f-7ffdfad0542d 3122->3139 3127 7ffdfad0558a-7ffdfad055c4 call 7ffdfad8bd50 call 7ffdfad2aa50 3123->3127 3128 7ffdfad05528-7ffdfad05534 3123->3128 3129 7ffdfad054c8-7ffdfad054cc 3124->3129 3130 7ffdfad054ce 3124->3130 3133 7ffdfad054d2-7ffdfad054e1 3126->3133 3128->3123 3135 7ffdfad05536-7ffdfad05539 3128->3135 3129->3133 3130->3133 3147 7ffdfad053bc-7ffdfad053be 3131->3147 3148 7ffdfad053c4-7ffdfad053e5 memcpy 3131->3148 3133->3119 3153 7ffdfad054e3-7ffdfad054e7 3133->3153 3140 7ffdfad05540-7ffdfad0554e 3135->3140 3138->3104 3143 7ffdfad05430-7ffdfad05432 3139->3143 3144 7ffdfad05554-7ffdfad05561 call 7ffdfad51ff0 3140->3144 3145 7ffdfad05550 3140->3145 3150 7ffdfad05434-7ffdfad05440 3143->3150 3151 7ffdfad0544d-7ffdfad05451 3143->3151 3161 7ffdfad05563-7ffdfad0556a 3144->3161 3162 7ffdfad05582-7ffdfad05588 3144->3162 3145->3144 3147->3148 3154 7ffdfad055c5-7ffdfad055d3 call 7ffdfad7a3f0 3147->3154 3148->3122 3150->3138 3150->3143 3151->3100 3157 7ffdfad055d4-7ffdfad055f9 call 7ffdfad7a3f0 3153->3157 3158 7ffdfad054ed-7ffdfad054f3 3153->3158 3154->3157 3170 7ffdfad055fb-7ffdfad055fe 3157->3170 3171 7ffdfad05616-7ffdfad05633 call 7ffdfaddfa00 LeaveCriticalSection 3157->3171 3163 7ffdfad054fb-7ffdfad0550b 3158->3163 3164 7ffdfad054f5-7ffdfad054f9 3158->3164 3167 7ffdfad05570-7ffdfad05572 3161->3167 3162->3140 3163->3119 3165 7ffdfad0550d-7ffdfad05518 call 7ffdfacf9b00 call 7ffdfad9ff60 3163->3165 3164->3124 3165->3119 3167->3127 3168 7ffdfad05574-7ffdfad05580 3167->3168 3168->3162 3168->3167 3170->3171 3174 7ffdfad05600 call 7ffdfad04fe0 3170->3174 3179 7ffdfad05639-7ffdfad05654 call 7ffdfaddfa00 3171->3179 3178 7ffdfad05605-7ffdfad0560b 3174->3178 3178->3179 3180 7ffdfad0560d-7ffdfad05615 3178->3180 3183 7ffdfad05656-7ffdfad0565b 3179->3183 3184 7ffdfad0569e-7ffdfad056f2 LeaveCriticalSection call 7ffdfaddfa00 LeaveCriticalSection 3179->3184 3186 7ffdfad056f3-7ffdfad056ff call 7ffdfad7a3f0 3183->3186 3187 7ffdfad05661-7ffdfad0566a 3183->3187 3187->3184 3190 7ffdfad0566c-7ffdfad05673 3187->3190 3192 7ffdfad0567b-7ffdfad05682 3190->3192 3193 7ffdfad05675 3190->3193 3194 7ffdfad05689-7ffdfad0568f 3192->3194 3195 7ffdfad05684 call 7ffdfad2a980 3192->3195 3193->3192 3196 7ffdfad05696-7ffdfad05699 call 7ffdfad9ff60 3194->3196 3197 7ffdfad05691 call 7ffdfad9ff60 3194->3197 3195->3194 3196->3184 3197->3196
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0280: TlsAlloc.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFAD11924), ref: 00007FFDFADA028D
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0280: TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFAD11924), ref: 00007FFDFADA02BB
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0280: GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFAD11924), ref: 00007FFDFADA02C9
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0280: LeaveCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFAD11924), ref: 00007FFDFADA036B
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0280: GetProcessHeap.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFAD11924), ref: 00007FFDFADA037E
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0280: HeapAlloc.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFAD11924), ref: 00007FFDFADA038F
                                                                                                                                                                                                              • memcpy.VCRUNTIME140 ref: 00007FFDFAD053D5
                                                                                                                                                                                                              • LeaveCriticalSection.KERNEL32 ref: 00007FFDFAD0545C
                                                                                                                                                                                                              • LeaveCriticalSection.KERNEL32 ref: 00007FFDFAD056AC
                                                                                                                                                                                                              • LeaveCriticalSection.KERNEL32 ref: 00007FFDFAD056E0
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CriticalLeaveSection$AllocHeap$ErrorLastProcessValuememcpy
                                                                                                                                                                                                              • String ID: FreeEncoding: refcount problem !!!$concurrent dictionary modification and search$unable to alloc %u bytes
                                                                                                                                                                                                              • API String ID: 1241236031-687981174
                                                                                                                                                                                                              • Opcode ID: a0acdfe217a5bab07ea69dd6836d4c172e550d3021eb1511b6a4a176fe26980e
                                                                                                                                                                                                              • Instruction ID: 2a2fcf50b4748884035948e5f29f27072b7e852129a186791206196b73b4ac6a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: a0acdfe217a5bab07ea69dd6836d4c172e550d3021eb1511b6a4a176fe26980e
                                                                                                                                                                                                              • Instruction Fuzzy Hash: B8D18D32B09A5685EB189F15E8A0ABD23A5FB44B94F4881B5CE2E477DCEF3DE451C340
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • GetStdHandle.KERNEL32(?,?,00000000,00007FFDFAD34AFC,?,?,00000000,00007FFDFAD10978), ref: 00007FFDFADCAAED
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Handle
                                                                                                                                                                                                              • String ID: -buffering$-eofchar$-translation$TclGetDefaultStdChannel: Unexpected channel type$auto$line$none
                                                                                                                                                                                                              • API String ID: 2519475695-1068246920
                                                                                                                                                                                                              • Opcode ID: 4378fe44cf6678d02434a5bd790598e4dc8de0408550d8f9589a8f7d3e6a241d
                                                                                                                                                                                                              • Instruction ID: 2ec4ad5d8e26c7d4228ff4b507252f7cfb23c83a4b078056872cb2b054eeab4a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 4378fe44cf6678d02434a5bd790598e4dc8de0408550d8f9589a8f7d3e6a241d
                                                                                                                                                                                                              • Instruction Fuzzy Hash: E821A720B1860741EB1C5765AD758F91293DF44790FD542B6EA3F4B2EAFE2DE9418200
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3215553584-0
                                                                                                                                                                                                              • Opcode ID: b84f99598af9228c6ddbc1f90d02b3ffc499ddb0e7ad6440c3b0aa44b94abea4
                                                                                                                                                                                                              • Instruction ID: 208c28849ad4add9b31f92cfe3a50b1e4305ee1d943763ca229224c843b9b315
                                                                                                                                                                                                              • Opcode Fuzzy Hash: b84f99598af9228c6ddbc1f90d02b3ffc499ddb0e7ad6440c3b0aa44b94abea4
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 13C1E52290C68251F7A0BB289444ABDB751EFA2B80FD54131DB6E2779DDF7CE4C58320
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CriticalLeaveSection
                                                                                                                                                                                                              • String ID: FreeEncoding: refcount problem !!!$PGV Initializer did not initialize$unable to alloc %u bytes
                                                                                                                                                                                                              • API String ID: 3988221542-1397560407
                                                                                                                                                                                                              • Opcode ID: 00cf9e3350454dff5e7d4b4c0e449f8dcd26618a97af673e3c54453f7bb94164
                                                                                                                                                                                                              • Instruction ID: f1f763163dbd4457c493198354bdd48c62eaf5643673813239866f039549bef3
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 00cf9e3350454dff5e7d4b4c0e449f8dcd26618a97af673e3c54453f7bb94164
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 7E713E32B0964696EB1CDF52E9A0AB96360FF48B84F044475DB6E4B6DAEF3CE451C340
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentProcess
                                                                                                                                                                                                              • String ID: Failed to load Python DLL '%ls'.$LoadLibrary$Path of Python shared library (%s) and its name (%s) exceed buffer size (%d)$Path of ucrtbase.dll (%s) and its name exceed buffer size (%d)$Reported length (%d) of Python shared library name (%s) exceeds buffer size (%d)$ucrtbase.dll
                                                                                                                                                                                                              • API String ID: 2050909247-2434346643
                                                                                                                                                                                                              • Opcode ID: e70446ed600507764bec00972ec05a3ec4fb4b34b4d62f745298a6ab68eb802e
                                                                                                                                                                                                              • Instruction ID: 0b222055d0d77214197108a2ccd08004cb5636c456e17c2a9c053fef6c86344a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: e70446ed600507764bec00972ec05a3ec4fb4b34b4d62f745298a6ab68eb802e
                                                                                                                                                                                                              • Instruction Fuzzy Hash: FE417231A1C68691EA91EB79E4441E9A361FF65348FC00132EB5D6369DDE3CE685C370
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: memcpy
                                                                                                                                                                                                              • String ID: LIST$concurrent dictionary modification and search$list$max size for a Tcl value (%d bytes) exceeded$unable to alloc %u bytes
                                                                                                                                                                                                              • API String ID: 3510742995-4178152732
                                                                                                                                                                                                              • Opcode ID: 77f56aba3e70309579e373acb201b80fe29f8675d5d7a9ace1c881df0a5edb10
                                                                                                                                                                                                              • Instruction ID: 0f7efacf83900093c3eca8784d1ac2adf1a7a66df885b8ba1f695c7604cffff8
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 77f56aba3e70309579e373acb201b80fe29f8675d5d7a9ace1c881df0a5edb10
                                                                                                                                                                                                              • Instruction Fuzzy Hash: C202C136B18B8586EB28CB15D870AB973A5FB84B84F144175DE6D07799EF7CE441C700
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADCB2B0: GetFileType.KERNEL32(?,?,?,?,?,?,?,?,00000000,00007FFDFADCA95C), ref: 00007FFDFADCB2CC
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADCB2B0: GetLastError.KERNEL32(?,?,?,?,?,?,?,?,00000000,00007FFDFADCA95C), ref: 00007FFDFADCB2DD
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADCB2B0: GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,00000000,00007FFDFADCA95C), ref: 00007FFDFADCB2EF
                                                                                                                                                                                                              • GetCurrentProcess.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,0000000B), ref: 00007FFDFADCA9DA
                                                                                                                                                                                                              • GetCurrentProcess.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,0000000B), ref: 00007FFDFADCA9E3
                                                                                                                                                                                                              • DuplicateHandle.KERNEL32 ref: 00007FFDFADCAA09
                                                                                                                                                                                                              • CloseHandle.KERNEL32 ref: 00007FFDFADCAA1D
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentHandleProcess$CloseConsoleDuplicateErrorFileLastModeType
                                                                                                                                                                                                              • String ID: line
                                                                                                                                                                                                              • API String ID: 166430681-3507795190
                                                                                                                                                                                                              • Opcode ID: f5ff231514f53abfa0644dac4fba4a87a11f29b967c384714289b26d6a1431ce
                                                                                                                                                                                                              • Instruction ID: 4b11b3eec876c5a66c632382855260b8b7ff2fc3fe26b819c8d9d81be09e6345
                                                                                                                                                                                                              • Opcode Fuzzy Hash: f5ff231514f53abfa0644dac4fba4a87a11f29b967c384714289b26d6a1431ce
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 2021D161B1868186E7288B11BC60B7AB3A1FB88BC0F514475DE5D87BACEF3CD8418B00
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • TlsGetValue.KERNEL32 ref: 00007FFDFAD8A9F8
                                                                                                                                                                                                              • memset.VCRUNTIME140 ref: 00007FFDFAD8AA44
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: TlsAlloc.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE21
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: TlsGetValue.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE4F
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: GetLastError.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE5D
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: GetProcessHeap.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE9B
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: HeapAlloc.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FEA9
                                                                                                                                                                                                              • memcpy.VCRUNTIME140 ref: 00007FFDFAD8B11A
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: AllocHeapValue$ErrorLastProcessmemcpymemset
                                                                                                                                                                                                              • String ID: couldn't compile regular expression pattern: $unable to alloc %u bytes
                                                                                                                                                                                                              • API String ID: 916272630-2728520199
                                                                                                                                                                                                              • Opcode ID: f328b9d37832b2467b2a04e3fe97cf44e5249b6643bfda9b410e0bb7b3b585fe
                                                                                                                                                                                                              • Instruction ID: 8081cb6250287a380396d932b66d9938f666e8f50784c3b6c4576fa258254785
                                                                                                                                                                                                              • Opcode Fuzzy Hash: f328b9d37832b2467b2a04e3fe97cf44e5249b6643bfda9b410e0bb7b3b585fe
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 0B22C136606B858ADB94CF29D8907E933A4F748F58F184136DE9C8B7A8EF38D454C760
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: TlsAlloc.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE21
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: TlsGetValue.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE4F
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: GetLastError.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE5D
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: GetProcessHeap.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE9B
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: HeapAlloc.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FEA9
                                                                                                                                                                                                              • TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000,00000000,::oo::define,00000001,?,00000000), ref: 00007FFDFAD6128B
                                                                                                                                                                                                              • TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,?,?,00000000,00000000,::oo::define,00000001,?,00000000), ref: 00007FFDFAD61365
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Value$AllocHeap$ErrorLastProcess
                                                                                                                                                                                                              • String ID: ::oo::Obj%d$::oo::define$unable to alloc %u bytes
                                                                                                                                                                                                              • API String ID: 827889809-1942930302
                                                                                                                                                                                                              • Opcode ID: 81b024fc376089ebfe4ee257acf0329801e0040a4ba409f7b7110a3688783aec
                                                                                                                                                                                                              • Instruction ID: ab75acddc98a0856299ed62f2c3dd1fdef3eee6f78f1b3de1bddc538eaeb7434
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 81b024fc376089ebfe4ee257acf0329801e0040a4ba409f7b7110a3688783aec
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 4BE17C32B09B4285EB089F15E860BB973A4FF98B84F488175EA5D47799EF3CE495C340
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Valuememcpy
                                                                                                                                                                                                              • String ID: binary encoding is not available$iso8859-1$unable to alloc %u bytes
                                                                                                                                                                                                              • API String ID: 574835123-1438692910
                                                                                                                                                                                                              • Opcode ID: bf20a894e85dcc0cfbca12cbde7f7e0f4b8192a0882f1008b5719ce47968aa4f
                                                                                                                                                                                                              • Instruction ID: f38d7c57fd719ee8edd81b0229e63ececae8a49741222425aae0358d0935cea7
                                                                                                                                                                                                              • Opcode Fuzzy Hash: bf20a894e85dcc0cfbca12cbde7f7e0f4b8192a0882f1008b5719ce47968aa4f
                                                                                                                                                                                                              • Instruction Fuzzy Hash: BBE17037B08B8186D768CF15E864BAA73A4FB88B84F558135DE9D43798EF38D494CB40
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • GetConsoleMode.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF7B35DDDEB), ref: 00007FF7B35DDF1C
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FF7B35DDDEB), ref: 00007FF7B35DDFA7
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ConsoleErrorLastMode
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 953036326-0
                                                                                                                                                                                                              • Opcode ID: 72bdbade8f7f3669228eabd23d25320e309643dcfe9983c62a88d960f5e90d12
                                                                                                                                                                                                              • Instruction ID: 223f08e9d8e09e750f431c0498ea63539936f55019655c1ad33281ed9237dc86
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 72bdbade8f7f3669228eabd23d25320e309643dcfe9983c62a88d960f5e90d12
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 7B91B462A0C65285F790AF3D9440A7DABA0AF66B88F944135DF1E76688DE38D4C5C720
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • memcpy.VCRUNTIME140 ref: 00007FFDFAD42386
                                                                                                                                                                                                              • memcpy.VCRUNTIME140 ref: 00007FFDFAD42410
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0280: TlsAlloc.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFAD11924), ref: 00007FFDFADA028D
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0280: TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFAD11924), ref: 00007FFDFADA02BB
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0280: GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFAD11924), ref: 00007FFDFADA02C9
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0280: LeaveCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFAD11924), ref: 00007FFDFADA036B
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0280: GetProcessHeap.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFAD11924), ref: 00007FFDFADA037E
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0280: HeapAlloc.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFAD11924), ref: 00007FFDFADA038F
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: AllocHeapmemcpy$CriticalErrorLastLeaveProcessSectionValue
                                                                                                                                                                                                              • String ID: chan$unable to alloc %u bytes
                                                                                                                                                                                                              • API String ID: 1951501822-1165644719
                                                                                                                                                                                                              • Opcode ID: e49b6b4a882a48f3326776b5da6bbf9e8c490c792e9277a28422be84d0793328
                                                                                                                                                                                                              • Instruction ID: 3d43c92b413b2aa92ab719675f828650629504739c83523eb807fe70e502ef0e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: e49b6b4a882a48f3326776b5da6bbf9e8c490c792e9277a28422be84d0793328
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 9271E032B08B4286E7589F12ACA0B6A67A0FB48B94F184178DF6D077CDEF3DE5418300
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CloseCreateFileHandle_invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 1279662727-0
                                                                                                                                                                                                              • Opcode ID: 90a68cc1d689661d78c71e507df06edcdc27397f5c551dab54a651660f08bd46
                                                                                                                                                                                                              • Instruction ID: 7e44d842bd0d9aa241b1e207dddb73d3af0aef2e873e0f51b50aec9df5a7e97f
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 90a68cc1d689661d78c71e507df06edcdc27397f5c551dab54a651660f08bd46
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 0641E462D1C78193E790AB349500779A260FFB6764F908334E7AC23AD9DF7CA1E18760
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CommConsoleErrorFileLastModeStateType
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3984557487-0
                                                                                                                                                                                                              • Opcode ID: 362d8e4a3f460dfc9f25ef1ce9f2f67178088f0cf2c9bc588b7a476edcd8b8e4
                                                                                                                                                                                                              • Instruction ID: d8fc0042d6fc92f001d10ec61c2beb8b647197009daecb1c635de2a0f209d12e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 362d8e4a3f460dfc9f25ef1ce9f2f67178088f0cf2c9bc588b7a476edcd8b8e4
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 54012531B0864581F7589B15ECA5A3A63A5EF48BC4F850074DA6E87698EF2CD8448605
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _errno
                                                                                                                                                                                                              • String ID: ctory$unable to alloc %u bytes
                                                                                                                                                                                                              • API String ID: 2918714741-474272330
                                                                                                                                                                                                              • Opcode ID: 5903b7dfcfb57437d9240b503c635d2bc8e5a84fc1e13866a6580c0b45067adf
                                                                                                                                                                                                              • Instruction ID: 69be2a4c9faa28b54e68c56b936a1f154c197cc5c27665233bba8a4a99853642
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 5903b7dfcfb57437d9240b503c635d2bc8e5a84fc1e13866a6580c0b45067adf
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 50A1CE22B0864786EB2D9B259C60A796B94FF44B84F4440B5DE6E477DAFF3CE985C300
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • GetCurrentProcessId.KERNEL32(?,00000000,00000000,?,00000000,00007FF7B35C1B79), ref: 00007FF7B35C1E9E
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentProcess
                                                                                                                                                                                                              • String ID: ERROR$[PYI-%d:%s]
                                                                                                                                                                                                              • API String ID: 2050909247-3005936843
                                                                                                                                                                                                              • Opcode ID: 62cbc377ad39f0f57ac113c1b5e744fc407643feec6e9a2503ac327b26b25e1c
                                                                                                                                                                                                              • Instruction ID: 42211835a5bade373c273f23bb90db599f08387dc6d4d7203d1fde77357c8508
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 62cbc377ad39f0f57ac113c1b5e744fc407643feec6e9a2503ac327b26b25e1c
                                                                                                                                                                                                              • Instruction Fuzzy Hash: C111D17260CB8141E660AB65B8816EAB3A4EF957C4F800131FBCD63A5DDE7CD2858710
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830637851.00007FFE0E161000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFE0E160000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830611219.00007FFE0E160000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830675705.00007FFE0E17B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830706221.00007FFE0E184000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830736890.00007FFE0E185000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830762935.00007FFE0E188000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830790164.00007FFE0E189000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0e160000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: mallocmemcpy
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 4276657696-0
                                                                                                                                                                                                              • Opcode ID: 875a03687d68dde039996013fda3a20d172582a3a1b2158224bd8d205a84eff8
                                                                                                                                                                                                              • Instruction ID: a49d7a07ece8321a3e26e37833c6375ac1aadd8ba9ff0f61d9aa197f7271b52e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 875a03687d68dde039996013fda3a20d172582a3a1b2158224bd8d205a84eff8
                                                                                                                                                                                                              • Instruction Fuzzy Hash: CC318E73B221514BD661CE26E8846AAF6E5FB94B94F046035CFCA87F50D97DF8808B40
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: strncmp
                                                                                                                                                                                                              • String ID: ::tcl$::tcl::
                                                                                                                                                                                                              • API String ID: 1114863663-1364682314
                                                                                                                                                                                                              • Opcode ID: 615062ffe100d1492889d847f9096eee415e4b79debdb0659d392f4b7ace34da
                                                                                                                                                                                                              • Instruction ID: 14a03beea8d5290a781a1f24bf685f256d652843716f97ef231eb4ccc4b32200
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 615062ffe100d1492889d847f9096eee415e4b79debdb0659d392f4b7ace34da
                                                                                                                                                                                                              • Instruction Fuzzy Hash: BD81AC36B08AC586DB59CB25E850AAD77A0FB48B88F440076DF5D57B9CEF38D941CB10
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • memmove.VCRUNTIME140(?,?,00000000,?,...,00007FFDFAD91EA4), ref: 00007FFDFAD923ED
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: memmove
                                                                                                                                                                                                              • String ID: ...$max size for a Tcl value (%d bytes) exceeded
                                                                                                                                                                                                              • API String ID: 2162964266-3564828104
                                                                                                                                                                                                              • Opcode ID: 5f34391651a3cf79b538a0bf609c6388166d1089f266b6f3b4f028dc17315685
                                                                                                                                                                                                              • Instruction ID: cb0aa3ed45e908c5866c1e178a6164f3af99685a34231dd9318dd42d3d107574
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 5f34391651a3cf79b538a0bf609c6388166d1089f266b6f3b4f028dc17315685
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 8121C03270868182EB18DF16A950A3EB765FB487A8F544634DE7D07BD8EF3CE4518B00
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • fprintf.MSPDB140-MSVCRT ref: 00007FFDFAC85858
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAC81060: __stdio_common_vsprintf.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FFDFAC810AB
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: __stdio_common_vsprintffprintf
                                                                                                                                                                                                              • String ID: ========= TREE NODE %s ==========
                                                                                                                                                                                                              • API String ID: 1618753959-1193519803
                                                                                                                                                                                                              • Opcode ID: f0340efec422160a7ffb661b286e4ca765d8d0ebb072d02ba4b84140810d0284
                                                                                                                                                                                                              • Instruction ID: 879490a76ed10b567469e169d24ca5e51d12889227957c9e4e9428404d6d9063
                                                                                                                                                                                                              • Opcode Fuzzy Hash: f0340efec422160a7ffb661b286e4ca765d8d0ebb072d02ba4b84140810d0284
                                                                                                                                                                                                              • Instruction Fuzzy Hash: D321D25AB0474681EB289B22E8609BE2395FF44BD0F4490B2EE2E1B7D9DE3CE441C300
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID: name
                                                                                                                                                                                                              • API String ID: 0-1579384326
                                                                                                                                                                                                              • Opcode ID: 20cb7061b5355cefca0373a44e4d7288eb452fe6fa878f6f838f900595a198b7
                                                                                                                                                                                                              • Instruction ID: e8817df3bbbf005ac8fd88253c060a609e9f4f98d1c65767a064f04bf7befb3e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 20cb7061b5355cefca0373a44e4d7288eb452fe6fa878f6f838f900595a198b7
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 6511E379F1824281EB5D9B22AD31B7E1291DF49BC0F4444B4ED3D4B7D9EE2CD4818740
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 3617616757-217463007
                                                                                                                                                                                                              • Opcode ID: 3d0b5fe31bdceefd0d16471987016516823057e139ed2a49c540c935358a7bd8
                                                                                                                                                                                                              • Instruction ID: 5beb3dd34175f2fd52736431fa55669c96c03ca3c1896f4888c28533d44377a1
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 3d0b5fe31bdceefd0d16471987016516823057e139ed2a49c540c935358a7bd8
                                                                                                                                                                                                              • Instruction Fuzzy Hash: ECF05E66F8AA0781FA199B0DA8505B423E26F40799B804035CD8D0B2B0DF2CF9858742
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID:
                                                                                                                                                                                                              • String ID: Buffer Underflow, BUFFER_PADDING not enough
                                                                                                                                                                                                              • API String ID: 0-3280121635
                                                                                                                                                                                                              • Opcode ID: 2c72081082c585c650c2c2678425b413c34ec000225da04b31894e445b4152e2
                                                                                                                                                                                                              • Instruction ID: 9651c604c20b9b2786c5a9fc9b7475690fd41ace6945d3ff683a316f89b48cf1
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 2c72081082c585c650c2c2678425b413c34ec000225da04b31894e445b4152e2
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 4481AF76B04B408AEB18CFA9D890AAD33B6FB48788F148139EE1D57B8CDB38D445C740
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3215553584-0
                                                                                                                                                                                                              • Opcode ID: eff41cba983b05e0f9e09f52185aba8178b112ae95ee52c2a1f9a5fdd57fcc68
                                                                                                                                                                                                              • Instruction ID: 0976c69595002e6217248c4f31ed2e5cf36afe6787f56246b82b501797e9b3a0
                                                                                                                                                                                                              • Opcode Fuzzy Hash: eff41cba983b05e0f9e09f52185aba8178b112ae95ee52c2a1f9a5fdd57fcc68
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 3051D521A0D24246EAA4BE399800679A291BF66BA8FD44735DF7C267DDCF3CD4908770
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Value
                                                                                                                                                                                                              • String ID: Tcl_RegisterChannel: channel without name
                                                                                                                                                                                                              • API String ID: 3702945584-115464937
                                                                                                                                                                                                              • Opcode ID: 4b04a55301aaad4597ee6c18eed481024358ad157d3e28fc0605e54a076445a9
                                                                                                                                                                                                              • Instruction ID: 905da0f04b1fbf5079cec63b52f927e23cd688961a7fd16c44f63f83e8509532
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 4b04a55301aaad4597ee6c18eed481024358ad157d3e28fc0605e54a076445a9
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 92415F72B18B4182EB588F15E8A066873A4FB98F84F585176DE6D473A9EF3CD8D0C340
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: __scrt_acquire_startup_lock__scrt_dllmain_crt_thread_attach__scrt_release_startup_lock
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 1236291503-0
                                                                                                                                                                                                              • Opcode ID: 0062f537d7c131bdaaf4aef5eb59421e6e9ee6bfc8727e8bca4d357a962c4ab6
                                                                                                                                                                                                              • Instruction ID: b8d75cb4109ced18e6681c5c033bebb31cee9ee95d2509d7762952b65e77a313
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 0062f537d7c131bdaaf4aef5eb59421e6e9ee6bfc8727e8bca4d357a962c4ab6
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 5B313E11E0C14241FA90BBBCA5513BA9291AF77788FC44035DB5E6B6EFDE2CA4C6C270
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ErrorFileLastWrite
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 442123175-0
                                                                                                                                                                                                              • Opcode ID: c27fe9df092fe972dc18f8e28df30e9d6822c627cf1a35e7333a40c8d1abf1b1
                                                                                                                                                                                                              • Instruction ID: ca3d3616df5bc69f32f1380523b5112132b3f5ffd769101b463d3b616eb11176
                                                                                                                                                                                                              • Opcode Fuzzy Hash: c27fe9df092fe972dc18f8e28df30e9d6822c627cf1a35e7333a40c8d1abf1b1
                                                                                                                                                                                                              • Instruction Fuzzy Hash: AC31E57260CA818AE790AF29E4406A9B7B0FF69784F844031DB9E57718DF3DD599C710
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: FileHandleType
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3000768030-0
                                                                                                                                                                                                              • Opcode ID: 336ff322d096320c7609ad2a1ebfb1af701ecd8db59b0b6a36a9cc413741d25d
                                                                                                                                                                                                              • Instruction ID: 787b2f56c7fd8a641bb04705cb3339d5b891f542daff008d466cd586f9205028
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 336ff322d096320c7609ad2a1ebfb1af701ecd8db59b0b6a36a9cc413741d25d
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 2D31A861A1CB4582D7A05B2D854057CA690FF56BB0BA40335DB7E277E4CF38E4E5C310
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • SetFilePointerEx.KERNEL32(?,?,?,?,?,00007FF7B35DCFC0,?,?,?,?,?,00007FF7B35DD0C9), ref: 00007FF7B35DD020
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,?,?,00007FF7B35DCFC0,?,?,?,?,?,00007FF7B35DD0C9), ref: 00007FF7B35DD02A
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ErrorFileLastPointer
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2976181284-0
                                                                                                                                                                                                              • Opcode ID: c8d9032d6f18d1acbd55ff3d5784a6e8b9f1708e95d0104a6ada3112851001ef
                                                                                                                                                                                                              • Instruction ID: 02da0227911f738a4e7c9071ac6c99de60500bd97d321224ef584b66cdc2f5e4
                                                                                                                                                                                                              • Opcode Fuzzy Hash: c8d9032d6f18d1acbd55ff3d5784a6e8b9f1708e95d0104a6ada3112851001ef
                                                                                                                                                                                                              • Instruction Fuzzy Hash: A511E2A160CB4181DA90AB39B844069A3A1AF96BF4F940331EF7D1B7DDDE7CD0858700
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • CloseHandle.KERNEL32(?,?,?,00007FF7B35DB87D,?,?,00000000,00007FF7B35DB932), ref: 00007FF7B35DBA6E
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,?,?,00007FF7B35DB87D,?,?,00000000,00007FF7B35DB932), ref: 00007FF7B35DBA78
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CloseErrorHandleLast
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 918212764-0
                                                                                                                                                                                                              • Opcode ID: 77e2bcd66fe63b7e32e9c420d5456187ea64b38b498190725808e49f9c0985ab
                                                                                                                                                                                                              • Instruction ID: da72571d634b1785e4deae0f77062f43c42cc3d9760f124a9be25e071d080fac
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 77e2bcd66fe63b7e32e9c420d5456187ea64b38b498190725808e49f9c0985ab
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 2021B011B0C64241EAE07B39A4846BD96825FA2BA0F844235DB7E673C9CE6CE4C54320
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3215553584-0
                                                                                                                                                                                                              • Opcode ID: 8b800d1c0215c395d8ee5cb256ced11da9c32d068479accee0e1705fd5882e0a
                                                                                                                                                                                                              • Instruction ID: aa45ba38ceaacb4e0f7d622e73aaebf5c7ff3df976eedd58c8d4bca44b742a19
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 8b800d1c0215c395d8ee5cb256ced11da9c32d068479accee0e1705fd5882e0a
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 6F41C67290C64187EAB4AB2DE540679B7A1EF67B40F900131D7AE576D9CF3CE482C760
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _fread_nolock
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 840049012-0
                                                                                                                                                                                                              • Opcode ID: ccc8401215857c79d55a409676db5ea5c339c950fc774aee4865bde6d3500267
                                                                                                                                                                                                              • Instruction ID: a90df266af9e0e3d5ff0d0b35afda754cc6dd2a372c6d9c265233fd7efd9e210
                                                                                                                                                                                                              • Opcode Fuzzy Hash: ccc8401215857c79d55a409676db5ea5c339c950fc774aee4865bde6d3500267
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 8721A925B0C65146FA90B63A65447F5DA45BF56BDCFC84431EF4D17B4ACE3DE081C220
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3215553584-0
                                                                                                                                                                                                              • Opcode ID: ec9d5ae5a000e04b57470e1a65c1a2ebd8d322b6e5cd5ccd1e774105d6e8e50b
                                                                                                                                                                                                              • Instruction ID: 78dfff5e102826a93ef55498242e3c2dc1aa2144f4a97ea36ea39fe31293d248
                                                                                                                                                                                                              • Opcode Fuzzy Hash: ec9d5ae5a000e04b57470e1a65c1a2ebd8d322b6e5cd5ccd1e774105d6e8e50b
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 9F318B22E1C60285E7917B6D8841E7CA650AFA6B94F910135EB3D633DACF7CA4818730
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: HandleModule$AddressFreeLibraryProc
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3947729631-0
                                                                                                                                                                                                              • Opcode ID: da7d5aaa001a85c1e13054e7b60926c5ebf14781b4d980b1a631c30dc526fcea
                                                                                                                                                                                                              • Instruction ID: 5b54ee556a1da72bf399868ca29d778137aca228c07c52740d4dd3427b01778a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: da7d5aaa001a85c1e13054e7b60926c5ebf14781b4d980b1a631c30dc526fcea
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 59218D32E1970589EBA4AF78C4406AD73A0EF55718F840635DB2D26AEDEF38D885C750
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3215553584-0
                                                                                                                                                                                                              • Opcode ID: 0e1df9a836e05c53306103cf914f9f5afd0b17d2d4247778ac0f8a736a470cc7
                                                                                                                                                                                                              • Instruction ID: d4cbfd1e096a0f7f84f12e9a40bfb8cdff4b5e9f72361983be733188a119e1a0
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 0e1df9a836e05c53306103cf914f9f5afd0b17d2d4247778ac0f8a736a470cc7
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 1F118421A0C64182EAA0BF69D40097EE260EF67B80FD44431EBAC6778EDF3DD5918760
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3215553584-0
                                                                                                                                                                                                              • Opcode ID: 3767eff042e46cd651120d9163f396646e5b690a05a83219cc7a0fcdceb2a680
                                                                                                                                                                                                              • Instruction ID: 2cfdc35adf4f054675d9dab2274f53a5399c16a2fc16018ce8e6f9810cb8c570
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 3767eff042e46cd651120d9163f396646e5b690a05a83219cc7a0fcdceb2a680
                                                                                                                                                                                                              • Instruction Fuzzy Hash: F921B332A0C68287DBA1AF2CD440379B2A4AF96B94FA40335E76D576DDDF3CD4408B10
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _invalid_parameter_noinfo
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3215553584-0
                                                                                                                                                                                                              • Opcode ID: 43297e0cb54a728217cf8f13d9f8c23c45e2da10c33361e46a2ef0799771412d
                                                                                                                                                                                                              • Instruction ID: 3b7cb7120d6e00d2754465552cf0fe4df2aca6df3da63202c43ed62c30c9956b
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 43297e0cb54a728217cf8f13d9f8c23c45e2da10c33361e46a2ef0799771412d
                                                                                                                                                                                                              • Instruction Fuzzy Hash: FB018621A0C74541ED84AB7A9900569D6A5BF66FE4BC84631EF6C237DECE3CD5818720
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • __scrt_dllmain_crt_thread_attach.LIBCMT ref: 00007FF7B35CC390
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35CCDB8: __vcrt_uninitialize_ptd.LIBVCRUNTIME ref: 00007FF7B35CCDC0
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35CCDB8: __vcrt_uninitialize_locks.LIBVCRUNTIME ref: 00007FF7B35CCDC5
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: __scrt_dllmain_crt_thread_attach__vcrt_uninitialize_locks__vcrt_uninitialize_ptd
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 1208906642-0
                                                                                                                                                                                                              • Opcode ID: 86517d9d3c6548b93fa1a500576de9512fe9d6a130677b1fbe86fe464c74cea3
                                                                                                                                                                                                              • Instruction ID: cf56bf78003734fd1f41f3931c5418909c9bfdd50561d3191e6c9b60485273bc
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 86517d9d3c6548b93fa1a500576de9512fe9d6a130677b1fbe86fe464c74cea3
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 5BE0B650D0D24381FEE9767929A22B896400F3770DFC100B9DB4E761CB9D4E30D795B1
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                                • Part of subcall function 00007FF7B35C88F0: MultiByteToWideChar.KERNEL32(?,?,?,00007FF7B35C3A14,00000000,00007FF7B35C1965), ref: 00007FF7B35C8929
                                                                                                                                                                                                              • LoadLibraryExW.KERNEL32(?,00007FF7B35C58C6,00000000,00007FF7B35C272E), ref: 00007FF7B35C82F2
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ByteCharLibraryLoadMultiWide
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2592636585-0
                                                                                                                                                                                                              • Opcode ID: 912286cff54bdb35db81b841aaf79fc17e93e1df921a3d78ac8a6212d3990a64
                                                                                                                                                                                                              • Instruction ID: b859021fb734a5a0e55a60bd97f018ed715011127909dbe3a583707a95bbd5c0
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 912286cff54bdb35db81b841aaf79fc17e93e1df921a3d78ac8a6212d3990a64
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 09D0C225F2825141EA84F77FBA469799152AF9ABC0FC88034EF0C07B4AED3CD0D54B04
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830637851.00007FFE0E161000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFE0E160000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830611219.00007FFE0E160000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830675705.00007FFE0E17B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830706221.00007FFE0E184000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830736890.00007FFE0E185000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830762935.00007FFE0E188000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830790164.00007FFE0E189000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0e160000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: malloc
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2803490479-0
                                                                                                                                                                                                              • Opcode ID: bdd92a4f14655f155a003dcce0022ad3609792a2082d0b9e02fcd449b09b0869
                                                                                                                                                                                                              • Instruction ID: cef129e65ce5974c5c9a98edc0ed72e19210060c472911a4e5e250f824d4716e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: bdd92a4f14655f155a003dcce0022ad3609792a2082d0b9e02fcd449b09b0869
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 6D318373A19A5346FB658B199450378A290BB58B98F155236CEDE4B3E2EF78D881C3C0
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • HeapAlloc.KERNEL32(?,?,?,00007FF7B35D0208,?,?,?,00007FF7B35D1872,?,?,?,?,?,00007FF7B35D4535), ref: 00007FF7B35DE6A2
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1826199889.00007FF7B35C1000.00000020.00000001.01000000.00000003.sdmp, Offset: 00007FF7B35C0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826170198.00007FF7B35C0000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826239657.00007FF7B35ED000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3600000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826272595.00007FF7B3603000.00000004.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1826329237.00007FF7B3606000.00000002.00000001.01000000.00000003.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ff7b35c0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: AllocHeap
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 4292702814-0
                                                                                                                                                                                                              • Opcode ID: 3c31cf8336a648e9ecfad8ff9b709a6d49b8502715341f1fffc2c41753e32efa
                                                                                                                                                                                                              • Instruction ID: b0568bdf9c39c97f4883086e07fd3df3e6699ea2e4766748e287d8f4919750f4
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 3c31cf8336a648e9ecfad8ff9b709a6d49b8502715341f1fffc2c41753e32efa
                                                                                                                                                                                                              • Instruction Fuzzy Hash: ADF05E40E1D20244FAE47A7D6941A7992805FA6760FD80630DF3E652C9DE2CA4C0C171
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: ExceptionFilterPresentUnhandledmemset$CaptureContextDebuggerEntryFeatureFunctionLookupProcessorUnwindVirtual
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 313767242-0
                                                                                                                                                                                                              • Opcode ID: 163f402a1fb0e79306561b7d1351dc0227e06d1d27abfb67021ae25e867ac1b0
                                                                                                                                                                                                              • Instruction ID: 4dcee894ba8a030e8a7eaa58ec78fbb647433919ce2b313e3cf8a5c9167b729b
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 163f402a1fb0e79306561b7d1351dc0227e06d1d27abfb67021ae25e867ac1b0
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 9E316D72648B8286EB608F68E8503ED77A1FF84749F40443ADA8E47AA8DF3CD548C701
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • LeaveCriticalSection.KERNEL32(?,?,?,?,00000000,?,?,00000000,?,00007FFDFAD58FDF), ref: 00007FFDFADB5C4A
                                                                                                                                                                                                              • LeaveCriticalSection.KERNEL32(?,?,?,?,00000000,?,?,00000000,?,00007FFDFAD58FDF), ref: 00007FFDFADB5D00
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FF60: TlsAlloc.KERNEL32(?,?,?,00007FFDFAD11924), ref: 00007FFDFAD9FF7A
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FF60: TlsGetValue.KERNEL32(?,?,?,00007FFDFAD11924), ref: 00007FFDFAD9FFA8
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FF60: GetLastError.KERNEL32(?,?,?,00007FFDFAD11924), ref: 00007FFDFAD9FFB6
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FF60: GetProcessHeap.KERNEL32(?,?,?,00007FFDFAD11924), ref: 00007FFDFAD9FFF9
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FF60: HeapFree.KERNEL32(?,?,?,00007FFDFAD11924), ref: 00007FFDFADA0007
                                                                                                                                                                                                              • LeaveCriticalSection.KERNEL32(?,00000000,00000000,00007FFDFAD13819,?,00007FFDFAD59DED), ref: 00007FFDFADB5FFA
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CriticalLeaveSection$Heap$AllocErrorFreeLastProcessValue
                                                                                                                                                                                                              • String ID: @$Cannot trace a variable with no name$Tcl_EventuallyFree called twice for %p
                                                                                                                                                                                                              • API String ID: 1157508047-3814855115
                                                                                                                                                                                                              • Opcode ID: 855c6141a927ef484894ec9777152fc504c8d7681d07f11e1d07ecfd96894e12
                                                                                                                                                                                                              • Instruction ID: 5d84e31cdb2ec48e684eedc2817ccf967569ec307313aff8d531a61d02617881
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 855c6141a927ef484894ec9777152fc504c8d7681d07f11e1d07ecfd96894e12
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 6912BE32B08A4686EB2D9F15D860B7963A4FB44BD4F488176DA6E477D9EF3CE841C340
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: String$DeallocObject_$Attr$Err_Unicode_$CompareType_Withstrcmp$Clear$AllocCalculateCallDictFastFromGenericMetaclassReadyTrueVectorcall
                                                                                                                                                                                                              • String ID: ABCMeta$GenericMeta$TypingMeta$_ProtocolMeta$__module__$__orig_bases__$__slots__$abc$mypyc classes can't have __slots__$mypyc classes can't have a metaclass$typing$typing_extensions
                                                                                                                                                                                                              • API String ID: 3039355408-3015203947
                                                                                                                                                                                                              • Opcode ID: 581e7a51ebe161312cd1d03399a5527e61c6b6fd9e8a3dc5876b46a657a736b2
                                                                                                                                                                                                              • Instruction ID: d685fe399cd9139c3680f5c7ba36ed1cb2c7f6be73cc522a1c4b661cddb153a0
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 581e7a51ebe161312cd1d03399a5527e61c6b6fd9e8a3dc5876b46a657a736b2
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 79D16065F88B4782EA549F2DEA942B823E1BF55BC9F449035CE8E46275DF3CE458C302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_$Dict_Format$ItemString$DeallocErrorNextOccurredWith$EqualSliceTuple_Unicode_strchr
                                                                                                                                                                                                              • String ID: %.200s%s missing required argument '%s' (pos %d)$%.200s%s missing required keyword-only argument '%s'$%.200s%s takes %s %d positional argument%s (%zd given)$%.200s%s takes at most %d %sargument%s (%zd given)$%.200s%s takes no positional arguments$'%U' is an invalid keyword argument for %.200s%s$argument for %.200s%s given by name ('%s') and position (%d)$at least$at most$exactly$function$keyword $keywords must be strings$this function
                                                                                                                                                                                                              • API String ID: 3559638176-2999033026
                                                                                                                                                                                                              • Opcode ID: 1f8ef507af8cc2a236b28dc01e6daa758a540280c688015cb7e3079141fe9442
                                                                                                                                                                                                              • Instruction ID: 9ef4e37d9ebe10316b77bbc43edec6a78dfa29c73d1a8b61888783b1afc92135
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 1f8ef507af8cc2a236b28dc01e6daa758a540280c688015cb7e3079141fe9442
                                                                                                                                                                                                              • Instruction Fuzzy Hash: B9325C71B88B8685EB258F49E5803AD63E1FF84B88F948036DA8E43675DF3CE455CB01
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: fprintf$__stdio_common_vfprintf__stdio_common_vsprintf
                                                                                                                                                                                                              • String ID: %ld-%ld$ (#%d)$ L:%s$ R:%s$ UNUSED$ hasbackref$ hascapture$ hasmixed$ longest$ shortest$ {%d,$%s. `%c'$@
                                                                                                                                                                                                              • API String ID: 2245253407-2605086021
                                                                                                                                                                                                              • Opcode ID: aafbc7adc5ad10478f44efa1f83f8238ea2b42259507b83fd4d6a24ccdc59e8c
                                                                                                                                                                                                              • Instruction ID: 77838d1f5454acbe4a2146f07f8841b82b930b9a75cbaaea340fdb8c19559137
                                                                                                                                                                                                              • Opcode Fuzzy Hash: aafbc7adc5ad10478f44efa1f83f8238ea2b42259507b83fd4d6a24ccdc59e8c
                                                                                                                                                                                                              • Instruction Fuzzy Hash: D1614B68B0868650EB1C9B25D9B5ABC2391FF05BC4F4480B2D96E0B6DEAF6CE945C740
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_Format$DeallocDict_$ContainsItemSequence_Tuple_Unicode_
                                                                                                                                                                                                              • String ID: %.200s%s missing required argument '%U' (pos %d)$%.200s%s missing required keyword-only argument '%U'$%.200s%s takes %s %d positional argument%s (%zd given)$%.200s%s takes at most %d %sargument%s (%zd given)$%.200s%s takes no positional arguments$'%S' is an invalid keyword argument for %.200s%s$argument for %.200s%s given by name ('%U') and position (%d)$at least$at most$exactly$function$keyword $this function
                                                                                                                                                                                                              • API String ID: 3590232122-3030676885
                                                                                                                                                                                                              • Opcode ID: 1ff9da88f9a7a57dac390b6711fe79e0e012da9bfee1266b6d806b6e39d40ce2
                                                                                                                                                                                                              • Instruction ID: 815eb750c0f8c1bd4ea07fa40206da498b93e4dfa167f535e24b073b9aac2056
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 1ff9da88f9a7a57dac390b6711fe79e0e012da9bfee1266b6d806b6e39d40ce2
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 6E126B72B89B8682EA518F49E9806B973E1FF84B88F544136DA8E43774DF3CE545C702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$Err_$Object_Vectorcall$ChainCode_ContainsDict_EmptyErrorExceptions1FetchFormatFrame_FromItemLong_MethodNumber_ObjectOccurredSet_Ssize_tState_SubtypeThreadType_With
                                                                                                                                                                                                              • String ID: bool$feed$set$str$str or None
                                                                                                                                                                                                              • API String ID: 2120016896-82482222
                                                                                                                                                                                                              • Opcode ID: e10df2e8b84fc016c60972893c28a7248685ceeda9d69689395281560c33c246
                                                                                                                                                                                                              • Instruction ID: fe481901ff25509432a959a9d0fcf5fc644433e067790362145d0137e7799378
                                                                                                                                                                                                              • Opcode Fuzzy Hash: e10df2e8b84fc016c60972893c28a7248685ceeda9d69689395281560c33c246
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 90023C75B89A4286EB249F1DEA823B923E2AF44B89F445031D98D477B5DE3CE448C743
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$Object_Vectorcall$Err_Method$ChainCode_EmptyExceptions1FetchFrame_FromLong_Number_Ssize_tState_Thread
                                                                                                                                                                                                              • String ID: bool$feed$str
                                                                                                                                                                                                              • API String ID: 476165880-2613659865
                                                                                                                                                                                                              • Opcode ID: 7f2e8c55a4eeca045cf774529f01804e1fee1cd08f798284cff5715901533d5d
                                                                                                                                                                                                              • Instruction ID: 71d83ce80337d7f960541607bdf3854854707b82c0198eb20e0fd2b1df82724b
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 7f2e8c55a4eeca045cf774529f01804e1fee1cd08f798284cff5715901533d5d
                                                                                                                                                                                                              • Instruction Fuzzy Hash: AE026B75B89A4282EB219F1DEA863B923E2EF44B89F444031D99D476B5DF3CE448C743
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$Object_$Vectorcall$CompareContainsErr_FormatFromLong_MethodNumber_RichSet_Ssize_tSubtypeType_
                                                                                                                                                                                                              • String ID: bool$feed$set
                                                                                                                                                                                                              • API String ID: 588643045-561237756
                                                                                                                                                                                                              • Opcode ID: 2ce494273f180fa024b86351a584eddda6a252b5bae88b763fbfbb79a573f59b
                                                                                                                                                                                                              • Instruction ID: 0c6756262ab30674952c91c7b0c81422af1e9705b7fde8f55c3f9770287bb717
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 2ce494273f180fa024b86351a584eddda6a252b5bae88b763fbfbb79a573f59b
                                                                                                                                                                                                              • Instruction Fuzzy Hash: E1D14071B89A0282FB619F1DEAC03B963D2AF54B95F485035CA4E076B5DFBDE644C302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: strchr
                                                                                                                                                                                                              • String ID: %$Empty keyword parameter name$Empty parameter name after $$Invalid format string ($ before |)$Invalid format string ($ specified twice)$Invalid format string (@ specified twice)$Invalid format string (@ without preceding | and $)$Invalid format string (| specified twice)$More keyword list entries (%d) than format specifiers (%d)$more argument specifiers than keyword list entries (remaining format:'%s')
                                                                                                                                                                                                              • API String ID: 2830005266-262724644
                                                                                                                                                                                                              • Opcode ID: 38c6c7fd6f791c59d1b5912cc3173f5b2923cab9302d414a8e120c7176cfda89
                                                                                                                                                                                                              • Instruction ID: 574c39822bcfc1a827c050de24e2a89e6abcc5ea13f4f84c69f4bd469cd3a8fd
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 38c6c7fd6f791c59d1b5912cc3173f5b2923cab9302d414a8e120c7176cfda89
                                                                                                                                                                                                              • Instruction Fuzzy Hash: F7919371B89A4282EB248B18E69027C77E1FF48B98F548535CA9D47BB5DF3CE465C302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • log.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFAD11D33), ref: 00007FFDFAD9CB04
                                                                                                                                                                                                              • log.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFAD11D33), ref: 00007FFDFAD9CB22
                                                                                                                                                                                                              • floor.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFAD11D33), ref: 00007FFDFAD9CB2F
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: TlsAlloc.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE21
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: TlsGetValue.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE4F
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: GetLastError.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE5D
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: GetProcessHeap.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE9B
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: HeapAlloc.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FEA9
                                                                                                                                                                                                              • frexp.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFAD11D33), ref: 00007FFDFAD9CBA6
                                                                                                                                                                                                              • log.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFAD11D33), ref: 00007FFDFAD9CBF0
                                                                                                                                                                                                              • log.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFAD11D33), ref: 00007FFDFAD9CC09
                                                                                                                                                                                                              • memset.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFAD11D33), ref: 00007FFDFAD9CCD8
                                                                                                                                                                                                              • memset.VCRUNTIME140(?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFAD11D33), ref: 00007FFDFAD9CDC6
                                                                                                                                                                                                              • log.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFAD11D33), ref: 00007FFDFAD9CE51
                                                                                                                                                                                                              • log.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFAD11D33), ref: 00007FFDFAD9CE66
                                                                                                                                                                                                              • log.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFAD11D33), ref: 00007FFDFAD9CE7F
                                                                                                                                                                                                              • log.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFAD11D33), ref: 00007FFDFAD9CE97
                                                                                                                                                                                                              • log.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFAD11D33), ref: 00007FFDFAD9CEAC
                                                                                                                                                                                                              • floor.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFAD11D33), ref: 00007FFDFAD9CEB9
                                                                                                                                                                                                              • log.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFAD11D33), ref: 00007FFDFAD9CECD
                                                                                                                                                                                                              • log.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFAD11D33), ref: 00007FFDFAD9CEE2
                                                                                                                                                                                                              • floor.API-MS-WIN-CRT-MATH-L1-1-0(?,?,?,?,?,?,?,?,?,?,00000000,00007FFDFAD11D33), ref: 00007FFDFAD9CEEF
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADC4260: memset.VCRUNTIME140 ref: 00007FFDFADC42D1
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADC4260: memset.VCRUNTIME140 ref: 00007FFDFADC4326
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADC4260: memset.VCRUNTIME140 ref: 00007FFDFADC4378
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: memset$floor$AllocHeap$ErrorLastProcessValuefrexp
                                                                                                                                                                                                              • String ID: This code doesn't work on a decimal machine!$unable to alloc %u bytes
                                                                                                                                                                                                              • API String ID: 3581738816-2774349006
                                                                                                                                                                                                              • Opcode ID: ee35b5b3adc3ba6cd6f7260ea0137abf0e6198d03ad0329c6ef839f08e08dcc7
                                                                                                                                                                                                              • Instruction ID: 049d8851efa9d7841ca9e3bc8520a7de835282853b3bcadf38221e6796bdcc8c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: ee35b5b3adc3ba6cd6f7260ea0137abf0e6198d03ad0329c6ef839f08e08dcc7
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 6AD1B170F18A4685F7099F34E860AB973A4EF59749F1492B2D92E532E8FF7DE4818700
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$List_$Object_$AppendAttrCallErr_FastLookupSliceStringTuple
                                                                                                                                                                                                              • String ID: __mro_entries__ must return a tuple
                                                                                                                                                                                                              • API String ID: 1865160900-2385075324
                                                                                                                                                                                                              • Opcode ID: b039deb2464f2060ae4a0bd026d99ad7f7f16f43939d06b91a08d2db725bb474
                                                                                                                                                                                                              • Instruction ID: 450dce8e916a15f71f7fa96deb48d823d8c4d4e658bb7064289d340a8042c750
                                                                                                                                                                                                              • Opcode Fuzzy Hash: b039deb2464f2060ae4a0bd026d99ad7f7f16f43939d06b91a08d2db725bb474
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 98518235B88A4282EB159F19EA8437D63E6EF45B99F048031CE4D82775DF3CE0658302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$Err_$AttrDict_Object_String$ClearExceptionItemMatches
                                                                                                                                                                                                              • String ID: __mypyc_attrs__$__mypyc_attrs__ is not a tuple
                                                                                                                                                                                                              • API String ID: 2346549887-4201147154
                                                                                                                                                                                                              • Opcode ID: e66151341709f08fa87d516288480836e991296861bc7efaf3a726328e6597ee
                                                                                                                                                                                                              • Instruction ID: ca61267fad7a84d31ad67e4a3e35f916514700af9b44496462be97c8c738a6ad
                                                                                                                                                                                                              • Opcode Fuzzy Hash: e66151341709f08fa87d516288480836e991296861bc7efaf3a726328e6597ee
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 4D413A75B88A4282EB188F19EA8427967F1FF45F9AF448435CA8E46774DF3CE449C702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,00007FFE0CFC28DB), ref: 00007FFE0CFC3599
                                                                                                                                                                                                              • fprintf.MSPDB140-MSVCRT ref: 00007FFE0CFC35A9
                                                                                                                                                                                                                • Part of subcall function 00007FFE0CFC1010: __stdio_common_vfprintf.API-MS-WIN-CRT-STDIO-L1-1-0 ref: 00007FFE0CFC1047
                                                                                                                                                                                                              • __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,00007FFE0CFC28DB), ref: 00007FFE0CFC35B3
                                                                                                                                                                                                              • fflush.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,00007FFE0CFC28DB), ref: 00007FFE0CFC35BC
                                                                                                                                                                                                              • abort.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,00007FFE0CFC28DB), ref: 00007FFE0CFC35C2
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: __acrt_iob_func$__stdio_common_vfprintfabortfflushfprintf
                                                                                                                                                                                                              • String ID: %U%U%s$%U.%U$None$__module__$__qualname__$builtins$fatal: out of memory$tuple[<%d items>]
                                                                                                                                                                                                              • API String ID: 3462009215-2533303582
                                                                                                                                                                                                              • Opcode ID: 3aae54b1b249fabbf7fa54b3ea6166519944189401f5320151bdc15871942efa
                                                                                                                                                                                                              • Instruction ID: 47d08e6dc220b78c8a16715273c4fb68ccf01008048b73f8b5e3f3f46760dc89
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 3aae54b1b249fabbf7fa54b3ea6166519944189401f5320151bdc15871942efa
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 20D09EE0E9990382FB08A75DE85A27822A7AF45B46F811438C58F06375DE2C64489353
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: AttrCapsule_DeallocObject_String$Create2Module_
                                                                                                                                                                                                              • String ID: charset_normalizer.md__mypyc.exports$charset_normalizer.md__mypyc.init_charset_normalizer___md$exports$init_charset_normalizer___md
                                                                                                                                                                                                              • API String ID: 2519120496-2411258805
                                                                                                                                                                                                              • Opcode ID: 6cb80ad11c98d76827863cb71e74507b593be2b67b62d800d4c12a6864baf513
                                                                                                                                                                                                              • Instruction ID: 0bc2a1d5510d1a8896086c0c9033cc4e229d57696a09335d39827bd2f8647e61
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 6cb80ad11c98d76827863cb71e74507b593be2b67b62d800d4c12a6864baf513
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 9631D872A99B0382FB558B1DE85467523F3AF45B99F495034CA8D067B4EE3CE888D703
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • _errno.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,00000001,00000000,00000000,?,?,00007FFDFAD482CB), ref: 00007FFDFAD48344
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _errno
                                                                                                                                                                                                              • String ID: POSIX$TCL_TEMPLOAD_NO_UNLINK$couldn't load library "%s": %s$unable to alloc %u bytes$ystem
                                                                                                                                                                                                              • API String ID: 2918714741-1716232485
                                                                                                                                                                                                              • Opcode ID: 1a0247754e96c3f7aa67e2f447aefbe0d2e793d8778f5174b7d20ec181f86aa3
                                                                                                                                                                                                              • Instruction ID: 07ec20c0f16438fa9e0438f5c695e8d8b4f888b0216e990526a9529e95aff076
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 1a0247754e96c3f7aa67e2f447aefbe0d2e793d8778f5174b7d20ec181f86aa3
                                                                                                                                                                                                              • Instruction Fuzzy Hash: DAC16725B0964386EB59AF21A874A7D63A0EF44BC4F4844B5DE6E077DAFF3CE6418700
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocErr_$Back_ChainCode_EmptyExceptions1FetchFrame_HereRestoreState_ThreadTrace
                                                                                                                                                                                                              • String ID: charset_normalizer\md.py
                                                                                                                                                                                                              • API String ID: 1599779757-1392889821
                                                                                                                                                                                                              • Opcode ID: 929c761034df64e23572057a73fe2c5fab85c31af172243b9a7b6395f97a8051
                                                                                                                                                                                                              • Instruction ID: 349b675603c7b60d45119e1a5cb0e4c227502a72d3142d6fbfeeb02f8757cd6f
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 929c761034df64e23572057a73fe2c5fab85c31af172243b9a7b6395f97a8051
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 6A210C76A48A4282EB108B15E9542A977E2FF89BDAF444031DA8E03B74DF3CD548CB02
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$Object_State_ThreadTrackTrash_beginTrash_condTrash_endUnchecked
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2819143443-0
                                                                                                                                                                                                              • Opcode ID: 34ec5bebfffadac6be9bf9876dce8c975bd5e57f5d382802bd6aac2d38012139
                                                                                                                                                                                                              • Instruction ID: abdd23d83e8d70f36aa21386b560fe011e4eec47a22979cbc47e7db45ddcfa35
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 34ec5bebfffadac6be9bf9876dce8c975bd5e57f5d382802bd6aac2d38012139
                                                                                                                                                                                                              • Instruction Fuzzy Hash: F551E672A9C64281EB558F3CD69837822E0AF45B7EF144335EA6A812F4DF7DE485C302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                                • Part of subcall function 00007FFDFACA9D80: _wgetenv.API-MS-WIN-CRT-ENVIRONMENT-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFACA7BBE), ref: 00007FFDFACA9E32
                                                                                                                                                                                                                • Part of subcall function 00007FFDFACA9D80: _tzset.API-MS-WIN-CRT-TIME-L1-1-0(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFACA7BBE), ref: 00007FFDFACA9E7C
                                                                                                                                                                                                                • Part of subcall function 00007FFDFACA9D80: LeaveCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFACA7BBE), ref: 00007FFDFACA9F16
                                                                                                                                                                                                              • TlsGetValue.KERNEL32 ref: 00007FFDFACA8B00
                                                                                                                                                                                                              • _localtime64.API-MS-WIN-CRT-TIME-L1-1-0 ref: 00007FFDFACA8B6E
                                                                                                                                                                                                              • LeaveCriticalSection.KERNEL32 ref: 00007FFDFACA8B84
                                                                                                                                                                                                              • _localtime64.API-MS-WIN-CRT-TIME-L1-1-0 ref: 00007FFDFACA8C2A
                                                                                                                                                                                                              • LeaveCriticalSection.KERNEL32 ref: 00007FFDFACA8C4B
                                                                                                                                                                                                              • memcpy.VCRUNTIME140 ref: 00007FFDFACA8D9B
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CriticalLeaveSection$_localtime64$Value_tzset_wgetenvmemcpy
                                                                                                                                                                                                              • String ID: %02d$CLOCK$localtimeFailed$unable to alloc %u bytes
                                                                                                                                                                                                              • API String ID: 2508344142-3078429109
                                                                                                                                                                                                              • Opcode ID: 6cce5858fe2a20d52ea3f9c0fa23a8807670c6f27afd4aae8f6ce25adca704fc
                                                                                                                                                                                                              • Instruction ID: e673560764da5695e4ea1886f049bd3d2b12e4c37aa3e70be92c5b73f82f68f1
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 6cce5858fe2a20d52ea3f9c0fa23a8807670c6f27afd4aae8f6ce25adca704fc
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 20A1B226B18B4686EB18DF24E8A09B977A0FF98B44F454175DA6D4B3E9EF3CE544C300
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Token$InformationProcess$CloseCurrentEqualFreeHandleInfoLocalNamedOpenSecurity
                                                                                                                                                                                                              • String ID: name$unable to alloc %u bytes
                                                                                                                                                                                                              • API String ID: 1764562822-3613934982
                                                                                                                                                                                                              • Opcode ID: 068a32edd16657965d15f04a1061be7b68ec3f919818ec949f3f8e4d1f8390bb
                                                                                                                                                                                                              • Instruction ID: 17452c3168e5b1ef3e371fe73ec1558c7f1200ff5ae8e32802d9d1b882893833
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 068a32edd16657965d15f04a1061be7b68ec3f919818ec949f3f8e4d1f8390bb
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 28519336B0868185EB688F52F860B7E63A0FB84B80F544075DEAD4BB9DEE3DE4458740
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Initialize__scrt_acquire_startup_lock__scrt_dllmain_after_initialize_c__scrt_dllmain_crt_thread_attach__scrt_initialize_crt__scrt_release_startup_lock
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 349153199-0
                                                                                                                                                                                                              • Opcode ID: 96e2149260328018f2ee9c3f905d278b01a8d9e20d367414482ed3a890371b1c
                                                                                                                                                                                                              • Instruction ID: 56ecd2fd4b823245a2fb32727f95f7fea0492ab08e18a0fb2b463f5ad325b0d2
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 96e2149260328018f2ee9c3f905d278b01a8d9e20d367414482ed3a890371b1c
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 7881DE21ECC20386FA54AB6EA44127966F3AF8578DF448135DACD873B6DE3DE4498703
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocFromLong_Ssize_t$BoolCompareErr_Object_OccurredRich
                                                                                                                                                                                                              • String ID: __init__$charset_normalizer.md.CjkInvalidStopPlugin$ratio
                                                                                                                                                                                                              • API String ID: 871640449-4126926341
                                                                                                                                                                                                              • Opcode ID: 50dfb51dc545f733170bcd5f131fd8dec372b9381f754ea30373e4415d5ce4ea
                                                                                                                                                                                                              • Instruction ID: c2f46c86bf5dc3333833c23a2e85a1984a749b699412ea76d86129031b33ca44
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 50dfb51dc545f733170bcd5f131fd8dec372b9381f754ea30373e4415d5ce4ea
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 70519C61F88A0682EB649B2DEA803BD63E1AF48B94F484531DE5D077F5DF7DE4818342
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$FromLong_Ssize_t$Err_ItemObject_Slice_String
                                                                                                                                                                                                              • String ID: interpreted classes cannot inherit from compiled
                                                                                                                                                                                                              • API String ID: 575668516-2110327174
                                                                                                                                                                                                              • Opcode ID: 4e2baef39ba8fe060f07d6d6f0bced05c2d01185e87a098f7d4dafbc9954950d
                                                                                                                                                                                                              • Instruction ID: 40616a1db10e1415949ab6c5fc586a3e73de259542dc5c565850168ce74bfe1a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 4e2baef39ba8fe060f07d6d6f0bced05c2d01185e87a098f7d4dafbc9954950d
                                                                                                                                                                                                              • Instruction Fuzzy Hash: A641A531F89A4382EA548F1DEAE427827E1AF49BA5F484130CA5E47BF4DF3DE4558702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • memset.VCRUNTIME140(?,?,00000000,00007FFDFADC290B,?,?,?,?,?,?,?,00007FFDFAD77CEE), ref: 00007FFDFADBE2AC
                                                                                                                                                                                                              • TlsAlloc.KERNEL32(?,?,00000000,00007FFDFADC290B,?,?,?,?,?,?,?,00007FFDFAD77CEE), ref: 00007FFDFADBE2BA
                                                                                                                                                                                                              • TlsGetValue.KERNEL32(?,?,00000000,00007FFDFADC290B,?,?,?,?,?,?,?,00007FFDFAD77CEE), ref: 00007FFDFADBE2E8
                                                                                                                                                                                                              • GetLastError.KERNEL32(?,?,00000000,00007FFDFADC290B,?,?,?,?,?,?,?,00007FFDFAD77CEE), ref: 00007FFDFADBE2F6
                                                                                                                                                                                                              • GetProcessHeap.KERNEL32(?,?,00000000,00007FFDFADC290B,?,?,?,?,?,?,?,00007FFDFAD77CEE), ref: 00007FFDFADBE339
                                                                                                                                                                                                              • HeapFree.KERNEL32(?,?,00000000,00007FFDFADC290B,?,?,?,?,?,?,?,00007FFDFAD77CEE), ref: 00007FFDFADBE347
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Heap$AllocErrorFreeLastProcessValuememset
                                                                                                                                                                                                              • String ID: TlsGetValue failed from TclpGetAllocCache$alloc: invalid block: %p: %x %x$could not allocate thread local storage
                                                                                                                                                                                                              • API String ID: 117382712-4238949377
                                                                                                                                                                                                              • Opcode ID: ca64179a5d3bdac4796b8714e603c964b479272b9ebbeb9f6a619867f5f20e63
                                                                                                                                                                                                              • Instruction ID: be34a92ff4c06757fd5836486160a5c0e6b2dc988d5df0076d400bdc6d54707b
                                                                                                                                                                                                              • Opcode Fuzzy Hash: ca64179a5d3bdac4796b8714e603c964b479272b9ebbeb9f6a619867f5f20e63
                                                                                                                                                                                                              • Instruction Fuzzy Hash: C5418231F087428AEB589B29AC6093873A0FF15B95B1851B5DA7E477D9EF3DE8428700
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$Err_$Dict_ErrorFromItemLong_Number_ObjectObject_OccurredSsize_tVectorcallWith
                                                                                                                                                                                                              • String ID: bool$feed
                                                                                                                                                                                                              • API String ID: 2189706420-2849697477
                                                                                                                                                                                                              • Opcode ID: 8e0caade2916fc91190bf6248451af5af673b86bd580171c2b13f121ea62ae45
                                                                                                                                                                                                              • Instruction ID: 885133bfa62c55718ef9f26d051f9fa518e79d91f50567545e651e9837bdda29
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 8e0caade2916fc91190bf6248451af5af673b86bd580171c2b13f121ea62ae45
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 3E416031B89A0282EB219F5DE690279A3E2FF48B85F584031DA9E477B5DF3CE4448703
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$Err_$Dict_ErrorFromItemLong_Number_ObjectObject_OccurredSsize_tVectorcallWith
                                                                                                                                                                                                              • String ID: bool$feed
                                                                                                                                                                                                              • API String ID: 2189706420-2849697477
                                                                                                                                                                                                              • Opcode ID: 958a22a6337853555e897f1e5a14fcd0471710981ec55253fe3441e9c772aafb
                                                                                                                                                                                                              • Instruction ID: d533c72e35af22866d82e4937fef50f49cd9cd57c79c68b3e10760b309d77ab7
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 958a22a6337853555e897f1e5a14fcd0471710981ec55253fe3441e9c772aafb
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 91417F31B89A0682FB209B1DE6942B973E2FF48B85F584031DA8E077B5DF2DF4409702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocErr_ItemObject_$Dict_ErrorObjectOccurredVectorcallWith
                                                                                                                                                                                                              • String ID: bool$feed
                                                                                                                                                                                                              • API String ID: 2902451266-2849697477
                                                                                                                                                                                                              • Opcode ID: f4f92837b73cd07083ecf196f641edd5c5d76e013ce287cc97f39c4dfbe217e1
                                                                                                                                                                                                              • Instruction ID: 22bf574b22b3526bed83f9f538037be64f699fae0206bfeb4c652c105beecc9c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: f4f92837b73cd07083ecf196f641edd5c5d76e013ce287cc97f39c4dfbe217e1
                                                                                                                                                                                                              • Instruction Fuzzy Hash: A2416075B89A0A82EB219F19E69427963E1FF48B85F484031DA8E077B5DF3CF452D302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocErr_ItemObject_$Dict_ErrorObjectOccurredVectorcallWith
                                                                                                                                                                                                              • String ID: bool$eligible
                                                                                                                                                                                                              • API String ID: 2902451266-3320767611
                                                                                                                                                                                                              • Opcode ID: eacaf991cd320d3b28d9c0a86148e8b297e2767c2de5e507dac64fabba49b49f
                                                                                                                                                                                                              • Instruction ID: 34871433674af3e6b3cfb049482723989d0b906d57dc5f5b94304871fe65e8d4
                                                                                                                                                                                                              • Opcode Fuzzy Hash: eacaf991cd320d3b28d9c0a86148e8b297e2767c2de5e507dac64fabba49b49f
                                                                                                                                                                                                              • Instruction Fuzzy Hash: E2310C72B89A4282EB548F59EA94279A3E3BF44B89F594031DA8D47774DF2CE444C702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$Object_State_ThreadTrackTrash_beginTrash_condTrash_endUnchecked
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2819143443-0
                                                                                                                                                                                                              • Opcode ID: 23d97488961b93e407653e4d04d1075f3d4a6115df0bee2f52c695c0df5d3962
                                                                                                                                                                                                              • Instruction ID: b729f4c34db554dcf70537dd7a4c9bcddde3495decb93444b970507ebda8f6b1
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 23d97488961b93e407653e4d04d1075f3d4a6115df0bee2f52c695c0df5d3962
                                                                                                                                                                                                              • Instruction Fuzzy Hash: BB41EB72A8860281EB554F399A9837832E5EF45FBDF165330CA6E422F5CF7DD4858302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$BoolCompareErr_FromLong_Object_OccurredRichSsize_t
                                                                                                                                                                                                              • String ID: __init__$charset_normalizer.md.UnprintablePlugin$ratio
                                                                                                                                                                                                              • API String ID: 2538524772-1538754472
                                                                                                                                                                                                              • Opcode ID: bd24d104d4e5ddc98eea7bfccf0ae522fc41dc3e0d7e104114ce5afde9d774f5
                                                                                                                                                                                                              • Instruction ID: dbe161fc800ba32d55f64bc7e3dd6660ca281382e38687581c74df51adb38b5f
                                                                                                                                                                                                              • Opcode Fuzzy Hash: bd24d104d4e5ddc98eea7bfccf0ae522fc41dc3e0d7e104114ce5afde9d774f5
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 2451A362F88A0A81E7519B2DEA801B963E1EF44B94F088631DD9D077F5DF3CF4459342
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Heap$AllocErrorFreeLastProcessValue
                                                                                                                                                                                                              • String ID: TlsGetValue failed from TclpGetAllocCache$alloc: invalid block: %p: %x %x$could not allocate thread local storage
                                                                                                                                                                                                              • API String ID: 3216287067-4238949377
                                                                                                                                                                                                              • Opcode ID: be96740cf8f7e0b5e119fe4fff375775447aacaea01372ae1198881d95a55691
                                                                                                                                                                                                              • Instruction ID: 24807c9e09e5309a2248e103d636c627a6585f5bfb27354fba2773166b8e7210
                                                                                                                                                                                                              • Opcode Fuzzy Hash: be96740cf8f7e0b5e119fe4fff375775447aacaea01372ae1198881d95a55691
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 5F41A576B18A5286EB58CF25E86097C33A0FB44BA4F1482B5DA7D47BD8EF3DE4418700
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DoubleErr_Float_Occurred$From
                                                                                                                                                                                                              • String ID: bool$float$mess_ratio$str
                                                                                                                                                                                                              • API String ID: 627764739-3758540285
                                                                                                                                                                                                              • Opcode ID: 8a02f97511670b38e9bcd773b23a0c6d973fa38f5433283c19ee847a82f0f0a0
                                                                                                                                                                                                              • Instruction ID: 97ff9cb8ba32e8e3052dd0b52c2ba62c55585e31d4b3b9774b4c58e87e8d440a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 8a02f97511670b38e9bcd773b23a0c6d973fa38f5433283c19ee847a82f0f0a0
                                                                                                                                                                                                              • Instruction Fuzzy Hash: DE41D222A4CA4681FB118B1DE4401BAA3E2FF95BC9F244136EACD436B4DF3CE945D742
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$Object_Vectorcall$Dict_Item
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 1355803777-217463007
                                                                                                                                                                                                              • Opcode ID: f44407c62ba38c985b018eb4be88fb5605f156d51110e078f0643a87e94a1170
                                                                                                                                                                                                              • Instruction ID: f3dece50694d6dbe6d43145b37037e23347bcc13cb5d387a002defbe259ddaab
                                                                                                                                                                                                              • Opcode Fuzzy Hash: f44407c62ba38c985b018eb4be88fb5605f156d51110e078f0643a87e94a1170
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 9F313A65E89A4381FB509F1DE9806B923E2AF45B99F448035CA8D0BBB5DF2DE448C703
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: From$String$Set_SizeUnicode_$Bytes_Complex_DoubleDoublesFloat_FrozenInternLong_PlaceTuple_
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 1377717875-0
                                                                                                                                                                                                              • Opcode ID: 1bc6b832a9b101eb94450793bee28bff6ca2690a3c262528acd6d01682900b35
                                                                                                                                                                                                              • Instruction ID: 69fdbd6bd1951f6beb4663c6726b2a0d864e49e1172914c02d00584bc5ae05dc
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 1bc6b832a9b101eb94450793bee28bff6ca2690a3c262528acd6d01682900b35
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 50C1F561F89B4686EA018F1CE9A02B97BE2FF05799F584235DA9E073B4DF2CE055C701
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$Object_State_ThreadTrackTrash_beginTrash_condTrash_endUnchecked
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2819143443-0
                                                                                                                                                                                                              • Opcode ID: fff406a76837bdfc3caa631c0de594268f2a13e9ca8c66fb56096f08c5388120
                                                                                                                                                                                                              • Instruction ID: 18cfc23af68b7618fb3cfebd2428fbffd395dd0188ea786375e7bd0c555b9c41
                                                                                                                                                                                                              • Opcode Fuzzy Hash: fff406a76837bdfc3caa631c0de594268f2a13e9ca8c66fb56096f08c5388120
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 64312D72A4860281EB595F3D9AA837836E1EF45F7EF158234CA6E022F4CF7DD4858352
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • memcpy.VCRUNTIME140 ref: 00007FFDFADA4CDF
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: TlsAlloc.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE21
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: TlsGetValue.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE4F
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: GetLastError.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE5D
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: GetProcessHeap.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE9B
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: HeapAlloc.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FEA9
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: AllocHeap$ErrorLastProcessValuememcpy
                                                                                                                                                                                                              • String ID: unable to alloc %u bytes
                                                                                                                                                                                                              • API String ID: 1456920652-2759121943
                                                                                                                                                                                                              • Opcode ID: ad50ca6a94e1e25a73d83ca7fc119f6538bde53ea5050e8631dc4addb833681f
                                                                                                                                                                                                              • Instruction ID: fb0e5d3767a51b518d0ebdef6d56c00ef20f162663e8e353209bc1ce65141749
                                                                                                                                                                                                              • Opcode Fuzzy Hash: ad50ca6a94e1e25a73d83ca7fc119f6538bde53ea5050e8631dc4addb833681f
                                                                                                                                                                                                              • Instruction Fuzzy Hash: A9B17C72B0978186EB688F25A864B6973A1FB88B94F184175DE6D0B79DEF3CE4418700
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_Unicode_$CharactersCopyFastFormatStringmemcpy
                                                                                                                                                                                                              • String ID: join() result is too long for a Python string$sequence item %zd: expected str instance, %.80s found
                                                                                                                                                                                                              • API String ID: 3966466113-1579438684
                                                                                                                                                                                                              • Opcode ID: bd94065e028ba6fa2eb67220a7b20d7e8b3b3746a6e474679368a889752c658a
                                                                                                                                                                                                              • Instruction ID: b9b837b9860ae4b914729984f0fd0051ffe11ff0bf536ea2cec3ee64b0f1403f
                                                                                                                                                                                                              • Opcode Fuzzy Hash: bd94065e028ba6fa2eb67220a7b20d7e8b3b3746a6e474679368a889752c658a
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 6161D3A2B4965682EA108B0DD5817F967D1FF45BE4F558231CD6D833F0DE3CD84A8302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$BoolCompareErr_FromLong_Object_OccurredRichSsize_t
                                                                                                                                                                                                              • String ID: ratio
                                                                                                                                                                                                              • API String ID: 2538524772-4234197119
                                                                                                                                                                                                              • Opcode ID: 3df6ddb79008031f2fa932144166eaa2e045ed27a22e43e2cec9a9a03f3e1f1f
                                                                                                                                                                                                              • Instruction ID: 0d74208cb5c896822614ad7d31eb44a8f9eb47e042c49100dcc9797dc3381b8f
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 3df6ddb79008031f2fa932144166eaa2e045ed27a22e43e2cec9a9a03f3e1f1f
                                                                                                                                                                                                              • Instruction Fuzzy Hash: FE519E31B88A0286F7659B6D9A902B823E1EF49BD4F184131DE5D077F5DF3DE8529203
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830637851.00007FFE0E161000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFE0E160000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830611219.00007FFE0E160000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830675705.00007FFE0E17B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830706221.00007FFE0E184000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830736890.00007FFE0E185000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830762935.00007FFE0E188000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830790164.00007FFE0E189000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0e160000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: QueryVirtual
                                                                                                                                                                                                              • String ID: VirtualProtect failed with code 0x%x$ VirtualQuery failed for %d bytes at address %p$Address %p has no image-section$Mingw-w64 runtime failure:
                                                                                                                                                                                                              • API String ID: 1804819252-1534286854
                                                                                                                                                                                                              • Opcode ID: 2d23e5b5e4a6b3a2941f311f6093bae03f5d17fafae689303d1f5b7671905812
                                                                                                                                                                                                              • Instruction ID: 7f3c4238a61c4ea82e4e9acee506b3710cc47d75045ee8abe34b544685c6b4d7
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 2d23e5b5e4a6b3a2941f311f6093bae03f5d17fafae689303d1f5b7671905812
                                                                                                                                                                                                              • Instruction Fuzzy Hash: F9418DB2B08B4682EB109B55E4406A977B1FB8AF84F584136DADC073B4EE3CE545D740
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Alloc$ErrorHeapLastValue$CriticalLeaveProcessSection
                                                                                                                                                                                                              • String ID: alloc: could not allocate %d new objects
                                                                                                                                                                                                              • API String ID: 4183754528-1866737643
                                                                                                                                                                                                              • Opcode ID: 8e3c70295d4e6dc4cc6b8ab5dd1595e84d9ca708e68755de6ff6b0f6283c91b9
                                                                                                                                                                                                              • Instruction ID: b88200fc9bc27ea3cb7fca9b4589a1e771bf68a02f0473f8e4aa9e3e3d534809
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 8e3c70295d4e6dc4cc6b8ab5dd1595e84d9ca708e68755de6ff6b0f6283c91b9
                                                                                                                                                                                                              • Instruction Fuzzy Hash: FD412B72B09B0286EB189F25E8A4A3833A0FB58B44F141175CA6E4B3DAEF3DE5548740
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$Object_Vectorcall$Err_FormatMethod
                                                                                                                                                                                                              • String ID: bool$eligible
                                                                                                                                                                                                              • API String ID: 131476257-3320767611
                                                                                                                                                                                                              • Opcode ID: f397ca9387d6dfb1835b31036ec0af176946d4d6a5d65748a34c9214785249c7
                                                                                                                                                                                                              • Instruction ID: 43aa5c3c2efcf80058437b721323dd87ad46e87eef10957cbbd26091df97fa46
                                                                                                                                                                                                              • Opcode Fuzzy Hash: f397ca9387d6dfb1835b31036ec0af176946d4d6a5d65748a34c9214785249c7
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 53419571F89A4682FB208B1DE9803B563E2EF44B99F585031DA4D077B5DE2CF484D312
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0280: TlsAlloc.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFAD11924), ref: 00007FFDFADA028D
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0280: TlsGetValue.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFAD11924), ref: 00007FFDFADA02BB
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0280: GetLastError.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFAD11924), ref: 00007FFDFADA02C9
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0280: LeaveCriticalSection.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFAD11924), ref: 00007FFDFADA036B
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0280: GetProcessHeap.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFAD11924), ref: 00007FFDFADA037E
                                                                                                                                                                                                                • Part of subcall function 00007FFDFADA0280: HeapAlloc.KERNEL32(?,?,?,?,?,?,?,?,?,?,?,?,00007FFDFAD11924), ref: 00007FFDFADA038F
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: TlsAlloc.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE21
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: TlsGetValue.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE4F
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: GetLastError.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE5D
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: GetProcessHeap.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE9B
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: HeapAlloc.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FEA9
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD75B50: TlsGetValue.KERNEL32(?,?,?,00007FFDFADAD0F5,?,?,00000000,00007FFDFADAD26E,?,?,?,?,?,?,?,00007FFDFADAD68A), ref: 00007FFDFAD75BAD
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD75B50: TlsGetValue.KERNEL32(?,?,?,00007FFDFADAD0F5,?,?,00000000,00007FFDFADAD26E,?,?,?,?,?,?,?,00007FFDFADAD68A), ref: 00007FFDFAD75C85
                                                                                                                                                                                                              • memcpy.VCRUNTIME140 ref: 00007FFDFAC9AD82
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: AllocHeapValue$ErrorLastProcess$CriticalLeaveSectionmemcpy
                                                                                                                                                                                                              • String ID: LOOKUP$MATHFUNC$TCL$hfunc::$list creation failed: unable to alloc %u bytes$unable to alloc %u bytes$unknown math function "%s"
                                                                                                                                                                                                              • API String ID: 2474507647-509392037
                                                                                                                                                                                                              • Opcode ID: 1735dbdf200fb8b18ae8690e8eb35d9849481e401474bdd2a71570092acbc854
                                                                                                                                                                                                              • Instruction ID: 874ce507b382d2777581b92b69f53fd428004cc4601bf3e8aba2baee57f2155a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 1735dbdf200fb8b18ae8690e8eb35d9849481e401474bdd2a71570092acbc854
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 90C18A36B0878286E718DF11E8609AD77A4FB88B84B448575DEAD077DAEF3CE451C740
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$Object_State_ThreadTrackTrash_beginTrash_condTrash_endUnchecked
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2819143443-0
                                                                                                                                                                                                              • Opcode ID: 1808094ad2c5952838fb359644ebaa2aa6756bbb3d9bb10f20ec9669fa938947
                                                                                                                                                                                                              • Instruction ID: e1b31f0a986faaac3dd5a0005749e0935c9fc878f5d0a72bf501d2e368ca073a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 1808094ad2c5952838fb359644ebaa2aa6756bbb3d9bb10f20ec9669fa938947
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 512103B2A8CA4281EB554F29969837823E1EF45F6EF154234D96E822F5CF3DD4858303
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$BoolCompareErr_FromLong_Object_OccurredRichSsize_t
                                                                                                                                                                                                              • String ID: ratio
                                                                                                                                                                                                              • API String ID: 2538524772-4234197119
                                                                                                                                                                                                              • Opcode ID: b6db84d1c7e11e830000ef7b1fab697241f009562e2efea8cddf9bf8aca289d7
                                                                                                                                                                                                              • Instruction ID: abc19d3ba9fe6ccd5dfcc19aeedd7c3be6aba8e90bcc0df0635d06c55c996683
                                                                                                                                                                                                              • Opcode Fuzzy Hash: b6db84d1c7e11e830000ef7b1fab697241f009562e2efea8cddf9bf8aca289d7
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 9A41A132F88A5286E7619B2D9A843B873E1EF49B95F180230DE9D177B4DF3DE4418342
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$BoolCompareErr_FromLong_Object_OccurredRichSsize_t
                                                                                                                                                                                                              • String ID: ratio
                                                                                                                                                                                                              • API String ID: 2538524772-4234197119
                                                                                                                                                                                                              • Opcode ID: c6cb76a82c0156d83f652a4623d6809029c4d4441d1b486eb3f0817f7220173e
                                                                                                                                                                                                              • Instruction ID: ab6b095d5476de5b002b6c6d083db78719bf5b2725779dd80cfcdb809851a92b
                                                                                                                                                                                                              • Opcode Fuzzy Hash: c6cb76a82c0156d83f652a4623d6809029c4d4441d1b486eb3f0817f7220173e
                                                                                                                                                                                                              • Instruction Fuzzy Hash: BC41C232F8C60282E6209B6D9A942B9B3E2EF49B94F084231DE5D136F5DF3DE4458742
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'CjkInvalidStopPlugin' object attribute '_wrong_stop_count' cannot be deleted$attribute '_wrong_stop_count' of 'CjkInvalidStopPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-420147485
                                                                                                                                                                                                              • Opcode ID: d003440fe6475c9f59ed82b76a527c73c740b1cb598ce72131a3b28642e6cd38
                                                                                                                                                                                                              • Instruction ID: 5ab349ef9741beca4c2229f31c5562952266447039539c57e4c05cf3e0d5359c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: d003440fe6475c9f59ed82b76a527c73c740b1cb598ce72131a3b28642e6cd38
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 3F31A071F88A0381EE44EB2DE5D42B923E1EF94B94F585132DA5D467F9DE2CE484CB02
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'UnprintablePlugin' object attribute '_unprintable_count' cannot be deleted$attribute '_unprintable_count' of 'UnprintablePlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-2997357838
                                                                                                                                                                                                              • Opcode ID: 05d8df805b557c735720644633408e4608b0fbfc31e106f8cc358c40349ee830
                                                                                                                                                                                                              • Instruction ID: 6249e3620784e919a91942f5edf98b3cb4e1aae481668f14860bf4fe55a6891d
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 05d8df805b557c735720644633408e4608b0fbfc31e106f8cc358c40349ee830
                                                                                                                                                                                                              • Instruction Fuzzy Hash: A931AF71F8860281EE44DB2DE5D42B823E0EF94B98F985132DA5E477F5DE2CE484E302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'SuperWeirdWordPlugin' object attribute '_bad_word_count' cannot be deleted$attribute '_bad_word_count' of 'SuperWeirdWordPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-3520798986
                                                                                                                                                                                                              • Opcode ID: 77c8772b984a2595aac65ff4e3f8c76f4f621aa382ae6883f4a9f238d60c89b9
                                                                                                                                                                                                              • Instruction ID: 4af4c5e8898bfec4978e95e78c16783eda5d68324148a11e7df58f912683abde
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 77c8772b984a2595aac65ff4e3f8c76f4f621aa382ae6883f4a9f238d60c89b9
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 0F31C671F8850282EE54AB2DE5D42B823E1FF84B94F584132EA5E477F5DE2CE485CB02
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'ArabicIsolatedFormPlugin' object attribute '_character_count' cannot be deleted$attribute '_character_count' of 'ArabicIsolatedFormPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-3970786323
                                                                                                                                                                                                              • Opcode ID: 2e629f3262497ccb22304782c1099c2c36976ab49dc67f606c1b062756317bff
                                                                                                                                                                                                              • Instruction ID: 524597a0c9a553ee8550209d8e8b0a423214fa5bd1b66a2a5fa29bb3af875c9f
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 2e629f3262497ccb22304782c1099c2c36976ab49dc67f606c1b062756317bff
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 4B318C62F88A0281EE54DB2DE5D42B823E1EF94BD4F985131DA5E477F5DE2CE484C702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              • int, xrefs: 00007FFE0CFC62A6
                                                                                                                                                                                                              • 'SuspiciousDuplicateAccentPlugin' object attribute '_successive_count' cannot be deleted, xrefs: 00007FFE0CFC621C
                                                                                                                                                                                                              • attribute '_successive_count' of 'SuspiciousDuplicateAccentPlugin' undefined, xrefs: 00007FFE0CFC61A8
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'SuspiciousDuplicateAccentPlugin' object attribute '_successive_count' cannot be deleted$attribute '_successive_count' of 'SuspiciousDuplicateAccentPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-1864222365
                                                                                                                                                                                                              • Opcode ID: 5778859781aa3561020ceb3b05ef8ae724d89a4ce4f3630b9ef98cc72eb7347a
                                                                                                                                                                                                              • Instruction ID: 374de074be33ccf81c5928446f8825a1ad05dc0e0b25f3f3c4b4187949b330cf
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 5778859781aa3561020ceb3b05ef8ae724d89a4ce4f3630b9ef98cc72eb7347a
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 49318361F8C90282EE449B1DE9D42F823E1EF88B98F585131EA5D877F5DE2CE495C702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              • int, xrefs: 00007FFE0CFC86C6
                                                                                                                                                                                                              • attribute '_successive_upper_lower_count_final' of 'ArchaicUpperLowerPlugin' undefined, xrefs: 00007FFE0CFC85C8
                                                                                                                                                                                                              • 'ArchaicUpperLowerPlugin' object attribute '_successive_upper_lower_count_final' cannot be deleted, xrefs: 00007FFE0CFC863C
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'ArchaicUpperLowerPlugin' object attribute '_successive_upper_lower_count_final' cannot be deleted$attribute '_successive_upper_lower_count_final' of 'ArchaicUpperLowerPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-528010561
                                                                                                                                                                                                              • Opcode ID: 2ca47d72e77a7153c4af469a22f98ddc2045af71414dbb353d6064c52d0c80cb
                                                                                                                                                                                                              • Instruction ID: 5c57d96abe5f17062358a1b58d3db4d52f07526b45fd83ec382a99a4b6288076
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 2ca47d72e77a7153c4af469a22f98ddc2045af71414dbb353d6064c52d0c80cb
                                                                                                                                                                                                              • Instruction Fuzzy Hash: F731D071F8850282EA449B2DE6D42B923E1FF84BD8F584131EA5E073F4DE2CE8848702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'TooManySymbolOrPunctuationPlugin' object attribute '_symbol_count' cannot be deleted$attribute '_symbol_count' of 'TooManySymbolOrPunctuationPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-2291034628
                                                                                                                                                                                                              • Opcode ID: 005893139290546e466727384096f8c4c27f16b4c59161034916739a6ab1bdf9
                                                                                                                                                                                                              • Instruction ID: 3e88bc517f37fea4c9de27c6c827c5282ca12ffd1dcc60b6c01e3fd9f68178e2
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 005893139290546e466727384096f8c4c27f16b4c59161034916739a6ab1bdf9
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 4831A062F8850382EF549B2DE5D52B923E0EF88B94F584131DA5E477F5DE2CE4849342
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'SuspiciousRange' object attribute '_character_count' cannot be deleted$attribute '_character_count' of 'SuspiciousRange' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-3882440367
                                                                                                                                                                                                              • Opcode ID: edf70cb319030b3d86d441b19e0745afc740f480ca4045dac8bdcfc512da58eb
                                                                                                                                                                                                              • Instruction ID: a9635f3dd58c8008a13a07e542993a8358dba6afff17fe6a15c95e16407c2d6f
                                                                                                                                                                                                              • Opcode Fuzzy Hash: edf70cb319030b3d86d441b19e0745afc740f480ca4045dac8bdcfc512da58eb
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 6D318161F8C50281EE549B2DE5D42B823E1EF88B94F584131EA9D877F5DE2CE495C702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'SuperWeirdWordPlugin' object attribute '_word_count' cannot be deleted$attribute '_word_count' of 'SuperWeirdWordPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-1212817586
                                                                                                                                                                                                              • Opcode ID: 16b82e3689da71a62fdb9f4fcb28de3a703054875de315429c3694e8e6cd4c3d
                                                                                                                                                                                                              • Instruction ID: d246d7e3f73cca2f13e3f77121f1121eca277341d25c13a8486299e8203d9282
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 16b82e3689da71a62fdb9f4fcb28de3a703054875de315429c3694e8e6cd4c3d
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 6531AF61F8860281EF54AB2DE9D52B823E1EF84B94F585132DA5D477F5DE2CE484CB02
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'SuperWeirdWordPlugin' object attribute '_bad_character_count' cannot be deleted$attribute '_bad_character_count' of 'SuperWeirdWordPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-2709777744
                                                                                                                                                                                                              • Opcode ID: 610f13cc42156de412b3f6d1ccc7dde81ee8bb81fe19c5e5436d4dfc6cd023cb
                                                                                                                                                                                                              • Instruction ID: 300790c6aafb73781c37e117f530e933bc830579f5993b8e83f958b061ba9330
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 610f13cc42156de412b3f6d1ccc7dde81ee8bb81fe19c5e5436d4dfc6cd023cb
                                                                                                                                                                                                              • Instruction Fuzzy Hash: A431D471F8860681EA44AB2DE5D42B823E0FF44BD4F984132DA5D077F5EE2DE494CB02
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'SuperWeirdWordPlugin' object attribute '_buffer_accent_count' cannot be deleted$attribute '_buffer_accent_count' of 'SuperWeirdWordPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-76466605
                                                                                                                                                                                                              • Opcode ID: 20ea869bad6b8ed73006467498f91221eb8f9dd8b91723df2faa57ca20f3ad29
                                                                                                                                                                                                              • Instruction ID: 78575848086e8310c7a4d152db715e3f0ab9f2ea6877bab69d9785a815138b3d
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 20ea869bad6b8ed73006467498f91221eb8f9dd8b91723df2faa57ca20f3ad29
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 9231AF71F8860282EA44AB2DE5D42B923E1FF84B94F584132DA5E477F5DE2CE494CB02
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'TooManyAccentuatedPlugin' object attribute '_accentuated_count' cannot be deleted$attribute '_accentuated_count' of 'TooManyAccentuatedPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-3693778415
                                                                                                                                                                                                              • Opcode ID: 7f11271614b407e1cd5d041de6a849fa1ce6af29865a2d7861870a54299a5fe4
                                                                                                                                                                                                              • Instruction ID: 8a45d6324d1f6ed7002628ba44a309f1847ea16930ed40eb65107a8820aea63b
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 7f11271614b407e1cd5d041de6a849fa1ce6af29865a2d7861870a54299a5fe4
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 6031B072F8850282EE549B2DE9D42B823E1FF48BE4F584131DA9E477F5DE2CE4949302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              • int, xrefs: 00007FFE0CFC8586
                                                                                                                                                                                                              • 'ArchaicUpperLowerPlugin' object attribute '_successive_upper_lower_count' cannot be deleted, xrefs: 00007FFE0CFC84FC
                                                                                                                                                                                                              • attribute '_successive_upper_lower_count' of 'ArchaicUpperLowerPlugin' undefined, xrefs: 00007FFE0CFC8488
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'ArchaicUpperLowerPlugin' object attribute '_successive_upper_lower_count' cannot be deleted$attribute '_successive_upper_lower_count' of 'ArchaicUpperLowerPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-634379450
                                                                                                                                                                                                              • Opcode ID: 3342e34050822ecdd092d2c1701ec675c9b80d10f8f017621af40ec443b25660
                                                                                                                                                                                                              • Instruction ID: d492d59626eec31c859ade3125440780104585eadb2b079cf53494ac5630c1c2
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 3342e34050822ecdd092d2c1701ec675c9b80d10f8f017621af40ec443b25660
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 8D31AF62F8890282EE54DB2DE5D42B823E1EF48BE8F584531DA5E477F5DE6CE484C702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'CjkInvalidStopPlugin' object attribute '_cjk_character_count' cannot be deleted$attribute '_cjk_character_count' of 'CjkInvalidStopPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-399339277
                                                                                                                                                                                                              • Opcode ID: f2c272c237092df4c159db7bbb8ebb4d417ee1358fd08bf9141b406699d39ed6
                                                                                                                                                                                                              • Instruction ID: 94356ef5acbd6a8a3236782c6263b30b35d17691ee2efdde0b5718ec88e2e0da
                                                                                                                                                                                                              • Opcode Fuzzy Hash: f2c272c237092df4c159db7bbb8ebb4d417ee1358fd08bf9141b406699d39ed6
                                                                                                                                                                                                              • Instruction Fuzzy Hash: C1318061F8890381EA54AB2DE5D42B923E1FF84B94F584132DA5E477F5EE2CE4948702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'UnprintablePlugin' object attribute '_character_count' cannot be deleted$attribute '_character_count' of 'UnprintablePlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-2596148235
                                                                                                                                                                                                              • Opcode ID: 073f5d8d8577f69fc90c9a8fdde1e95b02313488756eee5ef187c2381a1a2916
                                                                                                                                                                                                              • Instruction ID: 1c1a12473b69a85fc6cefa224f7487d1adfd764d2d0d6eccda2489e502083c87
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 073f5d8d8577f69fc90c9a8fdde1e95b02313488756eee5ef187c2381a1a2916
                                                                                                                                                                                                              • Instruction Fuzzy Hash: F031B271F8C60282EA54DB2DE5D82B823E1EF44B94F584131DA5E477F5DE2CE4849302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'SuperWeirdWordPlugin' object attribute '_foreign_long_count' cannot be deleted$attribute '_foreign_long_count' of 'SuperWeirdWordPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-3135691889
                                                                                                                                                                                                              • Opcode ID: 35cb3d4f2bd9c4a5d37c2cde372bddb3ca93a0b263ca3f3a2d664a0bc4599930
                                                                                                                                                                                                              • Instruction ID: d4909f42fa137828e273fc3cfe18230be83ceeac0441a7b0b4c8aac03f8d0db9
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 35cb3d4f2bd9c4a5d37c2cde372bddb3ca93a0b263ca3f3a2d664a0bc4599930
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 23318362F8850281EA54AB1DE5D42B823E1EF48B94F585132EA5D477F5DE2CE4D4CB02
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'ArabicIsolatedFormPlugin' object attribute '_isolated_form_count' cannot be deleted$attribute '_isolated_form_count' of 'ArabicIsolatedFormPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-4047731557
                                                                                                                                                                                                              • Opcode ID: 1ec334efbc93af8a0daa537c9c947367f6496fe570f3d383ebc24800b9db443f
                                                                                                                                                                                                              • Instruction ID: fd2a03eb921a1fcb5af8b75bb54e0be6b8f16c7d37cde97c2990032bb9011855
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 1ec334efbc93af8a0daa537c9c947367f6496fe570f3d383ebc24800b9db443f
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 85318062F8890281EA549B2DE5D42B923E1FF98BD4F584131DA5E077F5DE2CE4948702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              • int, xrefs: 00007FFE0CFC4FC6
                                                                                                                                                                                                              • 'TooManySymbolOrPunctuationPlugin' object attribute '_punctuation_count' cannot be deleted, xrefs: 00007FFE0CFC4F3C
                                                                                                                                                                                                              • attribute '_punctuation_count' of 'TooManySymbolOrPunctuationPlugin' undefined, xrefs: 00007FFE0CFC4EC8
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'TooManySymbolOrPunctuationPlugin' object attribute '_punctuation_count' cannot be deleted$attribute '_punctuation_count' of 'TooManySymbolOrPunctuationPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-1459665959
                                                                                                                                                                                                              • Opcode ID: 524d028e614f50b41909a65e2b05ff1c14cbdfe08726ae935d08e3c758078267
                                                                                                                                                                                                              • Instruction ID: 799a503478679d032798ff3e24be1d835e24473f34fa2f6bde7edfae4ffe9ef1
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 524d028e614f50b41909a65e2b05ff1c14cbdfe08726ae935d08e3c758078267
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 09318F72F8850281EE55DB2DE5E42B827E1EF84B94F984131EA5D477F5DE2CE494C302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              • 'SuspiciousDuplicateAccentPlugin' object attribute '_character_count' cannot be deleted, xrefs: 00007FFE0CFC635C
                                                                                                                                                                                                              • int, xrefs: 00007FFE0CFC63E6
                                                                                                                                                                                                              • attribute '_character_count' of 'SuspiciousDuplicateAccentPlugin' undefined, xrefs: 00007FFE0CFC62E8
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'SuspiciousDuplicateAccentPlugin' object attribute '_character_count' cannot be deleted$attribute '_character_count' of 'SuspiciousDuplicateAccentPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-543361526
                                                                                                                                                                                                              • Opcode ID: 1291b6d293bf1ed5ae64a56b00bf1b13860b617c90494c0dd0123d29bd04fbc4
                                                                                                                                                                                                              • Instruction ID: 6186ced251ad774ed112e54b0054e93aecfe9feea1561a55a758b6d408ddf4bd
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 1291b6d293bf1ed5ae64a56b00bf1b13860b617c90494c0dd0123d29bd04fbc4
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 1931B471F8C50282EE549B2DE5D42B823E0EF48B94F584231EA6E877F5DE2CE4948302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              • int, xrefs: 00007FFE0CFC67F6
                                                                                                                                                                                                              • attribute '_suspicious_successive_range_count' of 'SuspiciousRange' undefined, xrefs: 00007FFE0CFC66F8
                                                                                                                                                                                                              • 'SuspiciousRange' object attribute '_suspicious_successive_range_count' cannot be deleted, xrefs: 00007FFE0CFC676C
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'SuspiciousRange' object attribute '_suspicious_successive_range_count' cannot be deleted$attribute '_suspicious_successive_range_count' of 'SuspiciousRange' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-916769388
                                                                                                                                                                                                              • Opcode ID: 32c8cc5da1c5a4c53662f2a02eb56b9d7fcea26900f0b6a46b27aacae368bd4d
                                                                                                                                                                                                              • Instruction ID: da93f530b5704d7717dd975920d5aef8b0af82a0ed448fb642264110cdf2310a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 32c8cc5da1c5a4c53662f2a02eb56b9d7fcea26900f0b6a46b27aacae368bd4d
                                                                                                                                                                                                              • Instruction Fuzzy Hash: BA31B071F8C60281EE449B2DE5D42B823E0EF84B98F584531EA5D877F5DE2CE4A5C302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'ArchaicUpperLowerPlugin' object attribute '_character_count' cannot be deleted$attribute '_character_count' of 'ArchaicUpperLowerPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-4184598959
                                                                                                                                                                                                              • Opcode ID: 342a4cd3f7d259d24aeb9a776a1e708ee513c6b05d4146dbb2a3107d3dc6b54c
                                                                                                                                                                                                              • Instruction ID: 2e0b1325df2e20ca0ad367d5d5e696881cb501ed2ee1fa8aba1819e976324605
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 342a4cd3f7d259d24aeb9a776a1e708ee513c6b05d4146dbb2a3107d3dc6b54c
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 5431C172F8850285EE449B2DE5D52B823E0EF84BD4F985131DA5E077F5EE2CE8A4C302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'SuperWeirdWordPlugin' object attribute '_character_count' cannot be deleted$attribute '_character_count' of 'SuperWeirdWordPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-3920090044
                                                                                                                                                                                                              • Opcode ID: cd35c19dcae03a46ba023d8733dc0448e3e938908ebc375541851ad2aa41712c
                                                                                                                                                                                                              • Instruction ID: 7ecdc6ab9f324db6214ea68fcd8cfc55fd3262f9ebd2a6cd8cb3223862592d78
                                                                                                                                                                                                              • Opcode Fuzzy Hash: cd35c19dcae03a46ba023d8733dc0448e3e938908ebc375541851ad2aa41712c
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 3031B271F8850286EA44AB2DE5D42B823E1EF84B94F585532EA5E477F5DE2CE484C702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              • int, xrefs: 00007FFE0CFC5246
                                                                                                                                                                                                              • 'TooManySymbolOrPunctuationPlugin' object attribute '_character_count' cannot be deleted, xrefs: 00007FFE0CFC51BC
                                                                                                                                                                                                              • attribute '_character_count' of 'TooManySymbolOrPunctuationPlugin' undefined, xrefs: 00007FFE0CFC5148
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'TooManySymbolOrPunctuationPlugin' object attribute '_character_count' cannot be deleted$attribute '_character_count' of 'TooManySymbolOrPunctuationPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-4240200891
                                                                                                                                                                                                              • Opcode ID: 536accf797a1bbe65dc8a4d75f5ab69cf8332c7d165fc34bcb50e14afcb09dcc
                                                                                                                                                                                                              • Instruction ID: 4dff6f5fbd3aaf362796f64d6a0957396acd198b21e7d46ad44a4b8cd46d9a6c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 536accf797a1bbe65dc8a4d75f5ab69cf8332c7d165fc34bcb50e14afcb09dcc
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 7831C471F8850282EE549B1DE5D82B923E1EF48B94F984131DA5D477F5DE2CE484D302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'TooManyAccentuatedPlugin' object attribute '_character_count' cannot be deleted$attribute '_character_count' of 'TooManyAccentuatedPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-2022335554
                                                                                                                                                                                                              • Opcode ID: cef47ad94a8524b23c3b55ca13b9a14f862f4f76f789291d3bde506f314e6f26
                                                                                                                                                                                                              • Instruction ID: 0f183729a756347db3c5048ff3636c763830eb0662c4cf6188b161292962e628
                                                                                                                                                                                                              • Opcode Fuzzy Hash: cef47ad94a8524b23c3b55ca13b9a14f862f4f76f789291d3bde506f314e6f26
                                                                                                                                                                                                              • Instruction Fuzzy Hash: C931AC61F88A0682EE44DB2DE5D42B823E1EF88B94F984131DA5E477F5DE2CE4D4D702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              • int, xrefs: 00007FFE0CFC8446
                                                                                                                                                                                                              • 'ArchaicUpperLowerPlugin' object attribute '_character_count_since_last_sep' cannot be deleted, xrefs: 00007FFE0CFC83BC
                                                                                                                                                                                                              • attribute '_character_count_since_last_sep' of 'ArchaicUpperLowerPlugin' undefined, xrefs: 00007FFE0CFC8348
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'ArchaicUpperLowerPlugin' object attribute '_character_count_since_last_sep' cannot be deleted$attribute '_character_count_since_last_sep' of 'ArchaicUpperLowerPlugin' undefined$int
                                                                                                                                                                                                              • API String ID: 1450464846-2037488444
                                                                                                                                                                                                              • Opcode ID: 1006a038ca7837f55bf567080db1d952f620b641b4547de6e2a8b337716dbb5f
                                                                                                                                                                                                              • Instruction ID: c48811f46320cc73d646547adf166f3b95475960e48e22adb80b8d789e96e657
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 1006a038ca7837f55bf567080db1d952f620b641b4547de6e2a8b337716dbb5f
                                                                                                                                                                                                              • Instruction Fuzzy Hash: E631B272F8850282EE549B2DE5D42B823E1FF88BD4F985131DA5E477F5DE2CE4848302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$FromLong_Ssize_t$ContainsNumber_Object_Set_Vectorcall
                                                                                                                                                                                                              • String ID: bool$feed
                                                                                                                                                                                                              • API String ID: 3415927029-2849697477
                                                                                                                                                                                                              • Opcode ID: eb45302e3cef5080e95074768180575d99dfa37b4141d0cc9422c2bb42ee7491
                                                                                                                                                                                                              • Instruction ID: e9503f561ea27d2b27822cd93f7026673e9576622015213730b3a1605123e61a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: eb45302e3cef5080e95074768180575d99dfa37b4141d0cc9422c2bb42ee7491
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 7C413231F88A4282EB619F19F5912BA63E1FF44B84F485035DA8D47BB5DF2CE440C752
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3617616757-0
                                                                                                                                                                                                              • Opcode ID: 527074c6cd195ab482c56603e858959c90a590d2c84401fac90cb2060dcc2367
                                                                                                                                                                                                              • Instruction ID: 4e9a956e96cbfa7d1f3b59b7983789ec6c6f70f968c4eac03b3064190c540e8a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 527074c6cd195ab482c56603e858959c90a590d2c84401fac90cb2060dcc2367
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 2441C872A8DA0181E7654F3CDA8937827E0EF55B3EF140334EA6A811E5CF7E98858302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$Object_State_ThreadTrackTrash_beginTrash_condTrash_endUnchecked
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2819143443-0
                                                                                                                                                                                                              • Opcode ID: 1c16e7615a0f82207d80faaa12bf775c49de3bd6999ef687b31fc543c5e7b3c6
                                                                                                                                                                                                              • Instruction ID: 0acd6e1ffce9bbb40437cb0d9c8c231186417c8cfd488c59051c44678e6526b9
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 1c16e7615a0f82207d80faaa12bf775c49de3bd6999ef687b31fc543c5e7b3c6
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 0D211F71A48B0281EB558F39A69833822F1AF55FAAF154230D96E462F4CF7CE485A742
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • PyLong_FromSsize_t.PYTHON312 ref: 00007FFE0CFC2D16
                                                                                                                                                                                                              • PyLong_FromSsize_t.PYTHON312 ref: 00007FFE0CFC2D42
                                                                                                                                                                                                              • PyNumber_Remainder.PYTHON312 ref: 00007FFE0CFC2D5F
                                                                                                                                                                                                              • _Py_Dealloc.PYTHON312 ref: 00007FFE0CFC2D76
                                                                                                                                                                                                              • _Py_Dealloc.PYTHON312 ref: 00007FFE0CFC2D8A
                                                                                                                                                                                                              • _Py_Dealloc.PYTHON312 ref: 00007FFE0CFC2DE4
                                                                                                                                                                                                                • Part of subcall function 00007FFE0CFC3590: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,00007FFE0CFC28DB), ref: 00007FFE0CFC3599
                                                                                                                                                                                                                • Part of subcall function 00007FFE0CFC3590: fprintf.MSPDB140-MSVCRT ref: 00007FFE0CFC35A9
                                                                                                                                                                                                                • Part of subcall function 00007FFE0CFC3590: __acrt_iob_func.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,00007FFE0CFC28DB), ref: 00007FFE0CFC35B3
                                                                                                                                                                                                                • Part of subcall function 00007FFE0CFC3590: fflush.API-MS-WIN-CRT-STDIO-L1-1-0(?,?,?,?,00007FFE0CFC28DB), ref: 00007FFE0CFC35BC
                                                                                                                                                                                                                • Part of subcall function 00007FFE0CFC3590: abort.API-MS-WIN-CRT-RUNTIME-L1-1-0(?,?,?,?,00007FFE0CFC28DB), ref: 00007FFE0CFC35C2
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$FromLong_Ssize_t__acrt_iob_func$Number_Remainderabortfflushfprintf
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 1333916573-0
                                                                                                                                                                                                              • Opcode ID: 1ff0950ba76d1fb5de8f3a40737609fc14ed6e45cecf514f6e3c309322584276
                                                                                                                                                                                                              • Instruction ID: 243f7e59891f4784cc6171b792654fc40632dfeb5c615587c55cdf9a240f13fe
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 1ff0950ba76d1fb5de8f3a40737609fc14ed6e45cecf514f6e3c309322584276
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 7641B471F8864282EA544B1DE69437863E1EF59BE5F484130DE5E477F9DF2CE8828702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$FromLong_Ssize_t$MultiplyNumber_
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3214704217-0
                                                                                                                                                                                                              • Opcode ID: e441c8e1654ce7b2f422eefc1750921705619e20d6a3389d9b7057bf79d9000f
                                                                                                                                                                                                              • Instruction ID: 3433b5ff2f6c4ca1b1a75197b85bb267c832be03ca820b711ddadf847102afed
                                                                                                                                                                                                              • Opcode Fuzzy Hash: e441c8e1654ce7b2f422eefc1750921705619e20d6a3389d9b7057bf79d9000f
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 13317232B88A0382EA588F1DE69437862D0EF59BF5F085130DB5E477F8DE2CE4918302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$FromLong_Ssize_t$Number_
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 4245833954-0
                                                                                                                                                                                                              • Opcode ID: ae72d080b4b55a948d5582023073e92d7aff9d277a6dfd1cb9816ae3c140e2c2
                                                                                                                                                                                                              • Instruction ID: 6c119f76595757fddb976a7f547523a37558dc26d6f1d9e1df100b8f86425c55
                                                                                                                                                                                                              • Opcode Fuzzy Hash: ae72d080b4b55a948d5582023073e92d7aff9d277a6dfd1cb9816ae3c140e2c2
                                                                                                                                                                                                              • Instruction Fuzzy Hash: DF319831B8DA4386EA684B1D969437862E1EF45BE5F045130DE5D07BF5DF3CE4459302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$FromLong_Ssize_t$Number_Subtract
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2424657569-0
                                                                                                                                                                                                              • Opcode ID: aeebb34f4fc22b334b36647e21926670cdad37f7e6ebb6e2507bbb1c10b61d03
                                                                                                                                                                                                              • Instruction ID: bfa8d051664095150615740db1dd58a02d2bb21bdc2aacf9bd1e8d95883f2502
                                                                                                                                                                                                              • Opcode Fuzzy Hash: aeebb34f4fc22b334b36647e21926670cdad37f7e6ebb6e2507bbb1c10b61d03
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 73318E32B89A4386EE588F19E69437963E0EF48B95F485030DB5E077A9DF3CE4858702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830637851.00007FFE0E161000.00000020.00000001.01000000.00000018.sdmp, Offset: 00007FFE0E160000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830611219.00007FFE0E160000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830675705.00007FFE0E17B000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830706221.00007FFE0E184000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830736890.00007FFE0E185000.00000004.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830762935.00007FFE0E188000.00000008.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830790164.00007FFE0E189000.00000002.00000001.01000000.00000018.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0e160000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: _errno_writestrerror
                                                                                                                                                                                                              • String ID: internal error: deflate stream corrupt
                                                                                                                                                                                                              • API String ID: 3682106801-3609297558
                                                                                                                                                                                                              • Opcode ID: 452c91020052c469e2347378220a560f789623f8c2242b884211b170516ffe70
                                                                                                                                                                                                              • Instruction ID: d6a9fd82e7f428fc88950dba868e809ec5ee53e65391c1662ec0c4b3258abe78
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 452c91020052c469e2347378220a560f789623f8c2242b884211b170516ffe70
                                                                                                                                                                                                              • Instruction Fuzzy Hash: AF51E7726092DB87EA949A299544BBE339DFF847A4F518137DE8D432E2DF38E844C700
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String$Unicode_
                                                                                                                                                                                                              • String ID: Python int too large to convert to C ssize_t$string index out of range
                                                                                                                                                                                                              • API String ID: 2250126396-644864186
                                                                                                                                                                                                              • Opcode ID: e36458edd2254e28eaa8631afe286072e5f7bd0a67a5b6a46e6ef0c44dcb495f
                                                                                                                                                                                                              • Instruction ID: 4a90d42957cceec8548b574d3bb3932fad0b030ca8775eafb0b23170ec33e13e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: e36458edd2254e28eaa8631afe286072e5f7bd0a67a5b6a46e6ef0c44dcb495f
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 904181A6F4990186EF288B1EC4D12B927E1FFC8B88F895035CA4E433B1DE2DD549C702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: division by zero
                                                                                                                                                                                                              • API String ID: 1450464846-3764743415
                                                                                                                                                                                                              • Opcode ID: 1f310e5c3776cb982e72da88537671f8547cf76eb46f26856b816b508ecd4924
                                                                                                                                                                                                              • Instruction ID: d8937c4db9e10bf5656a4e6b1029b606e0fbd12599e0ab06a22117600df9d75d
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 1f310e5c3776cb982e72da88537671f8547cf76eb46f26856b816b508ecd4924
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 0921DB72BC8E0646EB558B2DDA9027452D29F55BE4F1C8330DA6E073F5EF2CE4948702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$AttrObject_PackTuple_
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 4195104747-217463007
                                                                                                                                                                                                              • Opcode ID: 4b12f555bacad9522f59093536ead85a57240267a6d3aa3ff40fce1b0501a7e8
                                                                                                                                                                                                              • Instruction ID: b47b006d0ab1bb0855fdb0f9d32ac63106cb5e45163d789cdb4b86e0b453ba17
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 4b12f555bacad9522f59093536ead85a57240267a6d3aa3ff40fce1b0501a7e8
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 0031DF75A88B4781FA059B19F8902B433E6BF49B89F44543AD9CE4B7B4DF3CE0958342
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$AttrObject_PackTuple_
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 4195104747-217463007
                                                                                                                                                                                                              • Opcode ID: 1860a7d5ba5a0637c41751a3ce46a500ea5aac3d17db15aaa5db88cbc2a32e66
                                                                                                                                                                                                              • Instruction ID: 609f7fca63985fb666bdf9e0d840c36fae0113b2d27bbdff075307c6447450e9
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 1860a7d5ba5a0637c41751a3ce46a500ea5aac3d17db15aaa5db88cbc2a32e66
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 5531C276E98B4681FA108B09F9802B433E6BF18B99F444536D98D8B770EF3CB158C342
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$AttrObject_PackTuple_
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 4195104747-217463007
                                                                                                                                                                                                              • Opcode ID: 3f2332356931184e6501015defa88c1d245f7b25bfe9b71bbf2c72ea6a00fa8a
                                                                                                                                                                                                              • Instruction ID: 8915c6d65b9b586a7649b852174c5a70f3fe77b79397df936d56a9ae8ce04794
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 3f2332356931184e6501015defa88c1d245f7b25bfe9b71bbf2c72ea6a00fa8a
                                                                                                                                                                                                              • Instruction Fuzzy Hash: A731CC75A89B4781FB519B09E9902B433E6BF18B99F445436C88E4B7B0DF3CA564C382
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$AttrObject_PackTuple_
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 4195104747-217463007
                                                                                                                                                                                                              • Opcode ID: 75194c0cbc9a507f0b92e1b34c94570ff1e2da8f97792c352aaccb42d87fe693
                                                                                                                                                                                                              • Instruction ID: 9638ce8b0074c10c59ecff891538cf98b6a2e530b346cbdf9fcd404aacbe8668
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 75194c0cbc9a507f0b92e1b34c94570ff1e2da8f97792c352aaccb42d87fe693
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 1621E379E9AB1781FA419F09B9902B433E6BF04B89F484435D88D0B3B0DF3CA9558382
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$AttrObject_PackTuple_
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 4195104747-217463007
                                                                                                                                                                                                              • Opcode ID: faebbaeb77ca0f4f516b262e93004c19f89b7d84595a6b1439bf542028db819b
                                                                                                                                                                                                              • Instruction ID: ae20fc7c93dc885842c7494d8ecd76e9f4d45153030bc9951895f067b1e5ccdc
                                                                                                                                                                                                              • Opcode Fuzzy Hash: faebbaeb77ca0f4f516b262e93004c19f89b7d84595a6b1439bf542028db819b
                                                                                                                                                                                                              • Instruction Fuzzy Hash: BA21E075E89B4785FB419F09B9902B433E6BF05B99F445436C88E4B7B0EF3CA5588382
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$AttrObject_PackTuple_
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 4195104747-217463007
                                                                                                                                                                                                              • Opcode ID: ee343125aa57c54faf244a34e48bc46db9da3b9588f8e1c1ef8b5bbee5cf8946
                                                                                                                                                                                                              • Instruction ID: 1333326b1086bbe9651b1fafbd890a4591beccb73efde3fc0aec24fa628df038
                                                                                                                                                                                                              • Opcode Fuzzy Hash: ee343125aa57c54faf244a34e48bc46db9da3b9588f8e1c1ef8b5bbee5cf8946
                                                                                                                                                                                                              • Instruction Fuzzy Hash: EC21EF75E99B4381FA459F0CF9802B423E6BF05B9AF484536D98D0B770DF3CA5688342
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$AttrObject_PackTuple_
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 4195104747-217463007
                                                                                                                                                                                                              • Opcode ID: e4eff726a2b882ab3716e79be69498aa5b1f0e510f484dcc5ac300c35e7575a4
                                                                                                                                                                                                              • Instruction ID: 9403d63954e5da149906b0396a007379f8d445454934bbbd2a14096a799cb2c1
                                                                                                                                                                                                              • Opcode Fuzzy Hash: e4eff726a2b882ab3716e79be69498aa5b1f0e510f484dcc5ac300c35e7575a4
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 2B21E0B5E89B4781FA059F18A9902B422E6BF05B99F445435D88D0B7B0DF3CA964C382
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$AttrObject_PackTuple_
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 4195104747-217463007
                                                                                                                                                                                                              • Opcode ID: a16e5229b7237972c2ee806c9dd78c651fb2e9dfacde5010816b5e6c7d31e686
                                                                                                                                                                                                              • Instruction ID: c8bd097317b0282ab6ca19d3b441aa66892ba471be89325c9d001b9d10cf93a3
                                                                                                                                                                                                              • Opcode Fuzzy Hash: a16e5229b7237972c2ee806c9dd78c651fb2e9dfacde5010816b5e6c7d31e686
                                                                                                                                                                                                              • Instruction Fuzzy Hash: EC21E275E99B0785FA449F18B9902B433E6BF05B89F444435D88D0B3B0DF3CA964D382
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$AttrObject_PackTuple_
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 4195104747-217463007
                                                                                                                                                                                                              • Opcode ID: ecdd50443da1972dac5f7d239e36a52e9dfd88a895bebb8cd24304ee5dc28952
                                                                                                                                                                                                              • Instruction ID: fc81c525de3c48a6b0a87398ff1afb78668862da6c30021e46165d624355a57d
                                                                                                                                                                                                              • Opcode Fuzzy Hash: ecdd50443da1972dac5f7d239e36a52e9dfd88a895bebb8cd24304ee5dc28952
                                                                                                                                                                                                              • Instruction Fuzzy Hash: EE21EEB1E89B0781FB449B09B9842B423E6BF04B99F445435C9AD4B3B0DF3DA1688342
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocDict_ItemPackTuple_
                                                                                                                                                                                                              • String ID: <module>$>
                                                                                                                                                                                                              • API String ID: 4228545439-4024159097
                                                                                                                                                                                                              • Opcode ID: 4e122b1be13b90b9fde975fa5c7cafe2c707fcb1664262955b8b1ef10f53763c
                                                                                                                                                                                                              • Instruction ID: f5b6d2d2c2aba726447fa313bc605699fd56727fc177f258300b99220caa95c6
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 4e122b1be13b90b9fde975fa5c7cafe2c707fcb1664262955b8b1ef10f53763c
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 3501E1A6A89A0785F7155B1DE8402B922E3AF44B99F544035C98E0B3B0DF3DE8858353
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: memcpy
                                                                                                                                                                                                              • String ID: STACK: Reallocating with no previous alloc$STACK: Stack after current is in use$STACK: Stack after current is not last$unable to alloc %u bytes
                                                                                                                                                                                                              • API String ID: 3510742995-1271171791
                                                                                                                                                                                                              • Opcode ID: 2ab768410fb25aaf9b8e46463214e0eae883f0cbbc21d409138b9cedc43f5e10
                                                                                                                                                                                                              • Instruction ID: d94779bd9fe33f7cd633d1fa9c33704b6d8535ca19544030a1a1b69bf79b4ab6
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 2ab768410fb25aaf9b8e46463214e0eae883f0cbbc21d409138b9cedc43f5e10
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 83A1AD72B15B4996EF59CF25E8647A863A4FB48B88F484035DE6D47798EF3CE4A1C300
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • memcpy.VCRUNTIME140 ref: 00007FFDFAC9B3CF
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FF60: TlsAlloc.KERNEL32(?,?,?,00007FFDFAD11924), ref: 00007FFDFAD9FF7A
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FF60: TlsGetValue.KERNEL32(?,?,?,00007FFDFAD11924), ref: 00007FFDFAD9FFA8
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FF60: GetLastError.KERNEL32(?,?,?,00007FFDFAD11924), ref: 00007FFDFAD9FFB6
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FF60: GetProcessHeap.KERNEL32(?,?,?,00007FFDFAD11924), ref: 00007FFDFAD9FFF9
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FF60: HeapFree.KERNEL32(?,?,?,00007FFDFAD11924), ref: 00007FFDFADA0007
                                                                                                                                                                                                              • LeaveCriticalSection.KERNEL32 ref: 00007FFDFAC9B440
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Heap$AllocCriticalErrorFreeLastLeaveProcessSectionValuememcpy
                                                                                                                                                                                                              • String ID: UpdateStringProc for type '%s' failed to create a valid string rep$UpdateStringProc should not be invoked for type %s$unable to realloc %u bytes
                                                                                                                                                                                                              • API String ID: 2887402581-56601162
                                                                                                                                                                                                              • Opcode ID: 21c63a5281dad78342bc5207c6073d6e3820d621e9715c0dfacb0655ec5b7e9d
                                                                                                                                                                                                              • Instruction ID: b4c2049b90ad1467ac1c16934a850571b204a3aa96a840abba0bcab70f4f76ca
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 21c63a5281dad78342bc5207c6073d6e3820d621e9715c0dfacb0655ec5b7e9d
                                                                                                                                                                                                              • Instruction Fuzzy Hash: EB515E26B0864A96EB1CDF65E86097D27A0FF48B88B084475CE2D477DCEE3CE891D340
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocFromLong_Ssize_t$BoolCompareObject_Rich
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 4107546884-0
                                                                                                                                                                                                              • Opcode ID: 48720d78ba32745252a3d04257a9edec78878515a75e68daf766dae4164bca8c
                                                                                                                                                                                                              • Instruction ID: 430a5a75c10c684fcf044554ebef3920b30172dab854b7525c797f1b2cc3cf36
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 48720d78ba32745252a3d04257a9edec78878515a75e68daf766dae4164bca8c
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 6C214232B8864B46E7654B1D9A9437822D1EF45BB1F484730DA6E477F4DF2CE451C702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3617616757-0
                                                                                                                                                                                                              • Opcode ID: 02352599f705a3241e88950aa0469c59beaf4792bcb6d3889a9a60b667567bda
                                                                                                                                                                                                              • Instruction ID: d3e68ebc2871c2a854357c2e18cb06334a6ba576007afecb32c0c3b316f57c91
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 02352599f705a3241e88950aa0469c59beaf4792bcb6d3889a9a60b667567bda
                                                                                                                                                                                                              • Instruction Fuzzy Hash: BA31B776AC9A4286EB654F3C969837832E4EF44B7EF145374CA7A411E1CF7E9485C302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Object_State_ThreadTrackTrash_beginTrash_condTrash_endUnchecked
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3074927763-0
                                                                                                                                                                                                              • Opcode ID: 827b1114b3bde6b7782323d29114232b68231d63ae6a03841d0d76945457bef3
                                                                                                                                                                                                              • Instruction ID: 9ffa2ecf46ee8017508ff83b7b8de709b1abdfbaf2a780feabf65ee860bba0cd
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 827b1114b3bde6b7782323d29114232b68231d63ae6a03841d0d76945457bef3
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 30F03065B4864381EB445F6AB99413963A2BF49FDAB489034CD5E47B34DE2CD495C302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: __init__$charset_normalizer.md.SuperWeirdWordPlugin$interpreted classes cannot inherit from compiled
                                                                                                                                                                                                              • API String ID: 1450464846-371468285
                                                                                                                                                                                                              • Opcode ID: 98918f0986896f26525c7bd9e5b43f4031bd6749c4d76523467727f76d4c2467
                                                                                                                                                                                                              • Instruction ID: 5358dd102b9d1faf11eb4aa4c9900b0f3eb50c5d5e08720669f7d2b1cd5fafe9
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 98918f0986896f26525c7bd9e5b43f4031bd6749c4d76523467727f76d4c2467
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 6141E272A48A4282E7148F29E88036933E5FF48B88F544135DA8C87779EF79E495C342
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: __init__$charset_normalizer.md.ArchaicUpperLowerPlugin$interpreted classes cannot inherit from compiled
                                                                                                                                                                                                              • API String ID: 1450464846-353558827
                                                                                                                                                                                                              • Opcode ID: d9e477cc0f5dbe889ee029430d6b8f0b420a3cfa5d140793ed0a56d7501aa99d
                                                                                                                                                                                                              • Instruction ID: d0b16d0d7454e3a2812bae5051a6eeb61e3f4e3c6edc5c803d363520f412b34e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: d9e477cc0f5dbe889ee029430d6b8f0b420a3cfa5d140793ed0a56d7501aa99d
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 7B314872A48A4286E7508F2DE8803A933E5FF48B8CF540536CA8C47369EF7DE494C741
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: __init__$charset_normalizer.md.TooManySymbolOrPunctuationPlugin$interpreted classes cannot inherit from compiled
                                                                                                                                                                                                              • API String ID: 1450464846-3280324660
                                                                                                                                                                                                              • Opcode ID: a1ddc10de017addce63480acb8cb0cb49846706b3ca5f678430c59beec134696
                                                                                                                                                                                                              • Instruction ID: 6396526e1ded9578ec4b6ee0e07f8f2da611fa1738d9583cd0a7241b9340c795
                                                                                                                                                                                                              • Opcode Fuzzy Hash: a1ddc10de017addce63480acb8cb0cb49846706b3ca5f678430c59beec134696
                                                                                                                                                                                                              • Instruction Fuzzy Hash: AC313672A49A4285EB408F2DE8903A963E5FF48B8CF544435DA8C47378DF3DE494C341
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: __init__$charset_normalizer.md.SuspiciousRange$interpreted classes cannot inherit from compiled
                                                                                                                                                                                                              • API String ID: 1450464846-880397153
                                                                                                                                                                                                              • Opcode ID: 49407b564c236b4001e082ae6d16e11313c9b7c79a02ae8e4e4803c904df55db
                                                                                                                                                                                                              • Instruction ID: d137ab5f6f654c229bf52e949cd4695a878cddda36c2fb9086c4d7ecfc09f014
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 49407b564c236b4001e082ae6d16e11313c9b7c79a02ae8e4e4803c904df55db
                                                                                                                                                                                                              • Instruction Fuzzy Hash: EE312972A49A4285EB40CF1DE88026963F1FF48B88F944531DA8C8B778DF3DE555C341
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: __init__$charset_normalizer.md.SuspiciousDuplicateAccentPlugin$interpreted classes cannot inherit from compiled
                                                                                                                                                                                                              • API String ID: 1450464846-1506521901
                                                                                                                                                                                                              • Opcode ID: c9011ee015d9b478a68b666d2386e0bc45b2be7c5bf24e43dd3277610430b050
                                                                                                                                                                                                              • Instruction ID: ea81a30810ffb3f26739c672418fcd1c984f7223c2721567ea288817cd6551d8
                                                                                                                                                                                                              • Opcode Fuzzy Hash: c9011ee015d9b478a68b666d2386e0bc45b2be7c5bf24e43dd3277610430b050
                                                                                                                                                                                                              • Instruction Fuzzy Hash: A8314E71B58A4286EB54CF1DE4402A963E1FF88B88F944431DA8C47774DF3DE555C742
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: __init__$charset_normalizer.md.CjkInvalidStopPlugin$interpreted classes cannot inherit from compiled
                                                                                                                                                                                                              • API String ID: 1450464846-2610960353
                                                                                                                                                                                                              • Opcode ID: 76a7a677629842859978aaa54d4c908ac2703a6c097ce1729baa8608753adc48
                                                                                                                                                                                                              • Instruction ID: b2b298d9edbb0be0091547cf4f8ae76bfd3a06d8bed4f179d55b3a61c8b28114
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 76a7a677629842859978aaa54d4c908ac2703a6c097ce1729baa8608753adc48
                                                                                                                                                                                                              • Instruction Fuzzy Hash: E4312A72B48A4285EB50DF2DE8402A963E2FF48B88F544432DA9C87778EF3DE555C742
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: __init__$charset_normalizer.md.UnprintablePlugin$interpreted classes cannot inherit from compiled
                                                                                                                                                                                                              • API String ID: 1450464846-116036081
                                                                                                                                                                                                              • Opcode ID: 571f9f9e96768ffb2ac53c4efc93ddbf52cbfab833ec0306282c52c0bf4d27d3
                                                                                                                                                                                                              • Instruction ID: 1d4c7742de9f8c255937e8d7e6a0480442ea268678d86dcaba6d9e83abaa1879
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 571f9f9e96768ffb2ac53c4efc93ddbf52cbfab833ec0306282c52c0bf4d27d3
                                                                                                                                                                                                              • Instruction Fuzzy Hash: E3312B71B48A4281EB408B1EE8802A963E2FF48B8CF544531CA8C47774EF7DE595C341
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: __init__$charset_normalizer.md.ArabicIsolatedFormPlugin$interpreted classes cannot inherit from compiled
                                                                                                                                                                                                              • API String ID: 1450464846-1141011871
                                                                                                                                                                                                              • Opcode ID: b59ea239b0ded2da1d7d86f123c67e001364e70b8c495ebd1fe9a254676c74a7
                                                                                                                                                                                                              • Instruction ID: 3c8cb17bd72f243ecf6d210a6a46d3d135bbd2f3faa303128d2bbfd291e2f16c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: b59ea239b0ded2da1d7d86f123c67e001364e70b8c495ebd1fe9a254676c74a7
                                                                                                                                                                                                              • Instruction Fuzzy Hash: EA312B72B49B4281EB408F2DE8402A963E2FF48B88F544432DA8C877B4EF3DE555C741
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: __init__$charset_normalizer.md.TooManyAccentuatedPlugin$interpreted classes cannot inherit from compiled
                                                                                                                                                                                                              • API String ID: 1450464846-2999409259
                                                                                                                                                                                                              • Opcode ID: 46a8908cafe4df30933cc1bf2f0944172b9d1b0b9ac90932bbe1890628880787
                                                                                                                                                                                                              • Instruction ID: cc9826acef74867baa5a2e590525ffa4148ac3d0107f8078c898ecec1588d95c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 46a8908cafe4df30933cc1bf2f0944172b9d1b0b9ac90932bbe1890628880787
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 70312972B49A4285EB508F2DE8402A963E2FF48B8CF944532DA8C87778EF3DE555C741
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: SubtypeType_
                                                                                                                                                                                                              • String ID: charset_normalizer.md.MessDetectorPlugin$eligible$str
                                                                                                                                                                                                              • API String ID: 2891779845-1291782451
                                                                                                                                                                                                              • Opcode ID: 7f0862f8ed2a2bf7f8ea4440bfcb9bd23f6d9e60511077b2f04859b75fbf1be2
                                                                                                                                                                                                              • Instruction ID: 298778391c00b2364a48e9d0c52620bc7a0835d987b8946b097079bc5ee268c0
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 7f0862f8ed2a2bf7f8ea4440bfcb9bd23f6d9e60511077b2f04859b75fbf1be2
                                                                                                                                                                                                              • Instruction Fuzzy Hash: C411BEA1B8864682FB049B1DD9D12F523E2BF45BC4F888032DD8D4B3B0DE6CEA54C302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocErr_String
                                                                                                                                                                                                              • String ID: 'SuspiciousRange' object attribute '_last_printable_seen' cannot be deleted$str or None
                                                                                                                                                                                                              • API String ID: 1259552197-1971554219
                                                                                                                                                                                                              • Opcode ID: a918d477a285616c2c2e4df8314c3c17314b771cecf0fb593c970a7c657b72bd
                                                                                                                                                                                                              • Instruction ID: 5e061ad4ce23d4de178398a30414e5cc694bf05c87105444b05b3e91f865111a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: a918d477a285616c2c2e4df8314c3c17314b771cecf0fb593c970a7c657b72bd
                                                                                                                                                                                                              • Instruction Fuzzy Hash: B0119372B48A4682EF58CB1DE59027823E1FF48F98F488131EA4D877B4DE3CE4948702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocErr_String
                                                                                                                                                                                                              • String ID: 'SuspiciousDuplicateAccentPlugin' object attribute '_last_latin_character' cannot be deleted$str or None
                                                                                                                                                                                                              • API String ID: 1259552197-4111674009
                                                                                                                                                                                                              • Opcode ID: 45422d08dff3ba37862566774811d1c873494940e91693ae83718888786eb3b7
                                                                                                                                                                                                              • Instruction ID: db69a9c8c6bcf6be9c174f053e92dad8913dd9f7d0ada13695e970d0578af19c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 45422d08dff3ba37862566774811d1c873494940e91693ae83718888786eb3b7
                                                                                                                                                                                                              • Instruction Fuzzy Hash: A2118E72B48A0686EF548B1DE59027833E1EF48B98F588131EA4D877B5DE2CE4948701
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocErr_String
                                                                                                                                                                                                              • String ID: 'ArchaicUpperLowerPlugin' object attribute '_last_alpha_seen' cannot be deleted$str or None
                                                                                                                                                                                                              • API String ID: 1259552197-1607602726
                                                                                                                                                                                                              • Opcode ID: 2eb1423d3a8d026875b47d3e487d8fbdb754b2b35a34fb420c45883b89527626
                                                                                                                                                                                                              • Instruction ID: 4562de32fe1940eadacfc4feded96783ffa56510be96ddcfca679a0ccac7b547
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 2eb1423d3a8d026875b47d3e487d8fbdb754b2b35a34fb420c45883b89527626
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 29116A72B48A0682EB558B1DE59027923E1EF48B98F888131DA5D47BF4DE2CE4848701
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocErr_String
                                                                                                                                                                                                              • String ID: 'TooManySymbolOrPunctuationPlugin' object attribute '_last_printable_char' cannot be deleted$str or None
                                                                                                                                                                                                              • API String ID: 1259552197-2331204894
                                                                                                                                                                                                              • Opcode ID: 4a2e56e4c18d021721d1ff58624d4138fa5cae7aafe6a9259ab8a3639d0b6b2d
                                                                                                                                                                                                              • Instruction ID: 19773c38f25dea3e58d33accb3bebb47383da02e8af51d8fe2e586a0258c5072
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 4a2e56e4c18d021721d1ff58624d4138fa5cae7aafe6a9259ab8a3639d0b6b2d
                                                                                                                                                                                                              • Instruction Fuzzy Hash: B2118E72B48A0686EF448B1DE69027823E2FF88B98F988131DA5D4B7B4DE3CE4548701
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: SubtypeType_
                                                                                                                                                                                                              • String ID: charset_normalizer.md.MessDetectorPlugin$feed$str
                                                                                                                                                                                                              • API String ID: 2891779845-1310269896
                                                                                                                                                                                                              • Opcode ID: 174ffd5a8d4fbd5a7ace33c46627c3910e0e1c50ab3d8efb39f58c9a0e45e4fb
                                                                                                                                                                                                              • Instruction ID: f55647ec386be3eb02ddcb6b16df094c15bb7e122519b202a76e7d8ab6e6f8a8
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 174ffd5a8d4fbd5a7ace33c46627c3910e0e1c50ab3d8efb39f58c9a0e45e4fb
                                                                                                                                                                                                              • Instruction Fuzzy Hash: F4116DA1B8860682EB549B1EE6811F963E2BF85BC4F884035DD9D4B3B4DF6CE955C302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocErr_String
                                                                                                                                                                                                              • String ID: 'SuperWeirdWordPlugin' object attribute '_buffer' cannot be deleted$str
                                                                                                                                                                                                              • API String ID: 1259552197-1393815803
                                                                                                                                                                                                              • Opcode ID: e3b12353829d0deeeabf54bb8e44c1ef7eec8a574ceacd3afffb07c93fd7f85b
                                                                                                                                                                                                              • Instruction ID: 277f5202ba517990f3284029ca4a2363103dd5d1dbecb95c10801d5d3ae036b7
                                                                                                                                                                                                              • Opcode Fuzzy Hash: e3b12353829d0deeeabf54bb8e44c1ef7eec8a574ceacd3afffb07c93fd7f85b
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 85119A72B4854286EB54CF2DE6C026833E1FF48B88F589032DB1D876A4DE2CD494CB02
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocErr_FormatMethodObject_Vectorcall
                                                                                                                                                                                                              • String ID: bool$eligible
                                                                                                                                                                                                              • API String ID: 2503426208-3320767611
                                                                                                                                                                                                              • Opcode ID: 45e89110cdaede4183728df16b150787876237ae891cae742361569b5cc7dc65
                                                                                                                                                                                                              • Instruction ID: 94b10de4df9973d7c1125813c06c7f827daff1d59c91e4663ca5a70012db7656
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 45e89110cdaede4183728df16b150787876237ae891cae742361569b5cc7dc65
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 76115261F89A4281EB608B1DF9C17B923E1EF44B88F585036E99D0A6B5DE6CE584C702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocErr_FormatMethodObject_Vectorcall
                                                                                                                                                                                                              • String ID: bool$eligible
                                                                                                                                                                                                              • API String ID: 2503426208-3320767611
                                                                                                                                                                                                              • Opcode ID: c5b4b4656a59a8e67beff081790a41d695e4145e237a7eb8b31be5e0c87158af
                                                                                                                                                                                                              • Instruction ID: 5e9f0b570661e7158c2f3fd2850c48903d47e9599bf392e85e2ec84d7077edee
                                                                                                                                                                                                              • Opcode Fuzzy Hash: c5b4b4656a59a8e67beff081790a41d695e4145e237a7eb8b31be5e0c87158af
                                                                                                                                                                                                              • Instruction Fuzzy Hash: E6116571F88A4281EB508B19F9C13B523E1FF44B88F585036D98D0B6F5DE6CE584D712
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocErr_FormatMethodObject_Vectorcall
                                                                                                                                                                                                              • String ID: bool$eligible
                                                                                                                                                                                                              • API String ID: 2503426208-3320767611
                                                                                                                                                                                                              • Opcode ID: 6ffd60cce85a421e8434590f2d4fc69a980ada6fd10450d1b70e0e88f2682bec
                                                                                                                                                                                                              • Instruction ID: fd8d216ccdf34e988718df27b9b79755accec9ce437710918a5a28d5573d862b
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 6ffd60cce85a421e8434590f2d4fc69a980ada6fd10450d1b70e0e88f2682bec
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 26115265F88A4382FB508F19F9C17B523E2EF44B88F585035D98D0B6B5DE2CD485C702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocDict_ItemPackTuple_
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 4228545439-217463007
                                                                                                                                                                                                              • Opcode ID: 032ea81c99ec7a83fc9ed446e6799de4a32a2fdf75c6d93fa13489cf3ba9ce95
                                                                                                                                                                                                              • Instruction ID: 2410e6c33b2ffea7e794b549b64567a9d9c12ce9007b6fbcd324377f6c0e01bf
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 032ea81c99ec7a83fc9ed446e6799de4a32a2fdf75c6d93fa13489cf3ba9ce95
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 110128A6E89B4381FB155F1DE84027822E3AF40BAAF445035C98E0B3B4DE7DE9858343
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocDict_ItemPackTuple_
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 4228545439-217463007
                                                                                                                                                                                                              • Opcode ID: 3307c57545eb4b4e003a50abc7e3a22bbca76da34ce5ed7b4551bd04aed3351c
                                                                                                                                                                                                              • Instruction ID: 3288d1ccda1e79605a01b92c916eb1a4161561621ae9ab0973f67463fe9f6750
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 3307c57545eb4b4e003a50abc7e3a22bbca76da34ce5ed7b4551bd04aed3351c
                                                                                                                                                                                                              • Instruction Fuzzy Hash: E7012CB2E89A0281F7155B1DE94027822E3AF00B9DF544035CA8E0B3B0DF3DE489C303
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocDict_ItemPackTuple_
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 4228545439-217463007
                                                                                                                                                                                                              • Opcode ID: 61c017c81d5e6fa3815ca9fce73e5b847532078dee348fb6f530cef8c5aad8c5
                                                                                                                                                                                                              • Instruction ID: 7dd3a02ca550a5a7241daf82305008ccfdb1605d0f300cfa688c08144fe4b15c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 61c017c81d5e6fa3815ca9fce73e5b847532078dee348fb6f530cef8c5aad8c5
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 08014FA6E89A4281F7155B1DE84037822E3AF00B9DF444035C98E0B3B4DF3DE985D343
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocDict_ItemPackTuple_
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 4228545439-217463007
                                                                                                                                                                                                              • Opcode ID: 70a5f35237a7bac29e318148100934e2ec0d39acdf239b2d5f662bd422f8af1b
                                                                                                                                                                                                              • Instruction ID: 39e5fd88f1b7ecffc305dd8c766b7d3333abd2e8e15fcef9b0d37dc419f020eb
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 70a5f35237a7bac29e318148100934e2ec0d39acdf239b2d5f662bd422f8af1b
                                                                                                                                                                                                              • Instruction Fuzzy Hash: DF0128A3E89A0292F7155B5CE84427822F3AF10B9AF444035CA8E4B3B0DF3DE5898303
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocDict_ItemPackTuple_
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 4228545439-217463007
                                                                                                                                                                                                              • Opcode ID: 5d81bad33af6d0c6a6d34ccc316adc70e06c6ff90d8471e672fe39720f4c7cf5
                                                                                                                                                                                                              • Instruction ID: cdf317a8a4dd3964a6d44b59258a76fe61fa2da35727c98d114e65cc038693fe
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 5d81bad33af6d0c6a6d34ccc316adc70e06c6ff90d8471e672fe39720f4c7cf5
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 4F01ECA6E89A0681F7155B1DE84027862E3BF54B99F544036C98E4B3B5DE3DE8C58343
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocDict_ItemPackTuple_
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 4228545439-217463007
                                                                                                                                                                                                              • Opcode ID: 097e68ef3b6926ae97075bdf610a732ab01175073ea4774d168167745da7d900
                                                                                                                                                                                                              • Instruction ID: 0ebdad72aba4db469070b9d3531e068be176487e7c034a14efb5595b871f3721
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 097e68ef3b6926ae97075bdf610a732ab01175073ea4774d168167745da7d900
                                                                                                                                                                                                              • Instruction Fuzzy Hash: D4014BB6E89A0281F7115B1CE84027C22F3AF40B99F444035C98E0B3B1DE3DF8858783
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocDict_ItemPackTuple_
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 4228545439-217463007
                                                                                                                                                                                                              • Opcode ID: 24728f44ecafede275bfe5869a5481c6ada5958cbf93234a040fc8aef190d785
                                                                                                                                                                                                              • Instruction ID: bdb969aaa2b0666dd7df83fdae102b4a9ff759154d0c5fedd026e5d4feb6e45d
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 24728f44ecafede275bfe5869a5481c6ada5958cbf93234a040fc8aef190d785
                                                                                                                                                                                                              • Instruction Fuzzy Hash: FB012CA6A89A0381F7159F1DE84037822E3AF40B9DF544035C98E0B3B0DE7DE8858343
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$Object_Vectorcall
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 1057673266-217463007
                                                                                                                                                                                                              • Opcode ID: d65abae93356dae59a4a840aaf2a40b004717b6640a575e0a43327181c576cc2
                                                                                                                                                                                                              • Instruction ID: 17ed0dd0473a8de21618455eb3b2e6ed126b10fa142c8acf04bc03fd3b84c0a2
                                                                                                                                                                                                              • Opcode Fuzzy Hash: d65abae93356dae59a4a840aaf2a40b004717b6640a575e0a43327181c576cc2
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 85F0D172F8965242E7615F08E9407B862E2AF40FE9F408031CE890BA70DE2C91898702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Object_$DeallocErr_$ArgsAttrCallInstanceObjectOccurred
                                                                                                                                                                                                              • String ID: ratio
                                                                                                                                                                                                              • API String ID: 1598006454-4234197119
                                                                                                                                                                                                              • Opcode ID: 35d559fc8b1310c0c6a435b23598347e2ea6a62b98f84bba43c18296abc6ca69
                                                                                                                                                                                                              • Instruction ID: e03b6326f15af38206050c4e958e57e778bba98ef3c375f9713b8e6d6b1e084b
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 35d559fc8b1310c0c6a435b23598347e2ea6a62b98f84bba43c18296abc6ca69
                                                                                                                                                                                                              • Instruction Fuzzy Hash: F8013C61F89A0781FB196F6DE9942B923E2AF48B99F085031C94D563B0DE3CE1848303
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_Format
                                                                                                                                                                                                              • String ID: %s object expected; and errored formatting real type!$%s object expected; got %U
                                                                                                                                                                                                              • API String ID: 376477240-2630277986
                                                                                                                                                                                                              • Opcode ID: 45f3feeb58d62d7b61bd12d7106d8e4dcb9e7cfdec48858d2051b2ab1d508661
                                                                                                                                                                                                              • Instruction ID: 9c1c23c636b38f9d048ee3802ef90cff3401f0842cf0c6decd3c860b89649ca4
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 45f3feeb58d62d7b61bd12d7106d8e4dcb9e7cfdec48858d2051b2ab1d508661
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 8CF04FA2F48A42C1EA054B1EFA801B863E2FF48BC9F549031DA4D076B5DE6DD5448701
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocDict_ItemPackTuple_
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 4228545439-217463007
                                                                                                                                                                                                              • Opcode ID: 6d3c8ef61b1ce4c915580a507c35e2098bc8d2d339069acd415264474d36893f
                                                                                                                                                                                                              • Instruction ID: 19df259589ab32a2a5ca1026cda90a785ac27a78fdf091846c89cffc1ee8846e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 6d3c8ef61b1ce4c915580a507c35e2098bc8d2d339069acd415264474d36893f
                                                                                                                                                                                                              • Instruction Fuzzy Hash: CBF0D066F89A1781F7155F1DA8842B922E36F1479EF404035CACD0B7B1DE7DA5898343
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: TlsAlloc.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE21
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: TlsGetValue.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE4F
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: GetLastError.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE5D
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: GetProcessHeap.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FE9B
                                                                                                                                                                                                                • Part of subcall function 00007FFDFAD9FC10: HeapAlloc.KERNEL32(?,?,?,?,?,?,?,00007FFDFADA047E), ref: 00007FFDFAD9FEA9
                                                                                                                                                                                                              • memcpy.VCRUNTIME140(?,00000000,00000000,00007FFDFAD54114,?,?,?,?,?,?,?,?,?,?,?,?), ref: 00007FFDFAD54385
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1827571067.00007FFDFAC81000.00000020.00000001.01000000.00000016.sdmp, Offset: 00007FFDFAC80000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827547533.00007FFDFAC80000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827679175.00007FFDFADE3000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827721571.00007FFDFAE28000.00000004.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1827747211.00007FFDFAE2B000.00000002.00000001.01000000.00000016.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfac80000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: AllocHeap$ErrorLastProcessValuememcpy
                                                                                                                                                                                                              • String ID: max size of Tcl literal array (%d literals) exceeded$unable to alloc %u bytes$unable to realloc %u bytes
                                                                                                                                                                                                              • API String ID: 1456920652-186258196
                                                                                                                                                                                                              • Opcode ID: 2292cc9fc3754e218cf5995ef7e035cb5776f7ae8047fcc707dbf382b4f0bf91
                                                                                                                                                                                                              • Instruction ID: d61fbbbc75a30e9f1d3df8fd049611fbc37b27d44e5be0a3ed0ec7353a4205e1
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 2292cc9fc3754e218cf5995ef7e035cb5776f7ae8047fcc707dbf382b4f0bf91
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 9531A872F196418AFB188F15E82177922A2EF94BA4F184675DA3D077EDFF7CE4428201
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc$BoolCompareObject_Rich
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 74976934-0
                                                                                                                                                                                                              • Opcode ID: 06e8f97dbb0ea0e89ed53f8803494b3fcf86a5d1c840b79286c23275ed2a61a7
                                                                                                                                                                                                              • Instruction ID: a6d9ffda4ed4603947a2694923d4ab3c1326499bbd3a7b3d4423369cade27bb8
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 06e8f97dbb0ea0e89ed53f8803494b3fcf86a5d1c840b79286c23275ed2a61a7
                                                                                                                                                                                                              • Instruction Fuzzy Hash: D0117232F9860286EB548B2DE6843B823D1EF55BB5F085330DA7A567F5DF2CD8518702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Dealloc
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 3617616757-0
                                                                                                                                                                                                              • Opcode ID: ece71df874b8b5f5a56a715ca088fb7d08a9acaf02b1d109a510bd9dd73bf957
                                                                                                                                                                                                              • Instruction ID: 40e46de20cb7a5c826c3954cae53b3cfd131af809981615989d6369281a7a90a
                                                                                                                                                                                                              • Opcode Fuzzy Hash: ece71df874b8b5f5a56a715ca088fb7d08a9acaf02b1d109a510bd9dd73bf957
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 8821C976E4960281EB65DF38D6A83782AE0EF55B3EF240330CA6A411F0CF7D9485C752
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1829277621.00007FFDFB421000.00000020.00000001.01000000.00000004.sdmp, Offset: 00007FFDFB420000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1829248560.00007FFDFB420000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1829460779.00007FFDFB6A0000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1829460779.00007FFDFB6C0000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1829460779.00007FFDFB6CF000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1829460779.00007FFDFB745000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1829460779.00007FFDFB810000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1829750142.00007FFDFB914000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1829801816.00007FFDFB981000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1829830623.00007FFDFB983000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1829855316.00007FFDFB984000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1829880511.00007FFDFB985000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1829905893.00007FFDFB987000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1829940629.00007FFDFB9A3000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1829992759.00007FFDFBA06000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830024444.00007FFDFBA09000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830058674.00007FFDFBA0A000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830092596.00007FFDFBA0D000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830125405.00007FFDFBA0F000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830159508.00007FFDFBA19000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830197784.00007FFDFBA3E000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830227686.00007FFDFBA3F000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830258753.00007FFDFBA40000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830287788.00007FFDFBA41000.00000008.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830318209.00007FFDFBA43000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830356995.00007FFDFBA92000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830356995.00007FFDFBAAD000.00000004.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830418129.00007FFDFBAAE000.00000002.00000001.01000000.00000004.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffdfb420000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2933794660-0
                                                                                                                                                                                                              • Opcode ID: 58ca966b9d884f561f65667e44ce70c8e579152a32341fb5b76eabc5ea06725d
                                                                                                                                                                                                              • Instruction ID: 30841d6f8d84ca07522888bd808f204d241b4cd3814d16a015c5d8747935ff5c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 58ca966b9d884f561f65667e44ce70c8e579152a32341fb5b76eabc5ea06725d
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 77111862B15B078AEF00CB61E8646B933A8FB19758F441A31DA6D8B7A8DF78D1648340
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: CurrentTime$CounterFilePerformanceProcessQuerySystemThread
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 2933794660-0
                                                                                                                                                                                                              • Opcode ID: d9e6e1a99beb20024c39237dbb01f35985b29cf17aeeaa0b650d61652553da3b
                                                                                                                                                                                                              • Instruction ID: 0c465301c6c288524f9cee5dec8bea12146458b0273e51fd0fd68c5a3794f360
                                                                                                                                                                                                              • Opcode Fuzzy Hash: d9e6e1a99beb20024c39237dbb01f35985b29cf17aeeaa0b650d61652553da3b
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 7D113022B54F068AEB00CF64E8582B833A4FB19758F440D35DAAD467B8DF7CD1988381
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Object_$ArgsCallDeallocErr_InstanceObject
                                                                                                                                                                                                              • String ID:
                                                                                                                                                                                                              • API String ID: 469999563-0
                                                                                                                                                                                                              • Opcode ID: 735d7802508a943567c1b886ab3bcdb7dadecb2b687cb30f547209437c5526d2
                                                                                                                                                                                                              • Instruction ID: b589bd39455328954a869a25ae6208286091ac6ec04771a4fc48deef7be4305e
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 735d7802508a943567c1b886ab3bcdb7dadecb2b687cb30f547209437c5526d2
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 08F0FF61F98A0282EA554B2AEA9427963E2AF45FD6F045030CD8E07774DF3CE4948702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Object_Unicode_
                                                                                                                                                                                                              • String ID: gfffffff
                                                                                                                                                                                                              • API String ID: 3285369508-1523873471
                                                                                                                                                                                                              • Opcode ID: 01e85d9c1bd3d17e433c8fb88ec89fd76347e07627257ce4696b6525bbbdcfea
                                                                                                                                                                                                              • Instruction ID: 0486ae529233166559a8447e72b1301dfe26938cfc38216035c1e1d94db17b55
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 01e85d9c1bd3d17e433c8fb88ec89fd76347e07627257ce4696b6525bbbdcfea
                                                                                                                                                                                                              • Instruction Fuzzy Hash: B74135A2B4878583EB018B1AE4613B97BE0EFA1BE0F051130DE8E477A5DE3CE541C742
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              • PyType_IsSubtype.PYTHON312 ref: 00007FFE0CFC93EB
                                                                                                                                                                                                                • Part of subcall function 00007FFE0CFC3800: PyErr_Format.PYTHON312 ref: 00007FFE0CFC3834
                                                                                                                                                                                                                • Part of subcall function 00007FFE0CFC3880: PyThreadState_Get.PYTHON312 ref: 00007FFE0CFC38A2
                                                                                                                                                                                                                • Part of subcall function 00007FFE0CFC3880: PyErr_Fetch.PYTHON312 ref: 00007FFE0CFC38BA
                                                                                                                                                                                                                • Part of subcall function 00007FFE0CFC3880: PyCode_NewEmpty.PYTHON312 ref: 00007FFE0CFC38CD
                                                                                                                                                                                                                • Part of subcall function 00007FFE0CFC3880: PyFrame_New.PYTHON312 ref: 00007FFE0CFC38E7
                                                                                                                                                                                                                • Part of subcall function 00007FFE0CFC3880: _Py_Dealloc.PYTHON312 ref: 00007FFE0CFC3902
                                                                                                                                                                                                                • Part of subcall function 00007FFE0CFC3880: _PyErr_ChainExceptions1.PYTHON312 ref: 00007FFE0CFC390D
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_$ChainCode_DeallocEmptyExceptions1FetchFormatFrame_State_SubtypeThreadType_
                                                                                                                                                                                                              • String ID: charset_normalizer.md.MessDetectorPlugin$reset
                                                                                                                                                                                                              • API String ID: 2783664582-4122180197
                                                                                                                                                                                                              • Opcode ID: 76f6fa13b8723754b9a60dd584603b75876082391e851e7e34e3c089995dae12
                                                                                                                                                                                                              • Instruction ID: f565fbb099eadb66ed096a4a55f7ba67c66d7ccf3c2ca9d22c8f2f28814453ef
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 76f6fa13b8723754b9a60dd584603b75876082391e851e7e34e3c089995dae12
                                                                                                                                                                                                              • Instruction Fuzzy Hash: D7015AA1FC850681FB189B6EA9810B512D6AF44BC4B888036CD5D4B3B1DE6CE695C312
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocImportImport_
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 187899110-217463007
                                                                                                                                                                                                              • Opcode ID: d69bcf240f74489f4bd497fc0b8f2cc414bf2c6a77f5002b559556706f64d9ad
                                                                                                                                                                                                              • Instruction ID: e4f8644271b2699999b3a27e6e053907a83208437ccb99b2c1b4d876b752ef13
                                                                                                                                                                                                              • Opcode Fuzzy Hash: d69bcf240f74489f4bd497fc0b8f2cc414bf2c6a77f5002b559556706f64d9ad
                                                                                                                                                                                                              • Instruction Fuzzy Hash: D7012166F89A1381FB199F0DE88017823E3AF85B99B548035C98D07370DF3DB945D742
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: DeallocDict_Item
                                                                                                                                                                                                              • String ID: <module>
                                                                                                                                                                                                              • API String ID: 1953171116-217463007
                                                                                                                                                                                                              • Opcode ID: d0256b5094a83c2cce43499a17dbe8ec4dca85f9fba9f3344b29a1cf4ce49e16
                                                                                                                                                                                                              • Instruction ID: a6608e2d78c1d9d1625af81f2400d27248561e8e2152a9608104ceb5422a3109
                                                                                                                                                                                                              • Opcode Fuzzy Hash: d0256b5094a83c2cce43499a17dbe8ec4dca85f9fba9f3344b29a1cf4ce49e16
                                                                                                                                                                                                              • Instruction Fuzzy Hash: E40121A2E9EA0781FB029B1DD84027823E2AF40B99F544435CA8D0B3B4DE3DF5498303
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Object_$Dealloc$ArgsAttrCallErr_InstanceObject
                                                                                                                                                                                                              • String ID: reset
                                                                                                                                                                                                              • API String ID: 1069087923-1352515405
                                                                                                                                                                                                              • Opcode ID: bbdd62e7f99f6cbdd23793489bb35b56453e91b9374609213c62ce4e8be85285
                                                                                                                                                                                                              • Instruction ID: 705f921e71b3ae130653b128e52b999a280f34abba9516e5fd6a085ab2cc6d82
                                                                                                                                                                                                              • Opcode Fuzzy Hash: bbdd62e7f99f6cbdd23793489bb35b56453e91b9374609213c62ce4e8be85285
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 82F082A5F8960781FB256F29E8842B413E1AF48B98F185032CC4D0B3F0DE6DE1888703
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'ArchaicUpperLowerPlugin' object attribute '_current_ascii_only' cannot be deleted$bool
                                                                                                                                                                                                              • API String ID: 1450464846-1261582747
                                                                                                                                                                                                              • Opcode ID: 8c7019ae60389a316b38f34d8583e21c126b8065cf809baa2539fb2ca883be19
                                                                                                                                                                                                              • Instruction ID: a316bc864fa717500975e51f7af5beb0f69710d1b76fb0353774de22412f17de
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 8c7019ae60389a316b38f34d8583e21c126b8065cf809baa2539fb2ca883be19
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 2AF082A5F4594291D904972DC9D006427E2BF54BA9FE44232D55C862F0EE1CE49AC302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'TooManySymbolOrPunctuationPlugin' object attribute '_frenzy_symbol_in_word' cannot be deleted$bool
                                                                                                                                                                                                              • API String ID: 1450464846-825057536
                                                                                                                                                                                                              • Opcode ID: 7687b87dcfade708e71cb8af8033597d5e5aa7a4328c8a6f7437823f4d63887e
                                                                                                                                                                                                              • Instruction ID: 124fe82c297b07fa08a0823ddbad62f5d7dd3e6ad530d6a49a1bb49f85de72c3
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 7687b87dcfade708e71cb8af8033597d5e5aa7a4328c8a6f7437823f4d63887e
                                                                                                                                                                                                              • Instruction Fuzzy Hash: A2F082A5F4590791D904972DD9D006423E3BF54B68FE54632D56C863F0EE5CE49AC302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'SuperWeirdWordPlugin' object attribute '_is_current_word_bad' cannot be deleted$bool
                                                                                                                                                                                                              • API String ID: 1450464846-604167972
                                                                                                                                                                                                              • Opcode ID: 6d01e49ecab393e01afea90eacf9c2f202f3be594d726ec8172ccd587fa77b69
                                                                                                                                                                                                              • Instruction ID: 28582257cb3a4556c4f12d844ac60b8a937ba5940bb517069765719c1d633e3c
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 6d01e49ecab393e01afea90eacf9c2f202f3be594d726ec8172ccd587fa77b69
                                                                                                                                                                                                              • Instruction Fuzzy Hash: C5F0E2A5F45A02C1D900972DD8D002423E2BF44B58FE45232C95C862F0EE1CE49A8702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Object_$Dealloc$ArgsAttrCallErr_InstanceObject
                                                                                                                                                                                                              • String ID: feed
                                                                                                                                                                                                              • API String ID: 1069087923-591414443
                                                                                                                                                                                                              • Opcode ID: ac8b0854f2a92f6ab02b8bc2362475409b68329c589d35864c18ec7a585ccd28
                                                                                                                                                                                                              • Instruction ID: 0931520d15cac336d3a39d1e3ab001eadfbfd5e9943a3170ac9d9eaf59d82209
                                                                                                                                                                                                              • Opcode Fuzzy Hash: ac8b0854f2a92f6ab02b8bc2362475409b68329c589d35864c18ec7a585ccd28
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 71F012A5F8D60781FB155F69E9842B423E1AF48B99F045031CC8D0B375DE6DE1898743
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Object_$Dealloc$ArgsAttrCallErr_InstanceObject
                                                                                                                                                                                                              • String ID: ratio
                                                                                                                                                                                                              • API String ID: 1069087923-4234197119
                                                                                                                                                                                                              • Opcode ID: 5e78501f0d171a08875d62dc5a220b8c7582ed247167608e56f1788c768f6b2b
                                                                                                                                                                                                              • Instruction ID: 33398501388e76129b60745401113293c30d7efca141a929f8ff8c3cf506da37
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 5e78501f0d171a08875d62dc5a220b8c7582ed247167608e56f1788c768f6b2b
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 70F05E60F8960781FB15AB2DE8842B523E2AF48B88F049031C84D4B3B1DE7CE1888343
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'SuperWeirdWordPlugin' object attribute '_foreign_long_watch' cannot be deleted$bool
                                                                                                                                                                                                              • API String ID: 1450464846-232606992
                                                                                                                                                                                                              • Opcode ID: f25d8b8b92148edbd20cfea33d340808ff6923455f8f104a8005e1d37519fff6
                                                                                                                                                                                                              • Instruction ID: c5b0ca26ce91507d9ed1d510bf8b5be718e4c289b53b2aa7d587fc8f5495b2f8
                                                                                                                                                                                                              • Opcode Fuzzy Hash: f25d8b8b92148edbd20cfea33d340808ff6923455f8f104a8005e1d37519fff6
                                                                                                                                                                                                              • Instruction Fuzzy Hash: B0F08CA5F89A0391EA04972DD9D006827E2BF54B68FE44632D55C863F0EE2CE49AC702
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Err_String
                                                                                                                                                                                                              • String ID: 'ArchaicUpperLowerPlugin' object attribute '_buf' cannot be deleted$bool
                                                                                                                                                                                                              • API String ID: 1450464846-2595685569
                                                                                                                                                                                                              • Opcode ID: 5445f695030172c0d74eedf3e058939476bfcef05161a035b360ea2110cf5acd
                                                                                                                                                                                                              • Instruction ID: 8919b24094a5107c52c65115ebc8a068b7a2409336b6e12791230f6e58c18771
                                                                                                                                                                                                              • Opcode Fuzzy Hash: 5445f695030172c0d74eedf3e058939476bfcef05161a035b360ea2110cf5acd
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 22F0A7A5F4590391DD04972DCDD007423E2BF54B98FE54232C55C863F0EE1CE59AC302
                                                                                                                                                                                                              APIs
                                                                                                                                                                                                              Strings
                                                                                                                                                                                                              Memory Dump Source
                                                                                                                                                                                                              • Source File: 00000002.00000002.1830479595.00007FFE0CFC1000.00000020.00000001.01000000.0000001C.sdmp, Offset: 00007FFE0CFC0000, based on PE: true
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830450149.00007FFE0CFC0000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830513318.00007FFE0CFD5000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830542703.00007FFE0CFDB000.00000004.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              • Associated: 00000002.00000002.1830576999.00007FFE0CFDF000.00000002.00000001.01000000.0000001C.sdmpDownload File
                                                                                                                                                                                                              Joe Sandbox IDA Plugin
                                                                                                                                                                                                              • Snapshot File: hcaresult_2_2_7ffe0cfc0000_main.jbxd
                                                                                                                                                                                                              Similarity
                                                                                                                                                                                                              • API ID: Object_$Dealloc$ArgsAttrCallErr_InstanceObject
                                                                                                                                                                                                              • String ID: eligible
                                                                                                                                                                                                              • API String ID: 1069087923-1278981203
                                                                                                                                                                                                              • Opcode ID: c4c18aafb7be077d316736c03388e8b3fc999084a9cdbfa9803da876a134bb0e
                                                                                                                                                                                                              • Instruction ID: 9319e3a8817d16098ece4c596839187a3520a369e833d8ed0ec62d77ce3fd770
                                                                                                                                                                                                              • Opcode Fuzzy Hash: c4c18aafb7be077d316736c03388e8b3fc999084a9cdbfa9803da876a134bb0e
                                                                                                                                                                                                              • Instruction Fuzzy Hash: 9BF012A5F89A0781FF146F69ED892B413E2AF48B99F085031C84D0B375DE6CE1848703